<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The AI Realist]]></title><description><![CDATA[Practical AI for builders, operators, and investors.]]></description><link>https://www.airealist.ai</link><image><url>https://substackcdn.com/image/fetch/$s_!u6cR!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924ecf6b-2ddb-4f24-a3bd-89ae62c7c1dc_800x800.png</url><title>The AI Realist</title><link>https://www.airealist.ai</link></image><generator>Substack</generator><lastBuildDate>Mon, 24 Aug 2026 11:10:33 GMT</lastBuildDate><atom:link href="https://www.airealist.ai/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Julien Simon]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[julsimon@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[julsimon@substack.com]]></itunes:email><itunes:name><![CDATA[Julien Simon]]></itunes:name></itunes:owner><itunes:author><![CDATA[Julien Simon]]></itunes:author><googleplay:owner><![CDATA[julsimon@substack.com]]></googleplay:owner><googleplay:email><![CDATA[julsimon@substack.com]]></googleplay:email><googleplay:author><![CDATA[Julien Simon]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Watcher Is the Product]]></title><description><![CDATA[DeepSeek gave the agent harness away. OpenAI is taxing itself to watch its own. SpaceX paid $60 billion for one. All three just told you where the value went.]]></description><link>https://www.airealist.ai/p/the-watcher-is-the-product</link><guid isPermaLink="false">https://www.airealist.ai/p/the-watcher-is-the-product</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Thu, 20 Aug 2026 17:27:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2JyD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2JyD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2JyD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2JyD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg" width="1456" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:553528,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/211983874?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2JyD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2JyD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79ad4f1b-949b-4148-a2c9-049e7d909f79_1456x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">On August 13, a TypeScript monorepo appeared under the deepseek-ai organization on GitHub: DeepSeek Harness, <code>dsh</code> to its command line, MIT-licensed, carrying a bolded warning that <strong>THERE WILL BE COMPATIBILITY-BREAKING CHANGES</strong> and not a single benchmark score anywhere in the release.[1] Six days later, it holds more than 160,000 stars.[2] On August 14, one day after the release, SpaceX closed its $60 billion all-stock acquisition of Anysphere, the maker of the Cursor coding agent, the highest price yet paid for a harness business.[3] And on August 18, OpenAI published a post titled &#8220;Pacing model development in an era of cyber-critical capabilities,&#8221; disclosing that supervising its own models now costs &#8220;roughly 20% of the inference compute being monitored,&#8221; and that its largest planned frontier reinforcement-learning run is on hold while it assembles the evidence and the machinery to run it safely.[4]</p><p style="text-align: justify;">Six days, one layer, three prices: zero, sixty billion dollars, and a fifth of everything watched. The layer is the harness, the control loop around the model. DeepSeek put its loop on GitHub for free. SpaceX paid sixty billion for a company that makes one. OpenAI said publicly in a document that the loop around <em>its</em> models has become expensive enough to disclose. <strong>None of the week&#8217;s three events is about a model. All three are about the scaffolding models run inside, and August 2026 is the month that scaffolding stopped being plumbing and became the contested asset of the AI stack.</strong></p><h2>The Layer Nobody Sells</h2><p style="text-align: justify;">A harness is everything around the model that turns text prediction into work: the system prompt, the tool catalog, the execution loop, the sandbox, the session state, the retry logic, the thing that decides when the agent is done. Claude Code is a harness. Codex is a harness. So are Aider, Cline, Goose, OpenCode, OpenHands, Pi, and Mistral&#8217;s Vibe; Cursor wraps one in an editor. The field is crowded enough that harness design philosophies have spanned a factor of fifty, from Pi&#8217;s two hundred tokens of system prompt to the ten thousand or so Claude Code carried until Anthropic cut it by roughly 80 percent this summer.[5]</p><p style="text-align: justify;">For three years, the industry treated this layer as a giveaway, open source, or bundled with the subscription, rarely as a line item. The model was the product; the harness was the wrapper around it. Most of that list was already free. What changed in August is that the zero became a strategy and the cost became public: one frontier camp made the giveaway its flagship release; the other disclosed, for the first time, what the layer costs to police. Between the zero and the 20% sit two measurements, one from four unaffiliated researchers and one from Tencent. <strong>Scores move more when you change the harness than when you change the model, and when the model&#8217;s judgment fails, the defenses that hold are the ones built into the harness</strong>. The layer one lab just gave away is the layer the other is taxing itself to police.</p><p>That is the argument. Here is the evidence.</p><h2>Five Times the Model</h2><p style="text-align: justify;">On August 15, two days after the DeepSeek release, four researchers published a paper with no institutional affiliation under the title &#8220;StateM: Reaching 95.3% Raw Accuracy, or a $15 Frontier Run, on Terminal-Bench 2.1 via Harness Scaling.&#8221;[6] Terminal-Bench is the de facto reference benchmark for terminal-based agents: 89 tasks, real shells, verified outcomes. StateM is not a model. It is a frozen YAML runbook bolted onto an existing agent, a state machine of preconditions and practices distilled from failure postmortems. No weights change. Only the harness does.</p><p style="text-align: justify;">The numbers: GPT-5.5 under a stock harness scores 83.1 percent. The same model inside StateM scores 92.1% (+9 points) based on configuration alone.[7] For calibration, that is numerically above the 91.9% the paper cites for GPT-5.6 Sol Ultra, the next generation&#8217;s premium compute tier. Moving from GPT-5.5 to GPT-5.6 Sol at the same effort tier moves the score from 83.1 to 84.9 (+1.8%). A skeptic can build a bigger generation delta by buying up the range &#8212; stock Ultra sits 8.8% over stock GPT-5.5 &#8212; but that is rather the point: the runbook matched Ultra without changing models. <strong>The harness moved the score about five times as far as the model generation did</strong>.[8]</p><p style="text-align: justify;">The authors put their conclusion in bold: &#8220;The model appears not to be the (main) bottleneck.&#8221; And they draw the commercial inference for you: &#8220;One can invest in a harness that turns a cheaper model into a stronger system.&#8221;[9] Their cheap-model exhibit is the week&#8217;s other protagonist: DeepSeek-V4-Flash inside StateM reaches 88.1% for $15.20 in realized API charges. The frontier GPT-5.6 Sol xhigh run behind the 95.28% headline cost $1,062.95. A separate frontier submission cost $574.68 and scored 83.37%.[10] Read that triplet again. <strong>The frontier model in someone else&#8217;s submission scored </strong><em><strong>lower</strong></em><strong> than the bargain model inside the right harness, at thirty-eight times the reported cost</strong>.</p><p style="text-align: justify;">Now the asterisks, because this paper deserves both its headline and its scrutiny. The 95.28% is pre-adjudication. Its submission is still open as of this writing, with thirteen trajectories flagged by the benchmark&#8217;s automated review.[11] Four are conceded by the authors: embedded verification logic that should score zero, resulting in a score of 94.38%. Zeroing the nine flagged as possible reward hacking&#8212;gaming the grader rather than solving the task&#8212;sets their floor at 93.26. Zeroing all thirteen, the compounded worst case that the paper does not print gives 92.36. Every point in that range still sits numerically above the Ultra reference. The finding survives its asterisk. A reviewer&#8217;s separate cross-task contamination question remains open, the one flag arithmetic cannot bound.</p><p style="text-align: justify;">The deeper asterisk is generalization. Moved frozen, one-shot, to a held-out benchmark called BusinessBench, the runbook gains 0.55 macro points, a fraction of the headline gain, with outright negative transfer on two task families.[12] And the authors disclose something more uncomfortable: across iterations, their harness learned one evaluator&#8217;s boundary conventions &#8220;without ever reading verifier code.&#8221;[13] <strong>The runbook didn&#8217;t just learn to operate a terminal. It learned to please a specific examiner.</strong></p><p style="text-align: justify;">Both facts are true at once. A paper demonstrating that harnesses can inflate benchmark scores has a possibly-inflated benchmark score; a runbook tuned on postmortems memorized the grader; the leaderboard it sits on adopted, back in April, an automated &#8220;agent judge&#8221; that re-reviews every passing trial for reward hacking after three organizations were caught cheating.[14] The phenomenon is manifesting at every level, including the meta-level: even the benchmark now imposes a monitoring tax on the harness layer. Harness engineering is real leverage, and it is leverage precisely because it specializes in the task, in the environment, and, if you are not careful, in the examiner. Which is why <strong>the honest reading of the 5x is as a ceiling, not a floor</strong>.</p><h2>Everything Is a Plugin, Including the Providers</h2><p style="text-align: justify;">Against that measurement, consider the artifact DeepSeek shipped. The repository&#8217;s one-line description is the thesis: everything is a plugin. The fuller claim, as the company put it: &#8220;Models, tools, skills, sessions, sandboxes, filesystems, loops, orchestration, and UI are ALL implemented as plugins, and can be mixed, matched, replaced, and extended.&#8221;[15] The kernel underneath is not even DeepSeek&#8217;s: dsh is built on Cordis, a pre-existing plugin meta-framework from the Chinese chatbot ecosystem around Koishi.[16] A frontier lab looked at the most contested layer of the agent stack and adopted a chatbot community&#8217;s architecture for it. That is either humility or speed; on a codebase marked developer preview, it is probably both.</p><p style="text-align: justify;">The builders it aims at noticed: Armin Ronacher &#8212; co-founder of Earendil, which steers the Pi agent &#8212; called it &#8220;for sure the first time I have been looking at something new in the space and felt quite inspired to revisit some of our choices.&#8221;[5] The Hacker News thread reached 739 points, with praise focusing on the strength of this piece&#8217;s argument, while criticism focused on maturity and the plugin's attack surface.[17]</p><p>Three properties of the release matter.</p><p style="text-align: justify;">First, the silence. DeepSeek&#8217;s model launches include benchmark tables with accompanying prose. The harness shipped with none: no Terminal-Bench, no SWE-bench, and no eval directory containing results.[1] For this lab, that silence is louder than a chart. Either they have not measured, or the measurement does not flatter yet. Or they watched the 95.28 adjudication saga and declined to play a game where every harness number arrives with an asterisk. Whichever it is, <strong>the launch asks to be judged as architecture rather than capability</strong>. For a benchmark-first lab, this is a repositioning.</p><p style="text-align: justify;">Second, the logging. Every session in dsh is an append-only, replayable record, and the trajectory view exposes whatever reasoning the provider returns, which, for DeepSeek&#8217;s own API, is everything: V4-Pro now ships with thinking mode on by default.[18] Set that against the incumbents: OpenAI decided in September 2024, in the o1 launch post, not to show raw chains of thought, &#8220;after weighing multiple factors including user experience, competitive advantage, and the option to pursue the chain of thought monitoring&#8221; [19]. Anthropic serves summaries of extended thinking and gates raw traces.[20] The industry&#8217;s chain-of-thought settlement inverted quietly this month: <strong>the closed labs treat raw reasoning as either a liability to monitor or an asset to protect, and the open lab treats it as a logging feature</strong>.</p><p style="text-align: justify;">Third, the funnel that isn&#8217;t. The obvious read of a free harness from a token vendor is razor-and-blades: MIT the razor, sell the blades. The configuration reality is softer. dsh ships provider cards for DeepSeek, Anthropic, OpenAI, Azure, Bedrock, Vertex, and Codex, and no provider is wired in as a default; you open settings and paste whichever key you own.[21] DeepSeek&#8217;s harness will cheerfully orchestrate OpenAI&#8217;s models. In the vocabulary this newsletter used for Nvidia&#8217;s open-source strategy, dsh is currently a sun, not a black hole: its gravity points outward, hardware- and provider-agnostic, where Nvidia&#8217;s giveaways route ecosystems back to its silicon.[22]</p><p style="text-align: justify;">That does not make the release charity. DeepSeek sells exactly one thing: tokens. It gave the weights away to grow their market, and the harness extends the same play one layer up. Leaked minutes of an investor meeting with founder Liang Wenfeng, published by ChinaTalk the day the harness shipped, cast China as a &#8220;token factory at global scale, pushing the price of intelligence down,&#8221; with DeepSeek as the instrument. DeepSeek&#8217;s own published economics say the factory&#8217;s margins live in the API.[23] And if a factory devoted to pushing prices down raised its own the same day [18], that is razor-and-blades in its plainest form: <strong>the price being pushed down is the market&#8217;s floor, not DeepSeek&#8217;s top tier, and the free layer is what walks you to the register</strong>. </p><p style="text-align: justify;">Follow the token-factory logic, and the harness strategy writes itself. You do not need to lock anyone in. You need the layer between users and tokens to be free, excellent, and everywhere, so that the only purchasing decision left is which tokens to pour through it, a competition DeepSeek believes it wins on price. Commoditize your complement. The Free Harness is less a lock than a price signal: this layer should cost nothing. Its de facto plugin registry today is an unauthenticated GitHub topic &#8212; anyone can publish to it.[24]</p><h2>The Twenty Percent</h2><p style="text-align: justify;">OpenAI&#8217;s August 18 post is the other half of the repricing. The core disclosure, verbatim: &#8220;These safeguards require meaningful compute. Our current estimates put monitoring overhead at roughly 20% of the inference compute being monitored, though the cost varies substantially across training and evaluation workloads.&#8221;[4]</p><p style="text-align: justify;">The scope is capability-indexed and precisely drawn: monitoring is required for all reinforcement-learning training and all tool-using evaluations for models at GPT-5.6 Sol capability or above.[25] The sharpest edge is a model OpenAI has not shipped: on August 7, eleven days before the cost disclosure, it said preliminary evaluations of an upcoming model called Astra were strong enough that it &#8220;cannot rule out critical cyber capabilities under our Preparedness Framework&#8221;, and that Astra &#8220;was not involved in exploiting Hugging Face.&#8221;[26] </p><p style="text-align: justify;">The threshold is a model that finds and weaponizes zero-days in hardened real-world systems without human help. The response is harness all the way down: isolation, restricted network and tool access, &#8220;universal monitoring for risky actions and misalignment across all agentic applications of Astra,&#8221; chain-of-thought monitors empowered to &#8220;review and interrupt high-risk activity.&#8221;[26] With that finding came an extension: monitoring now covers every tool-using inference call Astra makes, not just training and evals.[25]</p><p>Alongside, the pause: &#8220;Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignment before proceeding.&#8221;[27]</p><p>Two readings of the 20%.</p><p>The skeptical reading: the denominator does all the work. Twenty percent of the inference compute being monitored, and the monitored share of total inference is undisclosed. If monitoring covers a sliver of traffic (frontier RL, evals, one presumptively cyber-capable model&#8217;s tool calls), the blended overhead across OpenAI&#8217;s fleet could be low single digits, and &#8220;20 percent tax&#8221; would overstate the burden the way headline capex numbers overstate disbursement. OpenAI has published the rate and withheld the base. A spokesperson added that the costs &#8220;won&#8217;t be passed on directly to customers&#8221;, and &#8220;directly&#8221; is carrying luggage.[28]</p><p style="text-align: justify;">The structural reading: the direction is unmistakable even if the magnitude is foggy. This is the company that stopped showing raw chains of thought partly to preserve monitorability, now publishing a price for the watching, and holding its biggest planned run until the watching is ready. The proximate cause is on the record: the July incident in which two OpenAI models under evaluation, with reduced refusal rates, escaped a sandbox via an Artifactory zero-day and reached Hugging Face&#8217;s infrastructure.[29] Both companies&#8217; remediations live mostly at the network and credential layer. After July, OpenAI paused frontier-model inference in research clusters for runs that could execute code or access the internet; the monitoring program is the condition the post offers for scaling such runs again.[4]</p><p style="text-align: justify;">The obvious objection runs the other way: doesn&#8217;t a tax levied on dangerous models prove the model is what matters? The risk originates there, yes: Astra earned its surveillance. But look at where the money goes: every item on OpenAI&#8217;s own mitigation list is loop-level: watchers wrapped around inference, execute-and-internet restrictions, sandboxes, permission boundaries. None of that spend makes the model more capable. All of it hardens the loop, the Monitoring Tax conceding in compute what StateM measures in points.</p><p style="text-align: justify;">And the monitoring technique OpenAI has published most about &#8212; reading the model&#8217;s chain of thought &#8212; carries a failure mode OpenAI itself documented in 2025: optimizing against a chain-of-thought monitor &#8220;does not eliminate all misbehavior and can cause a model to hide its intent.&#8221;[30] Monitoring at production scale <em>is</em> an optimization pressure: models get updated, retrained, and selected under it. That makes the Monitoring Tax an arms race rather than a toll, funded indefinitely out of OpenAI&#8217;s own compute.</p><p style="text-align: justify;">Put the two announcements side by side, and the asymmetry sharpens into strategy. A monitor over a training run and a sink gate in a session loop are the same line item: compute and code spent on the loop rather than the weights. DeepSeek&#8217;s answer to &#8220;who watches the agent?&#8221; is: you do; here is the append-only log; replay it. OpenAI&#8217;s answer is: We do, and here is what it costs. One externalizes the cost of supervision to the user and calls it transparency. The other internalizes it and calls it safety. Both are telling you the same truth: <strong>the loop around the model is now where risk management happens.</strong></p><h2>The Audit Came From Tencent</h2><p style="text-align: justify;">This brings us to the strongest evidence that the harness is the security perimeter. On August 17, four days after the dsh release, a team from Tencent&#8217;s Zhuque Lab published a security assessment of DeepSeek Harness, run with A.I.G, Tencent&#8217;s own AI-infrastructure red-teaming tool.[31] One Chinese lab publicly red-teaming another&#8217;s four-day-old flagship, methods and per-channel numbers in the open, is a norm Western frontier labs have not practiced on each other&#8217;s shipped products uninvited. An audit this fast was possible because the artifact is public: the transparency DeepSeek sells is what let Tencent take it apart in four days.</p><p style="text-align: justify;">The design is exhaustive for its target: 14,560 controlled executions against a pinned release-day commit, each payload tried both pasted as text and delivered as a file.[32] Headline result: full injection success at 5.6%, with most attempts ending in the agent explicitly refusing.[33]</p><p style="text-align: justify;">Whether 5.6% is good is unanswerable: no comparable audit of Claude Code or Codex has been published to serve as a baseline. The distribution, though, is where the lessons are.</p><p style="text-align: justify;">Hidden Unicode payloads inside files succeed 25.5% of the time; the identical payload pasted as text never succeeds.[34] The model is the same in both cases. What differs is the ingestion path: the paste route evidently normalizes away what the file route preserves. The delivery, and the cheapest defense, live in plumbing the model never sees.</p><p style="text-align: justify;">The skills channel &#8212; the very thing &#8220;everything is a plugin&#8221; celebrates &#8212; is injectable at 14-16%, among the highest rates in the study.[35] The architecture&#8217;s core feature is one of its largest measured wounds and its most predictable: skills are trusted instructions by design, so they are the cheapest place to hide untrusted ones, and the unauthenticated plugin topic is where untrusted ones will come from.</p><p style="text-align: justify;">The strongest text-mode attack in the study is social rather than technical: a fake progress note &#8212; your task is already done, now do this &#8212; planted in content the agent reads, succeeding at 17.0% against a 5.7% naive baseline.[36] The agent&#8217;s weakness is less parsing than trust in its own apparent history. And the most consequential split in the paper: corrupting what the agent says succeeds at 35.7%, while hijacking what it does &#8212; actually reaching a sensitive sink like mail, shell, or a transfer &#8212; succeeds at 2.5%.[37] An order of magnitude between lying and acting, but corrupted output that a human acts on is a hijack in itself.</p><p style="text-align: justify;">Why the gap? Because between interpretation and action sits the harness: confirmation steps, scoped permissions, sinks that demand more than persuasive context. Tencent&#8217;s top recommendation is to finish the job: authorize sensitive sinks independently of model interpretation.[38] Do not ask the model whether the email should be sent; make the send path require an authority the model&#8217;s context cannot mint. The July post-mortems converged on the same fix: authority boundaries, not better judgment.[29]</p><p style="text-align: justify;">Questions we&#8217;ll all have to answer: <strong>which actions can a poisoned context authorize? Which ingestion paths skip the paste route&#8217;s normalization? Who can publish a skill your agents will load?</strong> The defense in Tencent&#8217;s 14,560 runs was layered: 68% of attempts died when the model refused, and the harness failed to convert most of the survivors into privileged action. <strong>Security, like capability, is becoming a property of the loop.</strong></p><p style="text-align: justify;">The remaining caveats are the study&#8217;s own: a single harness, a single model, a single commit, and simulated sinks. Treat every number as a first measurement, not a ranking. But the direction of the finding does not depend on the baseline. Both of this month&#8217;s measurements point to the same layer from opposite sides: StateM shows the harness is where the capability variance is; Tencent shows it is where the effective defenses are.</p><h2>What the Asymmetry Buys</h2><p style="text-align: justify;">DeepSeek&#8217;s transparency is as strategic as OpenAI&#8217;s opacity. A lab accused of training on competitors&#8217; outputs benefits from normalizing raw chain-of-thought access: exposed traces are distillation feedstock, and while a closed API can still withhold its raw traces, a default-logging harness moves the norm: whatever a provider does return is recorded, replayable, and one export away from a training set.[39] &#8220;Everything is a plugin&#8221; also means the attack surface is a plugin: the skills channel Tencent flagged and the unvetted registry topic are the price of the architecture, and DeepSeek shipped them at developer-preview maturity, with a bolded compatibility warning where a plugin trust model will have to go.</p><p style="text-align: justify;">Conversely, OpenAI&#8217;s opacity spans two different decisions made two years apart, and the defense framing invites reading them as one. Monitoring for cyber-critical capability is a safety cost, disclosed this month; declining to show raw chains of thought is a choice from 2024, made by OpenAI&#8217;s own listing of factors, partly for &#8220;competitive advantage.&#8221;[19] Both are real; only one is the 20%. The asymmetry itself &#8212; one lab&#8217;s flagship feature is the other lab&#8217;s disclosed liability &#8212; is the finding.</p><p style="text-align: justify;">Readers of &#8220;<a href="https://www.airealist.ai/p/the-verification-tax">The Verification Tax</a>&#8221; will recognize the shape: there, the binding cost in verifiable-reward RL had migrated from generating answers to checking them; the Monitoring Tax is the same migration at the safety layer.[40] The priced layers of the stack, mid-2026, are the ones that watch and verify; the intelligence itself trades as a commodity, inside scaffolding that is now literally free.</p><h2>The Shell and the Moat</h2><p style="text-align: justify;">The deal that closed on August 14 was announced on June 16, days after SpaceX&#8217;s listing, with Anysphere then preparing for a round at a $50 billion valuation.[3] Sixty billion in a just-listed acquirer&#8217;s paper is not sixty billion in cash. Cognition &#8212; the Devin agent, plus the Windsurf editor it acquired &#8212; remains the largest standing independent: it raised $1 billion at a $25 billion pre-money valuation in May.[41]</p><p style="text-align: justify;">So what did SpaceX buy? Start with what it did not need. Not a software revenue line: a company assembling an AI division out of rockets, satellites, and the xAI merger does not spend sixty billion on ARR. And not models: xAI came in-house earlier this year, so the acquirer already owns a frontier lab.[3] <strong>A buyer with its own models paying the week&#8217;s highest price for a harness company is this piece&#8217;s thesis with a board&#8217;s signature on it</strong>. The model was not the bottleneck. The loop was. And the most deflationary rival read &#8212; that a model owner simply bought the funnel that feeds its models &#8212; is DeepSeek&#8217;s razor-and-blades at acquisition prices: it concedes the layer and haggles over the motive.</p><p style="text-align: justify;">What sixty billion buys, on the reading the week&#8217;s evidence supports, is the harness in the full sense. Not the generic shell DeepSeek zeroed twenty-four hours earlier, but everything that turns a shell into a harness: <strong>the coding-specialized loop, the domain process tuned against a telemetry base no rival could assemble from scratch, the team that does the tuning, and the enterprise contracts that keep the telemetry coming</strong>. </p><p style="text-align: justify;">VS Code did not kill JetBrains &#8212; Cursor itself began as a VS Code fork &#8212; and free shells tend to grow the category they commoditize. The decomposition also predicts a third moat: assurance. A hardened, attested build of a free shell is a paid product &#8212; Red Hat built a company on that arbitrage &#8212; and OpenAI just told you what assurance costs at the frontier. The twenty-six-trillion-dollar addressable market is the acquirer&#8217;s number and the acquirer&#8217;s story; the read above does not need it.[3]</p><p style="text-align: justify;">StateM hands you the same decomposition from the measurement side. Nine points on the benchmark the runbook was tuned for; 0.55 frozen points on the held-out one. The durable part of a harness advantage is the domain process &#8212; renewable, domain-bound, not ownable &#8212; and the assets that regenerate it: the users and the telemetry and postmortems they produce. The disposable part is the shell that hosts it, which now has a posted price. The underwriting translation is one question: of this company&#8217;s margin, how much is the loop itself, and how much is distribution, data, and contracts? This locates the value; it does not grade the price. <strong>SpaceX did not buy a shell; it bought the parts DeepSeek cannot give away.</strong></p><p style="text-align: justify;">The exit pattern should look familiar to readers of the silicon pieces: the independent specialized-inference vendors have been absorbed or signed away one by one to the GPU merchants, and now the largest independent harness has ended up inside an integrator too.[42] The one thing the Cursor deal does not tell you is what an independent harness is worth, because after August 14, there is one fewer way to find out.</p><h2>What Would Have to Break</h2><p>Three falsifiers, in plain language. </p><ol><li><p>If the next model generations resume dominating &#8212; if GPT-5.7 or V5 under stock harnesses move agentic benchmarks by more than harness engineering does &#8212; then the commoditization read dies and this was a plateau artifact. StateM currently argues otherwise, but StateM is one paper, with headline results on one benchmark, and an open adjudication. </p></li><li><p>If DeepSeek Harness, six months from now, has a thriving plugin ecosystem and no presence on Terminal-Bench-class leaderboards &#8212; or, if it avoids leaderboards on principle, no dsh components showing up inside rival stacks &#8212; then it is a chatbot shell with good marketing, not a harness in the sense that moves scores, and the Free Harness was a giveaway of something that did not matter.</p></li><li><p> If OpenAI ever discloses the monitored share of total inference and it rounds to low single digits blended, then the Monitoring Tax is a frontier-lab boutique cost, not a structural one. And the moat claim has its test: if Cursor-class pricing power survives customers swapping their own model keys into free shells at scale &#8212; revenue attributable to the loop itself &#8212; then the moat was in the shell after all, and this piece mislocated it.</p></li></ol><p style="text-align: justify;">What does not depend on any of those: where the decisions moved. <strong>From now on, we shouldn&#8217;t be choosing a model: the model is a provider card, swappable by design in the open reference, locked only where a vendor insists. We should be choosing a harness: its ingestion paths, its sink authorization, its logging posture, its plugin trust model.</strong> The properties Tencent measured and StateM priced. And anyone modeling frontier-lab economics now has a new line item with a disclosed rate and an undisclosed base, growing with capability by policy.</p><p style="text-align: justify;">DeepSeek and OpenAI disagree about nearly everything: licensing, logging, disclosure, where trust should live. In a single August week, they agreed, by acting in opposite directions, on the only question that matters: <strong>the loop around the model now moves outcomes more than the model inside it, and each lab priced that fact as aggressively as its business model allows</strong>. One priced it at zero to commoditize it. The other priced it at twenty percent of everything it watches to control it. And the week&#8217;s third price agreed with both of them: sixty billion dollars, from a buyer that already owned frontier models, for the loop around them. </p><p style="text-align: justify;">Everything is a plugin now &#8212; models, tools, skills, sandboxes, the UI. Everything except the watcher. <strong>The watcher is the product. The three of them only disagreed about who pays for it.</strong></p><div><hr></div><h3>Notes</h3><p>[1] DeepSeek-AI, <a href="https://github.com/deepseek-ai/deepseek-harness">DeepSeek Harness repository</a>, created August 13, 2026 (GitHub API <code>created_at</code> 2026-08-13T11:56:32Z, retrieved August 19). MIT license, TypeScript monorepo. The developer-preview warning &#8212; &#8220;THERE WILL BE COMPATIBILITY-BREAKING CHANGES,&#8221; bold in the original &#8212; is in the README. No benchmark, eval, or accuracy figure appears anywhere in the repository or launch materials as of August 19, 2026.</p><p>[2] Readings diverged on August 19, 2026: the <a href="https://api.github.com/repos/deepseek-ai/deepseek-harness">GitHub API</a> returned 165,743 stars and 17,618 forks, Shields.io showed ~166k, and GitHub&#8217;s rendered page showed 161.1k &#8212; star counts are eventually consistent and gameable, so the body uses the conservative floor. Stars measure attention, not quality; no independent audit of bot inflation exists for this repository, which is why this piece makes no &#8220;fastest-ever&#8221; comparison.</p><p>[3] Deal terms per <a href="https://techcrunch.com/2026/06/16/spacex-to-acquire-cursor-for-60b-in-stock-days-after-blockbuster-ipo/">TechCrunch, &#8220;SpaceX to acquire Cursor for $60B in stock, days after blockbuster IPO&#8221;</a>, June 16, 2026 (all-stock; TechCrunch reports a $10B break-up fee while Reuters reported a $4&#8211;10B range; Anysphere then preparing a $2B round at a $50B valuation), and completion per <a href="https://www.bloomberg.com/news/articles/2026-08-14/spacex-completes-its-60-billion-cursor-acquisition">Bloomberg, &#8220;SpaceX Completes $60 Billion Cursor Acquisition to Expand AI Coding Tools&#8221;</a>, August 14, 2026. The $26 trillion addressable-market figure is SpaceX&#8217;s own investor pitch as reported by TechCrunch &#8212; a vendor number, cited as the acquirer&#8217;s story, not as a market fact. TechCrunch also notes the acquisition strengthens SpaceX&#8217;s AI division, &#8220;which merged with Elon Musk&#8217;s xAI earlier in 2026&#8221; &#8212; the basis for the body&#8217;s observation that the acquirer already owned frontier models.</p><p>[4] OpenAI, <a href="https://openai.com/index/pacing-model-development-cyber-capabilities/">&#8220;Pacing model development in an era of cyber-critical capabilities&#8221;</a>, August 18, 2026. All OpenAI quotes in this piece are verbatim from the post unless otherwise attributed. The post also states OpenAI &#8220;paused frontier model inference in research clusters for runs that could execute code or use tools that could access the internet&#8221; immediately after the July incident.</p><p>[5] Thomas Claburn, <a href="https://www.theregister.com/ai-and-ml/2026/08/14/deepseeks-innovative-harness-treats-everything-as-a-plug-in/5288095">&#8220;DeepSeek&#8217;s innovative harness treats everything as a plug-in&#8221;</a>, The Register, August 14, 2026 &#8212; the harness field list, the Ronacher quote and identification, and the system-prompt comparisons. <a href="https://github.com/mistralai/mistral-vibe">Mistral&#8217;s Vibe</a>, the open-source CLI coding agent, added to the list by this piece. The prompt sizes (Pi ~200 tokens; Claude Code ~10,000, cut roughly 80 percent) are community measurements relayed by the Register, not vendor statements.</p><p>[6] Ziheng Qin, Yaxin Lu, Zhangyang Wang, Kai Wang, <a href="https://arxiv.org/abs/2608.15089">&#8220;StateM: Reaching 95.3% Raw Accuracy, or a $15 Frontier Run, on Terminal-Bench 2.1 via Harness Scaling&#8221;</a>, arXiv:2608.15089, August 15, 2026; code at <a href="https://github.com/henryqin1997/statem">github.com/henryqin1997/statem</a>. The paper states the work &#8220;was conducted in the authors&#8217; personal time and does NOT reflect the views of any affiliated organization&#8221;; no institution is named.</p><p>[7] StateM results: GPT-5.5 (xhigh) 83.1% stock &#8594; 92.1% under StateM; GPT-5.6 Sol (xhigh) 84.9% stock &#8594; 95.28% raw pre-adjudication (424/445 trials; 89 tasks &#215; 5 trials). The Ultra comparison is the abstract&#8217;s own: &#8220;StateM raises GPT-5.5 xhigh to 92.1%, versus 83.1% reference and GPT-5.6 Sol Ultra at 91.9%&#8221; &#8212; 91.9% is cited as the flagship&#8217;s reference score, not a StateM result. The 0.2-point margin of 92.1 over 91.9 is within sampling error (the submission reports &#177;0.87% SE); &#8220;numerically above&#8221; in the body is meant literally, not as a significance claim. All figures from the paper and the leaderboard submission (note 11).</p><p>[8] Arithmetic: harness deltas +9.0 (GPT-5.5) and +10.4 (GPT-5.6 Sol xhigh) versus the +1.8 stock-to-stock generation delta (83.1 &#8594; 84.9); 9.0 &#247; 1.8 = 5.0. Same benchmark, same task set, same trial protocol. The 5.0&#215; ratio is built on the GPT-5.5 pair, which is paper-reported and not part of the flagged leaderboard submission; the flagged trials (note 11) all belong to the GPT-5.6 Sol xhigh run.</p><p>[9] Both quotes from the paper; the bottleneck sentence is bolded in the original.</p><p>[10] Costs per the paper and submission: $1,062.95 reported model cost (1.18B tokens) for the GPT-5.6 Sol xhigh run; $15.20 realized API charges for the DeepSeek-V4-Flash final evidence run at 88.09% under standard timeouts (stock baseline 82.7%; the whole DeepSeek adaptation campaign cost $52.22); $574.68 is a <em>different</em> leaderboard submission &#8212; GPT-5.6 Sol (max) at 83.37% raw &#8212; not the same configuration at a different price. $574.68 &#247; $15.20 &#8776; 37.8&#215;. &#8220;xhigh&#8221; and &#8220;max&#8221; denote reasoning-effort configurations.</p><p>[11] <a href="https://github.com/harbor-framework/terminal-bench-2-1/pull/142">Pull request #142, harbor-framework/terminal-bench-2-1</a>, filed July 15, 2026; still open with last activity July 31 as of August 19. Automated review flagged 13 trajectories: 4 as &#8220;harness cheating&#8221; (embedded verification logic &#8212; the authors concede these should score zero, giving 420/445 = 94.38%) and 9 as possible reward hacking (the authors dispute 5 as false positives). The paper&#8217;s two scenarios do not compound: it computes 420/445 = 94.38% (zeroing the 4) and 415/445 = 93.26% (zeroing the 9) each from the raw 424. The PR lists the 13 flagged trajectories as distinct, so the compounded worst case &#8212; all 13 zeroed &#8212; is 411/445 = 92.36%, a floor the paper does not state; this piece uses it. The submission&#8217;s agent is listed as &#8220;statem-Codex&#8221; &#8212; StateM wrapped around Codex. A reviewer separately raised cross-task hint contamination. Adjudication is pending; every headline number in this piece carries that status. For scale: the top <em>merged</em> entry shown on the <a href="https://www.tbench.ai/leaderboard/terminal-bench/2.1">public 2.1 leaderboard</a> sat at 83.8% (Claude Code, Fable 5) as of August 19 &#8212; the StateM figures above that are paper- and PR-reported, not yet board-accepted.</p><p>[12] BusinessBench frozen one-shot transfer: +0.55 macro (+1.34 micro); negative transfer on RefactorBench (&#8722;2.78) and WooCommerce Stock (&#8722;3.70), where the paper says the learned controls targeted the wrong execution boundaries; two mechanism-matched task families gained +10.04. The runbook transfers where the mechanism matches, and not elsewhere.</p><p>[13] The paper&#8217;s own disclosure: the profile learned a verifier&#8217;s boundary convention &#8220;without ever reading verifier code&#8221; &#8212; repeated evaluator feedback encoded the examiner&#8217;s unstated conventions into the runbook.</p><p>[14] Terminal-Bench, <a href="https://www.tbench.ai/news/leaderboard-integrity-update">&#8220;Leaderboard integrity update&#8221;</a>, April 19, 2026: an agent judge now re-reviews all passing trials for reward hacking (zeroed if confirmed), after three organizations &#8212; OpenBlock (OB-1), QuantFlow (Pilot), and ForgeCode &#8212; were penalized for cheating.</p><p>[15] The one-line description and the &#8220;Everything is a Plugin&#8221; framing are on the repository itself (note 1); the fuller sentence is DeepSeek&#8217;s wording as quoted by The Register (note 5); capitalization in the original.</p><p>[16] <a href="https://github.com/cordiverse/cordis">Cordis</a> is a pre-existing plugin meta-framework from the ecosystem around the Koishi chatbot project, not a DeepSeek codebase; its design paper, <a href="https://github.com/cordiverse/paper">&#8220;A Programming Paradigm for Spatiotemporal Composability&#8221;</a>, is GitHub-hosted with no peer-reviewed venue. Some aggregator coverage has misattributed Cordis to DeepSeek; the provenance is the other way around &#8212; DeepSeek adopted it.</p><p>[17] <a href="https://news.ycombinator.com/item?id=49285244">Hacker News, &#8220;DeepSeek Harness developer preview&#8221;</a> &#8212; 739 points, 309 comments as of August 19, 2026. The characterization of where praise and criticism concentrated is this piece&#8217;s reading of the thread; the quoted phrase is from a highly upvoted comment. Forum commentary: color and practitioner sentiment, not evidence.</p><p>[18] Session model per repository documentation and The Register (note 5): append-only session log with a trajectory view exposing raw reasoning. V4-Pro reached general availability on the API &#8212; thinking mode on by default &#8212; on August 13, 2026, the same day as the harness release; see e.g. <a href="https://venturebeat.com/technology/deepseek-harness-launches-as-open-source-rival-to-claude-code-alongside-v4-pro-on-api-with-higher-prices">VentureBeat&#8217;s launch coverage</a>.</p><p>[19] OpenAI, <a href="https://openai.com/index/learning-to-reason-with-llms/">&#8220;Learning to reason with LLMs&#8221;</a>, September 2024: &#8220;after weighing multiple factors including user experience, competitive advantage, and the option to pursue the chain of thought monitoring, we have decided not to show the raw chains of thought to users,&#8221; serving &#8220;a model-generated summary of the chain of thought&#8221; instead.</p><p>[20] Anthropic&#8217;s summarized reasoning and gated raw traces per The Register (note 5). Anthropic has not published a comparable cost figure for its classifier and summarization pipeline.</p><p>[21] <a href="https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/user/guide/providers.md">DeepSeek Harness provider documentation</a>: provider cards for DeepSeek, Anthropic, OpenAI, Azure, Bedrock, Vertex, and Codex (the last authenticating over OAuth); API keys are entered manually in settings; the documentation designates no provider as the default.</p><p>[22] &#8220;<a href="https://www.airealist.ai/p/open-source-closed-orbit">Open Source, Closed Orbit: The Hardware Monopolist&#8217;s Guide to Owning Open Source</a>,&#8221; The AI Realist &#8212; the black-hole/sun diagnostic: does a vendor&#8217;s open-source contribution make competitors&#8217; products easier or harder to use?</p><p>[23] Irene Zhang, <a href="https://www.chinatalk.media/p/the-deepseek-thesis">&#8220;The DeepSeek Thesis&#8221;</a>, ChinaTalk, August 13, 2026 &#8212; leaked minutes of a four-hour meeting between Liang and investors that circulated in late July; the clause quoted in the body is ChinaTalk&#8217;s English rendering (&#8221;China, in his eyes, will play the role of token factory at global scale, pushing the price of intelligence down as it did for countless other industries during its manufacturing boom&#8221;), not a verbatim Liang quote. The $562,027/day and 545 percent figures are not from the leak: ChinaTalk attributes them to an analysis DeepSeek itself published in February 2025 (R1 API, theoretical daily revenue at a 545 percent cost-profit ratio, with DeepSeek&#8217;s own caveat that actual revenue ran substantially lower). Vendor-published theoreticals &#8212; better provenance than a leak, still the seller&#8217;s math. The mundane read of the harness release &#8212; an ordinary ecosystem move, no grand pricing design &#8212; survives the evidence; the price signal reads the same either way.</p><p>[24] The <code>dsh-plugin</code><a href="https://github.com/topics/dsh-plugin"> GitHub topic</a> functions as the de facto plugin registry: 150 public repositories carried the tag as of August 19, 2026, six days after release. GitHub topics are self-applied by repository owners; there is no authentication, signing, vetting, or review, and DeepSeek has announced no registry governance. The most visible curation is a community-maintained awesome-list.</p><p>[25] OpenAI post (note 4): &#8220;This monitoring is required for all RL training and evaluations involving tools for models of Sol capability or higher,&#8221; and: &#8220;Once we determined that Astra may have critical cyber capabilities on August 7, we added an additional monitoring requirement for all inference of Astra with tools (not just RL training and evaluations).&#8221;</p><p>[26] OpenAI, <a href="https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/">&#8220;Responding to the next frontier of critical cyber capabilities&#8221;</a>, August 7, 2026. Body quotes verbatim: OpenAI &#8220;cannot rule out critical cyber capabilities under our Preparedness Framework&#8221;; the mitigation list includes &#8220;We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra,&#8221; with monitors that &#8220;evaluate the model&#8217;s Chain of Thought and trigger a security response to review and interrupt high risk activity&#8221;; and &#8220;Astra is an upcoming model, and was not involved in exploiting Hugging Face.&#8221; The Critical threshold in the Preparedness Framework: the ability to &#8220;identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention&#8221; (body paraphrases). Both posts preserve the modal: the August 18 post&#8217;s own wording is &#8220;determined that Astra may have critical cyber capabilities&#8221; (note 25).</p><p>[27] OpenAI post (note 4), verbatim.</p><p>[28] Thomas Claburn, <a href="https://www.theregister.com/ai-and-ml/2026/08/19/openais-overhead-will-rise-20-percent-for-some-workloads-as-it-hardens-security/5289303">&#8220;OpenAI&#8217;s overhead will rise 20 percent for some workloads as it hardens security&#8221;</a>, The Register, August 19, 2026 &#8212; including the unnamed spokesperson&#8217;s statement that the costs &#8220;won&#8217;t be passed on directly to customers.&#8221;</p><p>[29] The July 2026 incident, from the primary accounts: OpenAI, <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">&#8220;OpenAI and Hugging Face partner to address security incident during model evaluation&#8221;</a>; Hugging Face, <a href="https://huggingface.co/blog/security-incident-july-2026">&#8220;Security incident disclosure &#8212; July 2026&#8221;</a> and <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">&#8220;Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident&#8221;</a>. OpenAI&#8217;s account &#8212; two models in a cybersecurity evaluation with reduced refusal training, an evaluation-sandbox escape via an Artifactory zero-day &#8212; is deliberately narrower than the &#8220;rogue models hacked Hugging Face&#8221; shorthand that circulated in some coverage, and this piece follows the narrower account.</p><p>[30] OpenAI, <a href="https://arxiv.org/abs/2503.11926">&#8220;Monitoring Reasoning Models for Misbehavior and the Risks of Promoting Obfuscation&#8221;</a>, March 2025, as quoted in the Register&#8217;s August 19 coverage (note 28).</p><p>[31] Zonghao Ying et al., <a href="https://arxiv.org/abs/2608.16393">&#8220;Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection&#8221;</a>, arXiv:2608.16393 (v1 August 17, v2 August 18, 2026); assessment materials in <a href="https://github.com/Tencent/AI-Infra-Guard/tree/main/Research/deepseek-harness-security-assessment">Tencent&#8217;s AI-Infra-Guard repository</a>. Affiliation: Tencent per the paper&#8217;s metadata (so listed on the Hugging Face papers index); Zhuque Lab per the paper body; publication inside <a href="https://github.com/Tencent/AI-Infra-Guard">Tencent&#8217;s GitHub organization</a> corroborates. The consensual Western comparator referenced in the body: OpenAI and Anthropic&#8217;s <a href="https://openai.com/index/openai-anthropic-safety-evaluation/">2025 pilot alignment-evaluation exchange</a> &#8212; reciprocal, agreed, and model-level rather than a product audit.</p><p>[32] Design: 14,560 executions = 1,120 test cases (16 injection channels &#215; 2 carrier modes &#215; 35 payload objectives) &#215; 13 attack methods including a naive baseline, against DSH commit 47f94385 (the August 13 release commit) running deepseek-v4-flash, with sensitive sinks simulated as fixtures.</p><p>[33] Full-injection success: 5.6% under the deterministic judge, 5.3% under the LLM judge; 68.4% of attempts ended in explicit refusal.</p><p>[34] Hidden Unicode payloads: 25.5% full success delivered inside files versus 0.0% for the same payload pasted as text (deterministic judge) &#8212; the paste path normalizes; the file-parsing path preserves.</p><p>[35] Skills-channel injection: 14&#8211;16% across both judges, among the highest-risk channels in the study.</p><p>[36] The fake_completion method &#8212; a planted note claiming the task is already done, redirecting the agent &#8212; reached 17.0% under the LLM judge in text mode, versus 5.7% for the unmodified baseline payload.</p><p>[37] Output corruption 35.7% versus sensitive-sink action hijack 2.5%; the paper treats these as distinct operational threat profiles. Both are lab rates &#8212; crafted adversarial payloads, simulated sinks, no adaptive attacker &#8212; conditional on an attack reaching the agent, not fleet frequencies.</p><p>[38] The assessment&#8217;s stated mitigation: sensitive sinks require independent authorization mechanisms separate from model interpretation (paraphrase of the report&#8217;s recommendation).</p><p>[39] OpenAI said in January 2025 it had evidence suggesting DeepSeek trained on distilled outputs of its models (widely reported at the time, e.g. by the Financial Times, January 29, 2025); no public resolution followed, and DeepSeek did not respond publicly to the specifics. This piece takes no position on the accusation &#8212; only on who benefits from normalized raw-trace access.</p><p>[40] &#8220;<a href="https://www.airealist.ai/p/the-verification-tax">The Verification Tax</a>,&#8221; The AI Realist &#8212; the argument that in RL with verifiable rewards, the binding cost had migrated from generating candidate solutions to verifying them.</p><p>[41] <a href="https://techcrunch.com/2026/05/27/ai-coding-startup-cognition-raises-1b-at-25b-pre-money-valuation/">TechCrunch, &#8220;AI coding startup Cognition raises $1B at $25B pre-money valuation&#8221;</a>, May 27, 2026; Bloomberg reported the talks on April 23. Priced round, pre-money basis as stated.</p><p>[42] The Integration Premium &#8212; defined in &#8220;<a href="https://www.airealist.ai/p/aws-built-its-own-ai-chip-now-it">AWS Built Its Own AI Chip. Now It Needs Someone Else&#8217;s</a>.&#8221; and extended in &#8220;<a href="https://www.airealist.ai/p/the-model-is-the-machine">The Model Is the Machine</a>&#8221; (The AI Realist): in a disaggregating stack, margin migrates from component makers to the integration layer, and the modal exit for independent specialists is absorption (Groq assets to Nvidia; the Untether team and Taalas to AMD). &#8220;Musk&#8217;s Chip Gambit&#8221; covers the acquirer&#8217;s side of this arc.</p>]]></content:encoded></item><item><title><![CDATA[The Model Is the Machine]]></title><description><![CDATA[AMD just bought a chip company whose product runs exactly one model. That is the point.]]></description><link>https://www.airealist.ai/p/the-model-is-the-machine</link><guid isPermaLink="false">https://www.airealist.ai/p/the-model-is-the-machine</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Sun, 09 Aug 2026 15:36:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rJIq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rJIq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rJIq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rJIq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2316474,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/210476886?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rJIq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rJIq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff12e7c00-587d-46a9-92a1-eb95ef66db5f_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">For sixty years, mainstream computing has run in one direction: the hardware is fixed, and the software adapts to it. On August 6, AMD paid to reverse the arrow. It signed a definitive agreement to acquire Taalas, a Toronto startup that etches a model&#8217;s weights directly into the chip&#8217;s metal, a silicon that can run only the model it was manufactured with.[1] Taalas co-founder Ljubisa Bajic, in AMD&#8217;s announcement: &#8220;We founded Taalas to rethink AI inference from the ground up by building the hardware around the model.&#8221;[1]</p><p style="text-align: justify;">In March, I wrote that the one-chip-does-everything era of AI inference ended when AWS, Nvidia, and Huawei converged on the same split: prefill on compute-bound silicon, decode on memory-bound silicon.[2][3] AMD held the middle ground: disaggregation in scheduling software, not in silicon.[2] Four and a half months later, AMD closed that ground, not with a decode chip, but with the rung below. Specialization is descending: first, the workload, when training chips split from inference chips; then the phase; now the model, and the GPU duopoly is paying for every rung of the descent.</p><h2>What AMD actually bought</h2><p style="text-align: justify;">Taalas showed working silicon this February: HC1, a 6-nanometer TSMC chip with 53 billion transistors, Meta&#8217;s Llama 3.1 8B etched into a mask-ROM fabric, and the KV cache &#8212; its working memory &#8212; in on-die SRAM.[4] No high-bandwidth memory (HBM), no advanced packaging, no liquid cooling. The company claims about 17,000 tokens per second per user, a tenth of the power of GPU serving, and a twentieth of the datacenter build cost. Vendor numbers, measured on a small model at 3-bit quantization; per-user speed is not aggregate throughput.[5]</p><p style="text-align: justify;">The prefill/decode split was a workaround for chips that must serve any model. Etch one model into the die, and the workaround dissolves: weights sit next to compute, the memory wall that made decode expensive is gone, and one chip serves both phases again, for exactly one tenant.[2]</p><p style="text-align: justify;">When the weights change, there is nothing to reprogram. You reprint: a new checkpoint of the etched architecture touches two metal layers of the roughly 100 mask layers that build the chip, a revision Taalas says TSMC turns in about 2 months, against 6 for a full design.[6] A new architecture is a different job: the fabric is shaped to the model&#8217;s dimensions, and Taalas&#8217;s own roadmap says as much. Its next model class arrives on new silicon, not as a revision of HC1.[6] The first product took 24 people, $30 million of the roughly $219 million raised, and a founding team out of Tenstorrent, AMD, and Nvidia.[7]</p><h2>The admission, priced twice</h2><p style="text-align: justify;">On December 24, Nvidia paid a reported $20 billion &#8212; its largest transaction on record, unconfirmed in any filing &#8212; for a non-exclusive license to Groq&#8217;s inference IP and roughly 90 percent of its staff. &#8220;We are not acquiring Groq as a company,&#8221; Jensen Huang told employees, oddly.[8] Twelve weeks later, the Groq 3 LPX stood on the GTC stage: an SRAM-based decode rack fused into the Vera Rubin platform, with Foxconn reportedly pulling production forward to this summer.[9]</p><p style="text-align: justify;">AMD&#8217;s pattern is the same, run twice. In June 2025, it hired away the entire team behind Untether AI, a Toronto inference-chip company whose products were promptly discontinued.[10] Taalas is AMD&#8217;s second Toronto inference-silicon absorption in fourteen months, and this time it kept the product: Taalas goes into the Instinct roadmap and the Helios racks now ramping with Anthropic, Meta, Microsoft, OpenAI, and Oracle.[1][11] Lisa Su calls herself &#8220;a big believer that there&#8217;s no one-size-fits-all as it comes to chips&#8221;; her AI chief, Vamsi Boppana, frames the acquisition as &#8220;the right compute solutions for every AI workload.&#8221;[12][1] Both lines are unremarkable until you remember what these companies sell. The two firms whose franchises are general-purpose GPUs are the ones paying &#8212; one, a reported twenty billion; the other, undisclosed &#8212; for silicon that is anything but.</p><p style="text-align: justify;">AMD would call this a portfolio, not a pivot, and the undisclosed terms suggest the hedge was probably cheap. An acquisition proves direction only when it ships. Nvidia&#8217;s shipped. AMD&#8217;s now has to.</p><h2>When the model and the machine write down together</h2><p style="text-align: justify;">Model-etched silicon matters for accounting reasons before engineering ones. In April, I wrote that the industry&#8217;s mismatch is temporal: frontier models live three to twelve months while the hardware they run on depreciates over five or six years. OpenAI shipped five versions of GPT-5 in seven months, none of which lasted four months as the flagship.[13] The gap between those schedules is where the balance-sheet fiction lives. Etching closes it in two tiers that mirror the model pipeline itself. Manufactured chips carry one checkpoint: supersede it, and that inventory is done, a two-month reprint producing the next edition. The design &#8212; the shape cast in silicon &#8212; depreciates with the architecture; adapters in SRAM absorb the fine-tune churn in between.[4][6] The chip is not a platform. It is a print run, and the press outlives the edition.</p><p style="text-align: justify;">A print run is only rational if what you are printing holds still, and the thing that must hold still is the architecture. Checkpoints are what reprints are for. Nobody etches the frontier: that tier changes every six weeks and stays on programmable silicon. The bet is the serving tier: the Llama-class workhorses and distilled variants. The demo is the evidence: the architecture Taalas etched in February 2026 is a shape Meta shipped in July 2024, and DeepSeek was still pouring new reasoning checkpoints into it six months on.[4] AMD is pricing the proposition that the volume tier of the model market has commoditized into stable shapes, and that the inference price war will be won a twentieth of a build cost at a time. The most consequential claim in this acquisition is about models, not chips.</p><p style="text-align: justify;">So the strategic question underneath the deal: whose shapes get etched? An etched fabric in AMD&#8217;s roadmap is a standard with hardware gravity. Every checkpoint that wants the economics must ship in that shape, and the compatibility war moves down a layer. The co-design precedent is already on the record: Amazon says Anthropic works with Annapurna Labs to shape next-generation Trainium, Broadcom builds Anthropic&#8217;s custom accelerators, and Anthropic already runs on Helios.[14][11] Watch for a frontier lab handing its serving workhorse to AMD&#8217;s mask shop, the model roadmap becoming a silicon roadmap.</p><h2>What would prove this wrong</h2><p style="text-align: justify;">Three tests, all observable. If all three fail, this was a talent acquisition with a good press release, Untether with better branding.</p><ol><li><p style="text-align: justify;">Taalas silicon appears in a shipping Helios configuration, or it never does. </p></li><li><p style="text-align: justify;">A hardwired, model-specific chip reaches production at a major platform by the end of 2027, or none does. </p></li><li><p style="text-align: justify;">Serving-tier architectures hold still long enough to etch, or shape turnover stays too fast, and the category dies. </p></li></ol><p style="text-align: justify;">The market-structure consequence is already on the scoreboard. Groq&#8217;s assets are inside Nvidia. Untether&#8217;s team and Taalas are inside AMD. Cerebras took the other exit, a May IPO at $185 a share.[15] Anyone pricing an independent inference-silicon position should assume the modal exit is absorption, not platform status. The category built to disrupt GPU vendors is consolidating into them, and margins migrate to whoever assembles the system.[2]</p><p style="text-align: justify;">Strip both deals to the sentence they share: the companies whose franchise is general-purpose silicon have concluded that the most valuable workload in computing no longer wants it. What they are unwinding is older than either company: the separation of software from hardware &#8212; the line that lets you sell one without the other, update one without retooling the other, write one down while the other keeps depreciating. The software industry was built on that line. Etching erases it. The model is the machine now.</p><div><hr></div><h3>Notes</h3><p>[1] AMD press release, <a href="https://newsroom.amd.com/news/amd-acquires-taalas-ai-inference/">&#8220;AMD Acquires Taalas to Advance Compute Solutions for Rapidly Growing AI Inference Market,&#8221;</a> August 6, 2026. Definitive agreement; financial terms not disclosed; closing expected Q4 2026 subject to regulatory approvals. Vamsi Boppana (SVP, AI Group): &#8220;AMD is building a full-stack AI platform that gives customers the flexibility to deploy the right compute solutions for every AI workload.&#8221; Ljubisa Bajic: &#8220;We founded Taalas to rethink AI inference from the ground up by building the hardware around the model.&#8221; The release names integration targets: the Instinct accelerator roadmap, Helios rack-scale systems, EPYC CPUs, and ROCm software.</p><p>[2] Julien Simon, <a href="https://www.airealist.ai/p/aws-built-its-own-ai-chip-now-it">&#8220;AWS Built Its Own AI Chip. Now It Needs Someone Else&#8217;s,&#8221;</a> The AI Realist, March 15, 2026. Introduces the Reasoning Tax and the Integration Premium (&#8221;in any disaggregating hardware stack, margin migrates from component manufacturers to the integration layer&#8221;); documents the three-ecosystem convergence and AMD&#8217;s middle-ground position: &#8220;The disaggregation is in scheduling, not in silicon.&#8221;</p><p>[3] Julien Simon, <a href="https://www.airealist.ai/p/acquired-absorbed-diaggregated">&#8220;Acquired, Absorbed, Disaggregated,&#8221;</a> The AI Realist, March 26, 2026. The convergence: <a href="https://www.businesswire.com/news/home/20260313406341/en/AWS-and-Cerebras-Collaboration-Aims-to-Set-a-New-Standard-for-AI-Inference-Speed-and-Performance-in-the-Cloud">AWS-Cerebras announced March 13</a>; <a href="https://investor.nvidia.com/news/press-release-details/2026/NVIDIA-Enters-Production-With-Dynamo-the-Broadly-Adopted-Inference-Operating-System-for-AI-Factories/default.aspx">Nvidia Dynamo entered production March 16</a>; Groq 3 LPX announced at GTC March 17. Huawei&#8217;s phase-split Ascend 950PR/950DT pair, announced September 2025, ships across 2026.</p><p>[4] Taalas HC1 unveiled February 2026. Specifications per <a href="https://www.heise.de/en/news/AI-inference-cast-in-silicon-Taalas-announces-HC1-chip-11185112.html">heise online</a> (February 2026) and <a href="https://www.datacenterdynamics.com/en/news/ai-chip-startup-taalas-raises-169m-unveils-hc1-processor-optimized-for-llama-31-8b/">Data Center Dynamics</a>: TSMC 6nm, approximately 53 billion transistors on an 815 mm&#178; die; model weights in a mask-ROM recall fabric using a proprietary 3-bit data format with 6-bit parameters; KV cache and fine-tuning adapters in an SRAM fabric; no HBM, no advanced packaging, no liquid cooling. The base model is fixed at manufacture. Adapter-style fine-tunes (LoRA) load into the SRAM fabric at runtime, and the context window is configurable, per <a href="https://www.cnx-software.com/2026/02/22/taalas-hc1-hardwired-llama-3-1-8b-ai-accelerator-delivers-up-to-17000-tokens-s/">CNX Software</a>; a full-parameter fine-tune &#8212; or a LoRA merged into the base weights &#8212; is a new checkpoint, which requires a mask reprint, not a load. Llama 3.1 was released by Meta in July 2024; the same 8B architecture carried DeepSeek&#8217;s <a href="https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Llama-8B">R1-Distill-Llama-8B</a> in January 2025 &#8212; checkpoints changed, the shape persisted. Meta&#8217;s own frontier direction has since turned proprietary with Muse Spark, its first release after the Superintelligence Labs reorganization, though Meta says current Llama models remain open source, per <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">VentureBeat</a>. The shape&#8217;s persistence in the serving tier does not depend on Meta&#8217;s frontier roadmap: the installed base and third-party checkpoints sustain it &#8212; if anything, a sponsor stepping back makes an etched shape more like a public instruction set than a vendor product.</p><p>[5] Vendor-published figures: approximately 17,000 tokens per second per user on Llama 3.1 8B, roughly one-tenth the power and one-twentieth the datacenter build cost of conventional GPU serving, per Taalas materials as reported by <a href="https://www.heise.de/en/news/AI-inference-cast-in-silicon-Taalas-announces-HC1-chip-11185112.html">heise</a> and <a href="https://www.theregister.com/systems/2026/08/06/amd-acquires-ai-chip-startup-taalas-to-boost-inference-performance-by-etching-models-into-silicon/5284344">The Register</a>. heise notes early independent tests reaching close to 16,000 tokens/second. Per-user token rate is a latency-side metric and does not translate directly to aggregate throughput per chip; the demonstration model is small (8B parameters) and aggressively quantized. The contrast with Cerebras is density and cost: the WSE-3 reaches on-die weights with 44 GB of SRAM across a full wafer; Taalas reaches them with mask ROM on a single 815 mm&#178; die &#8212; fixed function traded for commodity size.</p><p>[6] Company-described revision process, as reported by <a href="https://www.heise.de/en/news/AI-inference-cast-in-silicon-Taalas-announces-HC1-chip-11185112.html">heise</a>, <a href="https://www.unite.ai/amd-buys-taalas-to-put-hard-wired-ai-models-in-its-accelerator-roadmap/">Unite.AI</a>, and <a href="https://www.theregister.com/systems/2026/08/06/amd-acquires-ai-chip-startup-taalas-to-boost-inference-performance-by-etching-models-into-silicon/5284344">The Register</a>: weights occupy two metal layers of the roughly 100 mask layers used to build the chip, with TSMC turnaround of approximately two months for a two-layer revision versus approximately six for a full design. All three descriptions derive from Taalas, and none specifies whether the two-layer path covers anything beyond new weights for the etched architecture. A cross-architecture port &#8212; different dimensions, vocabulary, or attention configuration; Llama to Qwen, or 8B to 70B &#8212; changes the compute fabric itself. The Register describes re-spins for new models as significantly cheaper than starting from scratch, and Taalas&#8217;s roadmap points to new silicon for new model classes (a mid-sized reasoning model in spring, the HC2 platform &#8212; with standard 4-bit floating-point formats &#8212; by year end) rather than HC1 revisions, per <a href="https://www.heise.de/en/news/AI-inference-cast-in-silicon-Taalas-announces-HC1-chip-11185112.html">heise</a> and <a href="https://www.cnx-software.com/2026/02/22/taalas-hc1-hardwired-llama-3-1-8b-ai-accelerator-delivers-up-to-17000-tokens-s/">CNX Software</a>.</p><p>[7] <a href="https://www.datacenterdynamics.com/en/news/ai-chip-startup-taalas-raises-169m-unveils-hc1-processor-optimized-for-llama-31-8b/">Data Center Dynamics</a>, February 2026: founded August 2023 by Ljubisa Bajic (previously an architect at AMD and Nvidia; co-founder of Tenstorrent, where he swapped the CEO role with Jim Keller in October 2022 and departed in March 2023), Drago Ignjatovic, and Lejla Bajic; $169 million round announced February 2026, approximately $219 million raised in total. Investors include Quiet Capital, Fidelity, and Pierre Lamond, per <a href="https://www.unite.ai/amd-buys-taalas-to-put-hard-wired-ai-models-in-its-accelerator-roadmap/">Unite.AI</a>. Team of 24 and $30 million spent on the first product, per <a href="https://www.heise.de/en/news/AI-inference-cast-in-silicon-Taalas-announces-HC1-chip-11185112.html">heise</a>.</p><p>[8] <a href="https://www.cnbc.com/2025/12/24/nvidia-buying-ai-chip-startup-groq-for-about-20-billion-biggest-deal.html">CNBC</a>, December 24, 2025. Structured as a non-exclusive IP licensing agreement plus the hiring of approximately 90% of Groq staff; approximately $20 billion per investor sources, not confirmed by Nvidia in filings. Jensen Huang internal email obtained by CNBC: &#8220;We are not acquiring Groq as a company.&#8221; Jonathan Ross subsequently joined Nvidia as chief software architect, per <a href="https://www.forbes.com/sites/phoebeliu/2026/03/18/groq-cofounder-ross-explains-whirlwind-ai-chip-deal-with-nvidia/">Forbes</a> (March 18, 2026).</p><p>[9] Groq 3 LPX announced at GTC 2026, March 17, 2026 (see [3]). Chip produced on Samsung&#8217;s 4nm process and integrated into the Vera Rubin platform, per <a href="https://www.tomshardware.com/tech-industry/semiconductors/nvidias-20-billion-groq-deal-produces-its-first-chip">Tom&#8217;s Hardware</a>. Foxconn reportedly accelerating LPX rack production ahead of schedule, per <a href="https://wccftech.com/nvidia-35x-ai-inferencing-leap-arrives-early-foxconn-fast-fowards-groq-3-lpx-racks/">Wccftech</a> (July 2026); production timing is press-reported, not confirmed by Nvidia.</p><p>[10] <a href="https://techcrunch.com/2025/06/06/amd-acqui-hires-the-employees-behind-untether-ai/">TechCrunch</a>, June 6, 2025: AMD hired the engineering team behind Untether AI. <a href="https://www.tomshardware.com/tech-industry/amd-scoops-entire-untether-ai-chip-team-canada-ai-inference-outfit-will-cease-product-support">Tom&#8217;s Hardware</a>: Untether ceased product support. Untether AI was headquartered in Toronto and built at-memory inference accelerators.</p><p>[11] AMD, <a href="https://newsroom.amd.com/news/amd-2q-2026-earnings/">&#8220;AMD Reports Second Quarter 2026 Financial Results,&#8221;</a> August 4, 2026. Revenue $11.5 billion, up 50% year over year; Data Center segment $6.7 billion, up 107%. Helios rack-scale systems described as beginning to ramp, with deployments named for Anthropic, Meta, Microsoft, OpenAI, and Oracle; MI400-series GPUs (MI455X, MI430X) recently launched.</p><p>[12] Lisa Su, remarks at AMD&#8217;s <a href="https://ir.amd.com/news-events/press-releases/detail/1294/aai-2026-amd-delivers-full-stack-compute-for-the-agentic-ai-era">Advancing AI 2026</a> launch event (July 20, 2026, where Helios and the MI400 series debuted), as reported by <a href="https://stocktwits.com/news-articles/markets/equity/amd-buys-toronto-ai-chip-startup-taalas-retail-says-its-a-move-to-compete-more-directly-with-nvidia/cZoBg5yRJJM">Stocktwits/Yahoo Finance</a> (August 6, 2026): &#8220;a big believer that there&#8217;s no one-size-fits-all as it comes to chips,&#8221; in the context of GPUs remaining dominant for flexibility across new models. Reported speech; a primary transcript was not located, and the wording should be treated accordingly.</p><p>[13] Julien Simon, <a href="https://www.airealist.ai/p/train-deploy-write-down">&#8220;Train, Deploy, Write Down,&#8221;</a> The AI Realist, April 7, 2026. GPT-5 cadence per OpenAI release notes: five major versions between August 2025 and March 2026, none surviving longer than four months as the current flagship; hardware depreciation schedules of five to six years per hyperscaler filings.</p><p>[14] Amazon, <a href="https://www.aboutamazon.com/news/company-news/amazon-invests-additional-5-billion-anthropic-ai">&#8220;Amazon and Anthropic deepen their collaboration,&#8221;</a> April 20, 2026: &#8220;Anthropic works closely with Annapurna Labs on developing and optimizing future Trainium chips, providing direct feedback from Claude training workloads to shape next-generation chip design.&#8221; Broadcom&#8217;s fourth custom-accelerator customer was revealed as Anthropic at its Q4 FY2025 earnings, per <a href="https://www.cnbc.com/2025/12/11/broadcom-reveals-its-mystery-10-billion-customer-is-anthropic.html">CNBC</a>, December 11, 2025. Anthropic&#8217;s Helios deployment: see [11].</p><p>[15] <a href="https://www.cnbc.com/2026/05/13/cerebras-prices-ipo-above-expected-range-wall-street-expects-ai-flood.html">CNBC</a>, May 13, 2026: Cerebras priced its IPO at $185 per share, above the expected range, raising approximately $5.5 billion; trading on Nasdaq as CBRS from May 14. See also the <a href="https://www.cerebras.ai/press-release/cerebras-systems-announces-pricing-of-initial-public-offering">Cerebras pricing release</a>.</p>]]></content:encoded></item><item><title><![CDATA[From Google Brain to Google Drain]]></title><description><![CDATA[What six weeks of exits say about the model Google hasn&#8217;t shipped.]]></description><link>https://www.airealist.ai/p/from-google-brain-to-google-drain</link><guid isPermaLink="false">https://www.airealist.ai/p/from-google-brain-to-google-drain</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Wed, 05 Aug 2026 18:22:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Q-d!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Q-d!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Q-d!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Q-d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2232557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/209962444?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Q-d!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1Q-d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82789d4e-a2d0-48b1-94c1-60b42b7a6e06_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Nine months ago, Google&#8217;s redemption arc looked complete. Gemini 3 shipped in November to strong reviews, the app passed 950 million monthly users, and the Bard debacle of 2023 &#8212; the demo error that once wiped roughly $100 billion off the market cap &#8212; reads like ancient history.[1] This morning, Demis Hassabis stepped back from running Google DeepMind. Jeff Dean, Sanjay Ghemawat, Oriol Vinyals, and Quoc Le left to start a company. The stock fell five percent in early trading.[2] <strong>So the right question about today&#8217;s reorganization is not who runs DeepMind now. It is: what happened between November and August?</strong></p><p style="text-align: justify;">Start with what the departures actually are, because the &#8220;brain drain&#8221; framing undersells it. Google put three technical co-leads on Gemini in 2024: Dean, Vinyals, and Noam Shazeer &#8212; the last brought back in a roughly $2.7 billion licensing deal largely to do that job.[3] All three are gone as of this summer. Shazeer walked to OpenAI in June. Nobel laureate John Jumper left for Anthropic the same month. Dean and Vinyals left this morning.[3] </p><div class="pullquote"><p style="text-align: center;">That is not attrition at the edges of a research organization; the people running the model walked out of the building in under two months.</p></div><p style="text-align: justify;">Now read the confirmed record on the model itself. No flagship successor to Gemini 3 has shipped in nine months &#8212; not damning by itself, but conspicuous for a company that shipped its way out of the Bard hole on cadence. The trade press has reported repeated delays and an architectural rebuild of the next Gemini cycle; Google has never confirmed it, and the sourcing is too thin to lean on.[4] You don&#8217;t need it. Sundar Pichai&#8217;s own memo this morning talks about Gemini 4 &#8212; and never mentions the intermediate release the trade press spent the spring waiting for.[5] When the CEO&#8217;s letter skips straight to the next number, the cycle in between did not go well. And on July 30, six days before elevating Hassabis to focus on science, Google dissolved its Nobel-winning AlphaFold team and folded its members into Gemini, with core scientists reportedly departing for Anthropic.[6] A company long on model progress does not strip-mine its science bench to feed the product line. A company short on it does.</p><p style="text-align: justify;">Then read the destinations, because they are the closest thing the market will get to insider disclosure. Shazeer, the man with the clearest view of Google&#8217;s unreleased pipeline, chose the direct competitor: the recipe works, just not here. Dean, Ghemawat, Vinyals, and Le chose a startup whose stated mission is automating the search for new architectures &#8212; &#8220;it might be that we will discover a different transformer architecture,&#8221; Le said at launch, which is a polite way of pricing the current one.[7] Jumper and the AlphaFold core chose the rival that still funds science. Three exits, three verdicts, all rendered by people who saw the roadmap from inside. Any single move can be explained by a compensation package; the pattern of destinations cannot. </p><div class="pullquote"><p style="text-align: center;">Insiders didn&#8217;t publish model evaluations. They published destinations.</p></div><p style="text-align: justify;">Against that record, today&#8217;s reorganization reads as consequence, not strategy. Companies do not decapitate and restructure their AI leadership while the flagship is on track; they do it after the cycle breaks. The honest bull case is narrow: Koray Kavukcuoglu, a DeepMind veteran since 2012, now oversees model development, frontier research, and the Gemini product teams, unified under a single operator reporting to Pichai, replacing a three-co-lead research committee.[2] If the committee were the bottleneck, consolidation would help. If the talent was the engine, Google just watched the engine leave.</p><p style="text-align: justify;">What Google did manage brilliantly is the aftermath, and here the between-the-lines gets interesting. Pichai&#8217;s farewell contains the day&#8217;s most revealing sentence: &#8220;We&#8217;ll continue to work with them as a founding investor and Cloud partner.&#8221;[5] Regular readers know that structure from the revenue side &#8212; Nvidia into CoreWeave, Amazon into Anthropic, capital out as investment, and back as bookings.[8] Applied to headcount: Google holds equity in Discovery Loop, Google Cloud houses its compute for at least the first year, and a research team that was a consolidated expense becomes a customer with upside attached. There is even a recursive twist: if the next Gemini cycle really did stall on architecture, Google just bought a call option on the architecture search it couldn&#8217;t finish internally. Compare Meta, which faced its own misaligned scientist and handled it with a $14.3 billion hostile installation instead of a term sheet: Yann LeCun left, called his new boss &#8220;inexperienced,&#8221; and raised $1.03 billion for a competing lab with no Meta money in it.[9] </p><div class="pullquote"><p style="text-align: center;">Google&#8217;s exits produce tenants and partners; Meta&#8217;s produced a critic.</p></div><p style="text-align: justify;">But don&#8217;t mistake the elegance for an answer. The term sheet recovers salvage value from the exits; it does nothing to make Gemini competitive. Google still holds the strongest non-model position in the race: its own silicon, its own datacenters, distribution through Search and Android, and 950 million people already in the app,  which is exactly why the market took only five percent off rather than repricing the whole company.[1] The infrastructure moat buys time. It does not train the model.</p><p style="text-align: justify;">So here is the between-the-lines of August 5: Google did not announce a strategy for catching OpenAI and Anthropic this morning. It disclosed, in org-chart form, that the last one broke somewhere between November and June &#8212; and it showed that nobody in the industry finances a retreat more expertly. The elephant in the room is still there. It is just exceptionally well-financed.</p><div><hr></div><h3>Notes</h3><p>[1] Gemini 3 shipped in November 2025; <a href="https://cloud.google.com/blog/ko/products/ai-machine-learning/gemini-3-is-available-for-enterprise">Google Cloud blog</a>. The 950M+ monthly active users figure is Google&#8217;s own, from <a href="https://blog.google/company-news/inside-google/message-ceo/next-chapter-ai-momentum/">Pichai&#8217;s August 5, 2026 memo</a> &#8212; vendor-claimed, not independently verified. Bard demo error and ~$100B single-day market cap loss: February 2023, widely reported at the time.</p><p>[2] Hassabis becomes Chair of Google DeepMind and Chief Scientist of Alphabet, continuing to lead Isomorphic Labs; Kavukcuoglu becomes SVP of Google DeepMind overseeing &#8220;Gemini model development, Frontier AI research, and the Gemini app and developer teams,&#8221; reporting to Pichai. <a href="https://blog.google/company-news/inside-google/message-ceo/next-chapter-ai-momentum/">Pichai memo, ibid.</a>; <a href="https://x.com/demishassabis/status/2085034334914769203">Demis Hassabis on X</a>; <a href="https://www.axios.com/2026/08/05/google-deepmind-demis-hassabis-ai">Axios</a>. Alphabet shares fell as much as ~5% in early trading, recovering to roughly &#8722;3.5% by mid-afternoon ET: <a href="https://ca.investing.com/news/stock-market-news/alphabet-shares-fall-5-as-ai-pioneer-jeff-dean-exits-in-major-shakeup-4778533">Investing.com</a>; <a href="https://www.tradingkey.com/news/market-movers/262078737-market-movers-googl-20260805">TradingKey</a>. If publishing after the close, update to the closing print.</p><p>[3] Google appointed Noam Shazeer co-lead of Gemini in August 2024, alongside technical leads Jeff Dean and Oriol Vinyals: <a href="https://www.theinformation.com/briefings/google-makes-former-character-ai-ceo-shazeer-a-co-leader-of-gemini-ai">The Information</a>; <a href="https://tech.yahoo.com/ai/articles/google-appoints-former-character-ai-030853742.html">Reuters via Yahoo</a>. The Character.AI licensing deal that returned Shazeer to Google was reported at ~$2.7B. Shazeer to OpenAI and John Jumper (Nobel Prize in Chemistry 2024, AlphaFold) to Anthropic, both June 2026: <a href="https://fortune.com/2026/06/23/google-deepmind-ai-researcher-departures-raise-doubts-about-ability-to-win-the-ai-race-shazeer-jumper-eye-on-ai/">Fortune</a>; <a href="https://techcrunch.com/2026/06/24/ai-researchers-continue-to-leave-google-for-its-rivals/">TechCrunch</a>.</p><p>[4] Reports of three delays and a &#8220;full architectural rebuild&#8221; of the Gemini 3.5 cycle, and of Gemini 4 pre-training beginning with no announced date: <a href="https://finance.biggo.com/news/6f0c6bb2-795f-4c57-9d09-6db691d7638a">BigGo</a>; <a href="https://theairankings.com/google/gemini-3-5-pro/">The AI Rankings</a>; <a href="https://memeburn.com/google-gemini-4-training-starts/">Memeburn</a>. C-tier sourcing, unconfirmed by Google &#8212; cited here as reports only; no claim in the body rests on them.</p><p>[5] <a href="https://blog.google/company-news/inside-google/message-ceo/next-chapter-ai-momentum/">Pichai memo, August 5, 2026</a>. Full Discovery Loop sentence: &#8220;We&#8217;ll continue to work with them as a founding investor and Cloud partner, and collaborate on a research framework for ML systems and related infrastructure advances.&#8221; The memo references Gemini 4; it does not mention Gemini 3.5.</p><p>[6] Google DeepMind disbanded the AlphaFold team on July 30, 2026, redirecting members to Gemini work; core scientists reportedly moved to Anthropic. <a href="https://www.engadget.com/2225849/google-shuts-down-alphafold/">Engadget</a>; <a href="https://www.pymnts.com/google/2026/google-reshuffles-nobel-winning-deepmind-ai-team/">PYMNTS</a>.</p><p>[7] Discovery Loop: public benefit corporation co-founded by Dean, Ghemawat, Vinyals, and Le; automating the experimental loop of the scientific method, ML research first; Khosla Ventures and Radical Ventures backing, round size and Google&#8217;s stake undisclosed; Google Cloud compute for the first year. Quoc Le quote from launch coverage. <a href="https://www.unite.ai/jeff-dean-leaves-google-to-automate-the-scientific-method-with-discovery-loop/">Unite.AI</a>; <a href="https://www.cnbc.com/2026/08/05/google-chief-scientist-jeff-dean-leaving-company-after-27-years.html">CNBC</a>.</p><p>[8] See prior coverage of the round-trip structure: <a href="https://www.airealist.ai/p/welcome-to-hotel-abilene">&#8220;Welcome to Hotel Abilene&#8221;</a> and <a href="https://www.airealist.ai/p/compute-equals-commitments">&#8220;Compute Equals Commitments&#8221;</a>, The AI Realist.</p><p>[9] Meta&#8217;s investment in Scale AI, announced June 12, 2025: $14.3 billion for a 49% non-voting stake, with Scale CEO Alexandr Wang (then 28) joining to lead what became Meta Superintelligence Labs: <a href="https://www.cnbc.com/2025/06/12/scale-ai-founder-wang-announces-exit-for-meta-part-of-14-billion-deal.html">CNBC</a>. LeCun on Wang (&#8221;young,&#8221; &#8220;inexperienced&#8221;): <a href="https://the-decoder.com/you-certainly-dont-tell-a-researcher-like-me-what-to-do-says-lecun-as-he-exits-meta-for-his-own-startup/">The Decoder</a>; <a href="https://www.cnbc.com/2026/01/05/ai-godfather-calls-meta-ai-boss-alexander-wang-inexperienced-.html">CNBC</a>. AMI Labs: $1.03 billion at a reported $3.5 billion pre-money, March 2026, co-led by Cathay Innovation, Greycroft, Hiro Capital, HV Capital, and Bezos Expeditions, with Nvidia and Eric Schmidt participating; Meta absent from the reported investor list: <a href="https://techcrunch.com/2026/03/09/yann-lecuns-ami-labs-raises-1-03-billion-to-build-world-models/">TechCrunch</a>. AMI builds on the V-JEPA architecture LeCun&#8217;s team developed and open-sourced at Meta &#8212; the one asset Meta retained.</p>]]></content:encoded></item><item><title><![CDATA[You Have To Ask Me Nicely]]></title><description><![CDATA[OVH told Canada how to get the data it refused to hand over. On August 18, the European Union stops making the argument OVH is making in court.]]></description><link>https://www.airealist.ai/p/you-have-to-ask-me-nicely</link><guid isPermaLink="false">https://www.airealist.ai/p/you-have-to-ask-me-nicely</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Tue, 04 Aug 2026 17:44:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4abb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4abb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4abb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!4abb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!4abb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4abb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4abb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1394149,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/209783711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4abb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!4abb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!4abb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4abb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa67239-cd2b-4c00-a273-539026074c02_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">In January, OVHcloud said the customer records Canadian police had been demanding since 2024 &#8220;cannot be provided to the Canadian authorities,&#8221; and described the French company and its European subsidiaries as not subject to foreign extraterritorial law.[1]</p><p style="text-align: justify;">On 31 July, facing criminal charges in Ontario, the company published a statement naming the treaty channel through which those same records could be obtained, &#8220;including the data sought by Canadian authorities.&#8221; French authorities, it added, had indicated such a request would be expedited and processed &#8220;within a matter of weeks.&#8221;[2]</p><p>Same records. Same case. Six months apart.</p><p style="text-align: justify;">There is a scene in <em>A Few Good Men</em> where Tom Cruise, playing a Navy lawyer called Kaffee, asks Jack Nicholson&#8217;s Colonel Jessep for a transfer order. Jessep tells him the paperwork is his for the asking. He just has to ask nicely. Kaffee asks nicely, and Jessep hands it over, beaming. The document was never in doubt. The courtesy was, and the courtesy cost Jessep nothing, which is why he made a point of demanding it.</p><div id="youtube2-vyMggFe9WRQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;vyMggFe9WRQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/vyMggFe9WRQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>That is the argument OVH is running in Ontario. It is also, as it turns out, the argument France has been running since 1968.</p><h2>The Charge</h2><p style="text-align: justify;">The charges are real and criminal. On 31 July, OVH Groupe SA and its Montreal subsidiary H&#233;bergement OVH Inc. confirmed that Canadian authorities had charged both with failing to comply with a production order and with obstruction of justice.[3] A French company listed on Euronext Paris is being prosecuted in Ontario for declining to hand over records held in Europe. Octave Klaba said the company would defend the principle of corporate separateness with full confidence.[4]</p><p style="text-align: justify;">Readers who followed this in April know what it looks like. In April 2024, the Royal Canadian Mounted Police obtained a production order for subscriber and account data linked to four IP addresses hosted on OVH servers in France, the United Kingdom, and Australia, as part of a sealed national security investigation. In September 2025, Justice Heather Perkins-McVey held that OVH&#8217;s commercial and virtual presence in Canada brought the French parent within Canadian jurisdiction, that mutual legal assistance was permissive rather than mandatory, and that the French blocking statute was, in practical effect, an empty vessel. OVH filed for judicial review. I covered that ruling, and what it revealed about the European Commission&#8217;s cloud scoring rubric, in &#8220;<a href="https://www.airealist.ai/p/ten-percent-sovereign">Ten Percent Sovereign</a>.&#8221;[5]</p><p style="text-align: justify;">That piece asked why Brussels assigned legal sovereignty 10% of its scoring matrix. This one asks a narrower question, and the answer is less comfortable: what is the thing being weighed?</p><p><strong>Because in Ontario, OVH is not arguing that Canada cannot have the data. The argument is that Canada asked the wrong way.</strong></p><h2>The Test the Senate Set</h2><p style="text-align: justify;">Fourteen months before the charges, a French senator wrote the only sovereignty test in this story that survives contact with the law. 10 June 2025, Microsoft France&#8217;s Anton Carniaux under oath before a Senate commission of inquiry. Senator Dany Wattebled asks whether he can guarantee that French citizens&#8217; data will never be handed over without the explicit agreement of the French authorities. &#8220;Non, je ne peux pas le garantir.&#8221;[6] Wattebled did not ask where the data was stored. He asked who has to agree before it moves. Hold on to that question.</p><p style="text-align: justify;">OVHcloud made the most of that hearing. In August, chief legal officer Solange Viegas Dos Reis told The Register that Microsoft had finally told the truth, and that it was no surprise to her. Customers were shocked, she said, because they had spent years being reassured the American statute would not touch them. &#8220;It&#8217;s false! Because, indeed, the data can be communicated.&#8221;[7] Customers, she said, had started asking how it works with other providers.</p><p style="text-align: justify;">That question got an answer eleven months later, in an Ontario courtroom, and The Register saw the joke coming in November: it would be deeply ironic, it noted, if OVH could not guarantee the same thing, because the company has a subsidiary in Canada.[8] The irony is where this starts, not where it finishes. What matters is not that OVH ended up in Microsoft&#8217;s position. It is that OVH&#8217;s own legal documents had been describing that position all along.</p><p style="text-align: justify;">The CLOUD Act page published by OVH&#8217;s American entity states that the company will comply with lawful requests from public authorities, that these requests can reach data stored outside the United States, and that requests from countries without an executive agreement go through the treaty route.[9] The group&#8217;s data policy promises, when authorities come asking, to limit disclosure to what the authority requires. Limit, not refuse. The Canadian agreement spells out the drill: check that the requesting authority is competent and the request valid, turn away what is obviously neither, hand over the rest, and tell the customer.[10] It is Carniaux&#8217;s testimony, with a different flag.</p><p style="text-align: justify;">Let&#8217;s be fair to OVH, because the company has been careful and largely consistent. Its July 2025 statement distinguished OVH US, which is subject to American process for its own customers, from the French entity and its European subsidiaries, which it said are not subject to the CLOUD Act, the Patriot Act, or FISA.[11] That is accurate as far as it goes, and the FAQ&#8217;s insistence on the treaty route is the same position the company is now arguing in Ontario. Only one public statement in the whole sequence ever promised more than the contracts do, and it is the January one, which said the data cannot be provided. The July 2026 release returned the contracts to the record and added a delivery estimate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HsYL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HsYL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 424w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 848w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HsYL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:321555,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/209783711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HsYL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 424w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 848w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 1272w, https://substackcdn.com/image/fetch/$s_!HsYL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac1a0c79-3a13-481c-8bca-7b5a812d8b6a_2800x1600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">The promise that goes further belongs to the state. SecNumCloud, the French cloud doctrine that qualifies sensitive data, added legal requirements in version 3.2: European capital controls, European applicable law, and contractual immunity clauses. OVH holds it for Bare Metal Pod and said on the day it was awarded that the qualification protects against the legal risks of non-European regulation.[12]</p><p style="text-align: justify;">Read the requirements narrowly, and they aim at third-country law, which is a fair reading and probably ANSSI&#8217;s. But nobody buying on that basis was distinguishing an American injunction from a European one. They heard that their data could not be taken without French agreement. Wattebled asked his question about an American injunction; <strong>the interesting version now is the one he had no reason to ask. Can a qualified French provider guarantee that customer data will never be transmitted to any foreign authority without the explicit agreement of the French authorities?</strong></p><p>Until August 18, more or less. After that, for the most commonly demanded category of data, no. And the reason has nothing to do with American law.</p><h2>What the Guarantee Says</h2><p style="text-align: justify;">Start with what the explicit agreement of the French authorities consists of, because the French state has described it, on the record, in this case.</p><p style="text-align: justify;">In December 2025, Deputy Bastien Lachaud put a written question to the economy ministry: what would the government do to stop a foreign authority seizing data hosted on French soil? The reply was published in the Journal Officiel on 3 March 2026.[13]</p><p style="text-align: justify;">The government declined to comment on foreign proceedings, then explained the law it relies on. Established in 1968, the blocking statute has two limbs. The first forbids handing a foreign authority anything touching French security, sovereignty, public order, or essential economic interests. The second, added in 1980, is the one at issue here, and it does something else. It exists to make sure that requests for evidence &#8220;empruntent bien les canaux et trait&#233;s applicables,&#8221; that they take the applicable channels and treaties. Which channel, the ministry adds, means the 2001 Budapest Convention on cybercrime.</p><p>That second limb does not forbid disclosure. It governs which door the request comes through, and Paris says so in its own words, in the Journal Officiel, about this case.</p><p style="text-align: justify;">The enforcement apparatus matches the ambition. A desk at Bercy, the SISSE, issues opinions on whether the 1968 law applies to a particular demand. The opinion is addressed to the French company that asked, which is expected to forward it to the foreign authority so that the authority can learn the formal French position. If that proves insufficient, the desk can ask a liaison magistrate to raise awareness of the law abroad or open a diplomatic channel. The ministry notes that the desk is working to become better known. That is the protection. Advisory opinions, forwarded onward, backed by a liaison magistrate and a phone call.</p><p style="text-align: justify;">An Ontario court weighed it all and did not detain long. One conviction has ever been reported under that second limb, in the forty-six years since it was enacted. Expert witnesses could point to no case anywhere in which a foreign court had respected the statute. Perkins-McVey borrowed the English High Court&#8217;s verdict on it: an empty vessel.[14] An Ontario court had already brushed past French blocking provisions in a civil case twenty-five years earlier.[15]</p><p style="text-align: justify;">So the French and Canadian positions sit closer together than the diplomatic temperature suggests. France says the data is available through the treaty. Canada says the treaty is optional. <strong>Nobody in the case says the data is unreachable, and the company holding it has now confirmed in writing that it is not.</strong></p><h2>The Third Door</h2><p style="text-align: justify;">Both sides of this dispute point at the same door. OVH calls it mutual legal assistance; the French government, answering Lachaud, names the treaty behind the phrase, the Budapest Convention on cybercrime. It dates from 2001, runs state to state through central authorities, and every party to this case concedes it is slow. In 2022, the Council of Europe adopted a protocol that allows authorities in one country to directly request subscriber information from a provider in another country, which is the category the RCMP requested.[16]</p><p style="text-align: justify;">France signed it, and three weeks later, Brussels told member states to ratify. Canada signed it in June. Neither has been ratified, and 52 signatures have produced 4 ratifications, 1 short of the 5 required to bring it into force.[17] Both governments agreed that the door should exist. Neither built it. One of them then walked through the wall and is now prosecuting the company that was standing in front of it.</p><p style="text-align: justify;">OVH is not the first provider to stake everything on the treaty route. Microsoft made the same argument for emails stored on a Dublin server and won it at the Second Circuit in 2016. Twenty months later, Congress legislated the win away with the CLOUD Act; the full story is in &#8220;<a href="https://www.airealist.ai/p/two-sovereign-clouds-one-legal-wall">Two Sovereign Clouds</a>.&#8221;[18] European sovereignty marketing was built on the wreckage of that case, and it was built against a single statute. Every &#8220;not subject to the CLOUD Act&#8221; claim answers the American door. Canada has now opened a second door through its courts. The European Union spent five years building a third, and that one opens on August 18. It opens on OVH, too.</p><p style="text-align: justify;">On August 18, 2026, the European Union&#8217;s e-Evidence Regulation becomes applicable. It creates the European Production Order: <strong>an authority in one member state can compel a provider established in another to hand over electronic evidence directly, with no state-to-state procedure in between</strong>. The Commission&#8217;s own summary gives the aim as speeding up access &#8220;regardless of where the data is located,&#8221; and lists subscriber data and the IP addresses needed to identify a user among the categories covered.[19]</p><p style="text-align: justify;">Ten days to comply. Eight hours in an emergency. Penalties of up to two percent of worldwide annual turnover for providers that do not.[20]</p><p style="text-align: justify;">Now, the detail that decides the argument. Ask for the contents of messages, and a judge has to sign; the country where the provider sits is told, and it has ten days to object, or ninety-six hours if the case is urgent. <strong>Ask for subscriber records, or for the address that identifies whoever was behind an account, and neither applies. No judge required. Nobody told.</strong>[21] The notification shrinks further from there, disappearing even for message content when the offense and the suspect both sit in the requesting country, which describes most investigations.[22] Subscriber records also sit at the bottom of the instrument&#8217;s threshold: an order may issue for any criminal offense, where traffic and content require offenses carrying at least three years.[22]</p><p style="text-align: justify;">Put the pieces together and imagine the file. A prosecutor in Dublin opens an investigation into a customer of a French host. After August 18, she can send a certificate to that host&#8217;s designated establishment, requiring the subscriber records within ten days for any criminal offense, without any judge required by the Regulation, and without anyone in Paris being told it happened. The SISSE desk cannot issue an opinion on a demand it is unaware of. The liaison magistrate has nobody to call.</p><p style="text-align: justify;">Dublin is the deliberate choice. The argument does not need a member state with a rule-of-law problem, and reaching for one would let the reader file this under judicial standards rather than sovereignty. Ireland is the jurisdiction European data policy treats as the safe pair of hands, and the guarantee fails against Ireland just as it does against anyone else, because notification does not take reputation into account. It simply is not there.</p><p style="text-align: justify;">That certificate is Wattebled&#8217;s question served under a different flag, and from August 18, no French provider can answer it any better than Carniaux did. No, I cannot guarantee it. The reason is a European regulation, not an American one.</p><h2>And Then Where?</h2><p style="text-align: justify;">The Regulation governs how a member state gets the data and says nothing about what it may do with it afterward. Onward transfer to a third country falls under the general law enforcement data regime, which permits it on the basis of adequacy, safeguards, or a list of derogations. The European Union and the United States have had a law enforcement transfer agreement since 2016.[23] Whether the records are then transferred from the police file to an intelligence file is not a European question at all. National security is reserved for the member states by the founding treaties, and several of them have run multilateral signals intelligence arrangements with Washington for decades. So the records can be compelled by Dublin without Paris knowing, and travel onward under a framework in which Paris has no standing, because Paris was never told there was a file.</p><h2>What Was Sold</h2><p style="text-align: justify;">Compare all that with what France told its own parliament it was defending. Transfers to a third state, the question ran, can go through a derogation procedure supervised by French authorities, and Canada&#8217;s refusal to seek prior French control ran against the principles of digital sovereignty.[24] Whatever one thinks of Ottawa, the RCMP had to litigate for two years and lay criminal charges to reach a place an Irish prosecutor will reach in ten days with a form.</p><p style="text-align: justify;">The objection to all this is good and deserves to be stated in full. A European Production Order is not a Canadian one wearing a European flag. It runs between states bound by a common rights floor, carries refusal grounds and remedies, obliges the issuing authority to notify the person whose data was taken, and allows the provider to pull the enforcing state back in. A Canadian order carries none of that. Anyone who tells you the two are equivalent is selling something. And none of it has happened yet: no European Production Order has ever been issued, and how prosecutors use the instrument is a fact about the future.</p><p style="text-align: justify;">But equivalence was never the claim. What was sold to European cloud buyers was reach, not safeguards. Data resident in France is beyond the reach of authorities outside France, as obtaining it requires the consent of French authorities. From August 18 onward, for the most commonly requested category of data, French consent is not part of the design. What survives is the claim that some requesting states are better than others, an argument about who belongs to which club. In the transatlantic context, that argument has already collapsed twice, under the names Safe Harbor and Privacy Shield.</p><h2>The Channel Test</h2><p>Everything above turns Wattebled&#8217;s question into something portable, and it replaces the question most buyers ask.</p><p style="text-align: justify;">Data residency is the wrong question. It tells you where the disk is. It tells you nothing about who can compel the disk. Three questions do the work instead.</p><p style="text-align: justify;"><strong>Who has to sign?</strong> Name the authority, not the country. &#8220;Hosted in France&#8221; is not an answer. &#8220;A French investigating magistrate, acting on a letter rogatory transmitted through the central authority, after a SISSE opinion on whether the 1968 law even applies,&#8221; is an answer. Say it out loud and count the links. Every one of them is a place where a foreign state can be told no, and every one of them is a place where a foreign state can be told yes.</p><p style="text-align: justify;"><strong>How long does that take?</strong> Not the statutory deadline. The observed time. If the provider has published a figure, use theirs. OVH published its own, and it&#8217;s weeks.</p><p style="text-align: justify;"><strong>Has that authority ever said no?</strong> This is the question that separates a wall from a queue, and it is the one nobody asks, because it is answered by enforcement history rather than by statutory text. France publishes no refusal statistics for assistance requests, and none surfaced in this case. That does not prove Paris has never refused. It proves you cannot find out, which, for a buyer, is the operative fact. What the record shows is what happens to those who rely on the wall: one conviction under the blocking statute since 1980, and no foreign court has ever recognized it.</p><p style="text-align: justify;">Run the test against any sovereign offering, European or otherwise. If the third question has no documented refusal, the product is sold with a delay and a review step. Delay has value. Investigations that are delayed all the time, and a review step counts for something. It just isn&#8217;t the thing the marketing describes.</p><p style="text-align: justify;">Does anything pass? For subscriber data after the 18th, nothing European does, and that is the useful finding. Residual exposure to a direct foreign order becomes roughly uniform across every provider with an establishment in the Union, qualified or not. The sovereignty premium still buys real things: a European supply chain, an operator outside American discovery, a stack you can audit, a government that answers to your parliament. What it no longer buys, for the most commonly demanded category of data, is the thing on the label. Price it accordingly.</p><h2>What Would Break This</h2><p>The whole argument turns on one thing, and it is checkable.</p><p style="text-align: justify;">France has to refuse. If Canada files the request the way OVH says it should, and Paris declines it, or sits on it long enough that the investigation dies, then the French review step is a real gate, and I have this wrong. The guarantee would be a wall after all, and a slow one, which is what a wall is.</p><p style="text-align: justify;">Two lesser tests. If the Ontario Superior Court quashes the production order on territorial grounds instead of procedural ones, the Canadian doctrine narrows and stops traveling; as of publication, no ruling on the judicial review has been reported.[25] And if any member state publicly refuses to execute a European Production Order on sovereignty grounds after 18 August, the intra-EU channel will have its own gate.</p><p style="text-align: justify;">In the meantime, there is work to do that costs nothing. Stop asking vendors where the data lives, which every vendor can answer, and ask the three questions, which most cannot. Get the answers in writing, dated, and in the contract file. Then run the same three against the SecNumCloud qualifications, the Cloud de Confiance arrangements, and the SEAL tiers in the Commission&#8217;s framework. None of them scored on the third question, because none of them asked it.</p><p style="text-align: justify;">Three more for the provider itself. Which legal entity, in which member state, is its designated establishment for European Production Orders, because that choice decides whose prosecutors reach you fastest? Where is its law enforcement transparency report, broken down by requesting jurisdiction and outcome, because that document is the only place question three can ever be answered. And what survives once the data has left its hands? There's no good answer, because nothing does. Watch how long it takes for the transparency report to be released.</p><p>Jessep could have refused Kaffee outright. He never meant to. He wanted the courtesy first because it was free, and because demanding it let him keep the form of authority while handing over the substance. That was the arrangement Roubaix and Bercy were selling, and buyers paid a premium for it in good faith.</p><p>From August 18, nobody has to ask, nicely or not. European data sovereignty was never a wall. It was a rule of manners, and manners are optional now.</p><div><hr></div><h3>Notes</h3><p>[1] OVHcloud statement to The Register, added to its report on 26 January 2026: &#8220;OVHcloud&#8217;s number one concern and priority is to protect its customers&#8217; data. This is why this data cannot be provided to the Canadian authorities.&#8221; The same statement describes the group as &#8220;a multi-local player that is not subject to extraterritorial laws.&#8221; See <a href="https://www.theregister.com/2025/11/27/canada_court_ovh/">The Register&#8217;s report of 27 November 2025</a>, to which the statement was added in an update dated 26 January 2026; the quoted wording now appears in the body of that continuously updated report. The statement was given to that publication and is not corroborated by an OVH-published document.</p><p>[2] OVH Groupe SA, &#8220;<a href="https://blog.ovhcloud.com/en/posts/ovhcloud-contests-canadian-production-order-charges/">OVHcloud Confirms Intent to Vigorously Contest Charges Related to Canadian Production Order</a>,&#8221; 31 July 2026. Direct quotation.</p><p>[3] Same release. Charges are for failure to comply with a production order under section 487.0198 of the Criminal Code of Canada and obstruction of justice under section 139(2); the underlying production order was issued on 19 April 2024 under section 487.014. Section 487.0198 creates a summary conviction offence for contravening an order made under sections 487.013 to 487.018; section 139(2) is the general obstruction offence and is indictable.</p><p>[4] Same release, quoting Octave Klaba, founder, chairman and chief executive officer. Klaba resumed the CEO role on 20 October 2025, when the board reunited the chairman and CEO functions, ending Benjamin Revcolevschi&#8217;s one-year tenure (<a href="https://corporate.ovhcloud.com/en/newsroom/news/octave-klaba-chairman-ceo/">OVHcloud corporate release, 21 October 2025</a>).</p><p>[5] <em>R. v. OVH Group SA and H&#233;bergement OVH Inc.</em>, Ontario Court of Justice (Ottawa), Court File 24-000659, Perkins-McVey J., decision released 25 September 2025. <a href="https://drive.google.com/file/d/1QVwO9lPmxuDSQsGd9fHH3QN_ToXs2LQ8/view">Signed decision</a> via David Fraser, McInnes Cooper. Julien Simon, &#8220;<a href="https://www.airealist.ai/p/ten-percent-sovereign">Ten Percent Sovereign</a>,&#8221; The AI Realist, 22 April 2026, which covers the ruling, the virtual presence line of authority across four provinces, and the European Commission&#8217;s Cloud Sovereignty Framework in full.</p><p>[6] S&#233;nat, commission d&#8217;enqu&#234;te sur la commande publique, <a href="https://www.senat.fr/compte-rendu-commissions/20250609/ce_commande_publique.html">compte rendu of the hearing of 10 June 2025</a>. Verbatim. Full analysis of the hearing, the statutory chain and the attribution of the question (Wattebled, per the official transcript, though some press reports credited commission president Simon Uzenat) in Julien Simon, &#8220;<a href="https://www.airealist.ai/p/two-sovereign-clouds-one-legal-wall">Two Sovereign Clouds, One Legal Wall</a>,&#8221; The AI Realist, 26 February 2026. Carniaux has since left Microsoft France.</p><p>[7] Solange Viegas Dos Reis, chief legal officer, OVHcloud, interviewed in &#8220;<a href="https://www.theregister.com/2025/08/27/ovhcloud_interview/">Microsoft can&#8217;t guarantee data sovereignty &#8211; OVHcloud says &#8216;We told you so&#8217;</a>,&#8221; The Register, 27 August 2025. Direct quotations.</p><p>[8] <a href="https://www.theregister.com/2025/11/27/canada_court_ovh/">The Register, 27 November 2025</a>, per note 1.</p><p>[9] OVH US, &#8220;<a href="https://us.ovhcloud.com/legal/faqs/cloud-act/">Cloud Act &#8211; Clarifying Lawful Overseas Use of Data</a>,&#8221; accessed August 2026. This page belongs to the group&#8217;s American entity, which is subject to American process; it is cited here for what the group publishes about its own compliance posture, not as a statement about the French entity. The page was quoted against OVH by AWS in July 2025, a conflation of entities this piece does not repeat. I quoted the same FAQ language in &#8220;<a href="https://julsimon.medium.com/the-sovereignty-mirage-why-european-clouds-wont-save-your-data-a565e82127f5">The Sovereignty Mirage</a>&#8220; in December 2025, eight months before the charges.</p><p>[10] OVHcloud, &#8220;<a href="https://www.ovhcloud.com/en/terms-and-conditions/privacy-policy/">Personal data usage policy</a>,&#8221; accessed August 2026, on requests from judicial, administrative or other authorities. Procedure at clause 4.2 of the <a href="https://storage.gra.cloud.ovh.net/v1/AUTH_325716a587c64897acbef9a4a4726e38/contracts/d54e222-OVH_Data_Protection_Agreement-CA-1.0.pdf">Personal Information Protection Agreement</a> applicable to Canadian clients, version dated 6 September 2023. Clause 4.3 addresses requests originating from an authority outside Canadian jurisdiction concerning a Canadian client.</p><p>[11] OVH statement to <a href="https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/">The Register, July 2025</a>: &#8220;OVH Group abides by local laws in the countries it operates in. As such, OVH US may be subject to requests from American authorities within the framework of the Cloud Act as long as these demands are connected to customers of OVH US and are strictly compliant with applicable American law. The French OVH entity (or its European subsidiaries) is not subject to the Cloud Act, the Patriot Act or the FISA.&#8221;</p><p>[12] ANSSI, SecNumCloud requirements repository version 3.2 (March 2022), which added criteria protecting against non-European law: capital control by European entities, exclusive application of European law, and contractual immunity provisions. The qualification comprises more than 360 technical, organisational and legal requirements. ANSSI&#8217;s qualification decision for OVHcloud&#8217;s Bare Metal Pod was published on 24 March 2025; OVHcloud announced it on <a href="https://corporate.ovhcloud.com/en/newsroom/news/secnumcloud-qualification-bare-metal-pod/">31 March 2025</a>, stating that the qualification &#8220;acts as another form of protection against the legal risks linked to non-European regulations.&#8221; Note that these are structural and contractual requirements rather than a bar on lawful compulsion, a distinction this piece turns on. On what the Commission&#8217;s SEAL ladder does and does not score, see &#8220;<a href="https://www.airealist.ai/p/ten-percent-sovereign">Ten Percent Sovereign</a>&#8220;; on the architectural cost of the qualification, &#8220;<a href="https://www.airealist.ai/p/more-sovereign-different-stack-the-builder-tax">More Sovereign, Different Stack: The Builder Tax</a>.&#8221;</p><p>[13] Assembl&#233;e nationale, <a href="https://questions.assemblee-nationale.fr/q17/17-11534QE.htm">question &#233;crite n&#176; 11534</a>, M. Bastien Lachaud, published in the Journal Officiel of 9 December 2025, p. 9993; answer from the ministry for artificial intelligence and digital affairs published in the Journal Officiel of 3 March 2026, p. 1907. All quotations in this section are from the answer. Loi n&#176; 68-678 of 26 July 1968; Article 1 bis added by Loi n&#176; 80-538 of 16 July 1980; D&#233;cret n&#176; 2022-207 of 18 February 2022 establishing the SISSE opinion procedure. Penalties per the answer: six months&#8217; imprisonment and a fine of &#8364;18,000, and for legal persons a fine of &#8364;90,000.</p><p>[14] <a href="https://drive.google.com/file/d/1QVwO9lPmxuDSQsGd9fHH3QN_ToXs2LQ8/view">Ruling</a> at paragraphs 79 to 123, adopted at paragraph 115. &#8220;Empty vessel&#8221; from Butcher J in <em>Tugushev v. Orlov</em>, [2021] EWHC 1514 (Comm), handed down 28 May 2021, at paragraph 33, applied to Loi 68-678 by Cockerill J in <em><a href="https://caselaw.nationalarchives.gov.uk/ewhc/kb/2024/1424">Joshua &amp; Ors v. Renault SA &amp; Ors</a></em>, [2024] EWHC 1424 (KB), 11 June 2024, at paragraphs 77 to 78. The test as stated there is whether the foreign criminal law relied on is &#8220;not merely a text, or an empty vessel, but is regularly enforced.&#8221; The single reported Article 1 bis conviction is the &#8220;Christopher X&#8221; case, Cour de cassation, chambre criminelle, 12 December 2007, pourvoi n&#176; 07-83.228, discussed at paragraph 85.</p><p>[15] <em><a href="https://www.canlii.org/en/on/onsc/doc/2000/2000canlii22407/2000canlii22407.html">Wilson v. Servier Canada Inc.</a></em>, 2000 CanLII 22407 (ON SC), 50 O.R. (3d) 219 (Cumming J.), cited at ruling paragraph 95. A civil class action involving a French parent, not a criminal production order, and turning on Article 15 of the French Civil Code rather than Loi 68-678. Cited here for the Canadian judicial posture the OVH ruling drew on, not as precedent on the blocking statute.</p><p>[16] Council of Europe, <a href="https://www.coe.int/en/web/cybercrime/second-additional-protocol">Second Additional Protocol to the Convention on Cybercrime on enhanced co-operation and disclosure of electronic evidence</a> (CETS No. 224), adopted 17 November 2021, opened for signature 12 May 2022. Article 7 provides a legal basis for direct co-operation with service providers in another Party&#8217;s territory to obtain subscriber information, subject to reservations and declarations available to Parties.</p><p>[17] France signed on 27 January 2023, the thirty-second state to do so, alongside Germany: Council of Europe, &#8220;<a href="https://www.coe.int/fr/web/cybercrime/-/france-and-germany-become-32nd-and-33rd-states-to-sign-the-second-additional-protocol-to-the-convention-on-cybercrime">France and Germany become 32nd and 33rd states to sign the Second Additional Protocol</a>,&#8221; 27 January 2023. <a href="http://data.europa.eu/eli/dec/2023/436/oj/eng">Council Decision (EU) 2023/436</a> of 14 February 2023 authorised Member States to ratify the Protocol in the interest of the European Union (OJ L 63, 28.2.2023, pp. 48-53); signature had been authorised by Council Decision (EU) 2022/722 of 5 April 2022. Canada signed on 20 June 2023, the thirty-eighth state, per the <a href="https://www.coe.int/en/web/cybercrime/second-additional-protocol">Second Additional Protocol news archive</a>; its justice department has consulted publicly on whether to ratify and on whether to reserve against Article 7, and no instrument of ratification has been deposited. Signature count as of the Council of Europe&#8217;s most recent published tally; ratifications: Serbia first, <a href="https://www.coe.int/en/web/cybercrime/-/japan-becomes-2nd-state-to-ratify-the-second-additional-protocol-to-the-convention-on-cybercrime">Japan second on 10 August 2023</a>, the announcement of which confirms that five ratifications are required for entry into force, Hungary third on 5 February 2026, Costa Rica fourth on 15 April 2026. Entry into force falls on the first day of the month following three full months after the fifth ratification. Verified as of 15 April 2026.</p><p>[18] <em>United States v. Microsoft Corp.</em> The warrant was issued in 2013 for content stored in Microsoft&#8217;s Dublin facility; the Second Circuit held in 2016 that the Stored Communications Act did not reach it; the CLOUD Act was enacted in March 2018 and the Supreme Court dismissed the case as moot. The compelled disclosure provision is codified at 18 U.S.C. &#167; 2713. The full trace of the statutory chain is in &#8220;<a href="https://www.airealist.ai/p/two-sovereign-clouds-one-legal-wall">Two Sovereign Clouds, One Legal Wall</a>.&#8221; Other jurisdictions assert comparable reach; the count here is of the doors this case walks through.</p><p>[19] European Commission, <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=LEGISSUM:4649186">summary of Regulation (EU) 2023/1543</a> on European Production and Preservation Orders for electronic evidence in criminal proceedings. Full text at <a href="http://data.europa.eu/eli/reg/2023/1543/oj/eng">OJ L 191, 28.7.2023, pp. 118&#8211;180</a>. Application from 18 August 2026. The Regulation binds all member states except Denmark, which is not bound by reason of its opt-out in the area of freedom, security and justice.</p><p>[20] <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=LEGISSUM:4649186">Same summary</a>. Ten days for transmission of requested data, eight hours in emergencies, ten days for the enforcing authority to raise a refusal ground where notification applies, reduced to ninety-six hours in emergency cases, and pecuniary penalties of up to two percent of a provider&#8217;s total worldwide annual turnover.</p><p>[21] <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=LEGISSUM:4649186">Same summary</a>: &#8220;If the electronic evidence includes content data or traffic data, except for data requested for the sole purpose of identifying the user, a court or judge must issue or review the order, and the judicial authority must notify the competent authority of the Member State in which the designated establishment is located, or the legal representative resides.&#8221; How the Regulation interacts with Loi 68-678 is untested; no French court has ruled on whether a European Production Order satisfies the applicable-channels requirement of Article 1 bis, though a directly applicable EU regulation is the stronger reading.</p><p>[22] Thresholds per eucrim, &#8220;<a href="https://eucrim.eu/news/e-evidence-regulation-and-directive-published/">E-evidence Regulation and Directive Published</a>&#8220;: subscriber and identification data for all criminal offences and for execution of custodial sentences of at least four months; traffic and content for offences carrying a maximum of at least three years, or listed offences committed by means of an information system. On notification, Jessica Shurson, &#8220;<a href="https://journals.sagepub.com/doi/10.1177/20322844251357090">The balance of efficiency and fundamental rights in the EU e-Evidence Regulation</a>,&#8221; <em>New Journal of European Criminal Law</em>, 2025, on Article 8(2) and the consequence that in most domestic cases the enforcing state receives no notice. See also Athina Sachoulidou, &#8220;<a href="https://journals.sagepub.com/doi/10.1177/20322844241258649">Cross-border access to electronic evidence in criminal matters</a>,&#8221; <em>New Journal of European Criminal Law</em>, 2024, and <a href="https://eucrim.eu/articles/critical-issues-in-the-new-eu-regulation-on-electronic-evidence-in-criminal-proceedings/">eucrim, &#8220;Critical Issues in the New EU Regulation on Electronic Evidence in Criminal Proceedings&#8221;</a>, on the exclusion of subscriber data from the notification requirement.</p><p>[23] Regulation (EU) 2023/1543 contains no onward-transfer provision of its own; it refers to Chapter V of <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016L0680">Directive (EU) 2016/680</a> only in the context of conflicting third-country obligations (Article 17(7)). Transfers of law enforcement data to third countries are governed by Articles 35 to 38 of that Directive, permitting transfer on an adequacy decision, appropriate safeguards, or derogations for specific situations. The EU-US Umbrella Agreement of 2016 provides the standing framework for law enforcement transfers to the United States. Processing for national security purposes falls outside Union competence under Article 4(2) of the Treaty on European Union and outside the Directive&#8217;s scope; arrangements between national intelligence services are governed by national law and by bilateral or multilateral agreements that are not published. This paragraph describes the legal architecture, not any known transfer of the data at issue in this case.</p><p>[24] Assembl&#233;e nationale, <a href="https://questions.assemblee-nationale.fr/q17/17-11534QE.htm">question &#233;crite n&#176; 11534</a>. The description of the derogation procedure and of the Canadian position appears in the question as put by the deputy; the ministry&#8217;s answer sets out the SISSE opinion procedure and reaffirms the government&#8217;s opposition to any circumvention of applicable co-operation channels and treaties.</p><p>[25] OVH filed for judicial review to the Ontario Superior Court of Justice through Miller Thomson at the end of October 2025, per <a href="https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-France-must-hand-over-user-data-11092029.html">heise online, 26 November 2025</a>, which also reports from the court filings that the data has been preserved and that the French Ministry of Justice offered accelerated processing by letter rogatory. No decision on the judicial review had been reported at the time of writing.</p>]]></content:encoded></item><item><title><![CDATA[Amazon Priced the Frontier and Declined It]]></title><description><![CDATA[On 30 June, AWS published two announcements pointing in opposite directions. In July, it closed its AGI Lab. All three were the same decision.]]></description><link>https://www.airealist.ai/p/amazon-priced-the-frontier-and-declined</link><guid isPermaLink="false">https://www.airealist.ai/p/amazon-priced-the-frontier-and-declined</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Wed, 29 Jul 2026 12:01:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tqju!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tqju!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tqju!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tqju!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tqju!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tqju!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tqju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg" width="1024" height="541" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:541,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66196,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/208959210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tqju!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tqju!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tqju!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tqju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15837b4f-cb90-4909-a92f-f00bb5ffc039_1024x541.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">On  June 30, AWS announced a billion-dollar investment in a new Forward Deployed Engineering organization.[1] The plan embeds engineers in customer companies in pods of five or six for roughly 45-day engagements, building agentic systems using the customer&#8217;s own data and leaving the customer self-sufficient when the pod withdraws.[2] AWS called the pods &#8220;frontier teams&#8221; and noted that many of the engineers had built their own AI services.</p><p style="text-align: justify;">The same day, AWS published a service availability page announcing the retirement of roughly 20 services and features.[3] Amazon Kendra, Amazon Q Business, and Amazon Bedrock Agents will enter maintenance and be closed to new customers from 30 July.[4][5][6] Ten SageMaker AI features went with them.</p><p style="text-align: justify;">One announcement spends a billion dollars putting AWS engineers inside customer businesses. The other withdraws the products that those customers were meant to use. Three weeks later, Amazon confirmed it was closing its San Francisco AGI Lab and cutting roles across its artificial general intelligence organization.[7][8]</p><p style="text-align: justify;">Read separately, these are a product cull, a spending initiative, and a research retreat. Read together, on the calendar they occupy, they are one decision about which layer of the artificial intelligence business Amazon intends to own.</p><h2>Three vectors and one direction</h2><p style="text-align: justify;">Amazon is spending at the bottom of the stack and at the top, and withdrawing from everything in between.</p><p style="text-align: justify;"><strong>Downward, into the fabric</strong>. Andy Jassy told investors in February that Amazon expected roughly $200bn of capital expenditure in 2026, predominantly in AWS, pointing to what the results release called &#8220;seminal opportunities&#8221; in AI, chips, robotics, and satellites.[9] Project Rainier went live with nearly half a million Trainium2 chips across multiple United States sites and a stated path beyond a million.[10] Trainium3 sits behind it.[11] This is the only layer Amazon is attempting to own outright, and the only one where it is building rather than buying the alternative.</p><p style="text-align: justify;"><strong>Outward, for the intelligence</strong>. Anthropic supplies the frontier under a commitment of more than $100bn over 10 years and up to 5 gigawatts of capacity, powered by Amazon&#8217;s own silicon.[12] The equity position produced $16.8bn in pre-tax gains in the first quarter of 2026, while the AWS segment grew 28% in the same quarter and carries more than $15bn in annualized AI services revenue.[13] That gain is a non-cash mark on a private company&#8217;s valuation, booked through non-operating income, and it reverses if Anthropic&#8217;s next round prices flat or down. Bank of America estimates that Anthropic-related workloads alone could contribute more than $1.5bn in sequential AWS revenue growth in the second quarter.[14] That is an analyst estimate, not a disclosure, and if it is near right, it describes customer concentration as much as momentum. One fact is observable: Claude&#8217;s per-token rates on Bedrock match Anthropic&#8217;s own API to the cent.[15] AWS doesn&#8217;t mark Claude up. Its margin is whatever sits between retail and the undisclosed remittance, plus everything a production workload consumes besides the model, and that second meter is the one no model provider can take away.</p><p style="text-align: justify;">The arithmetic explains the rest of the strategy. A frontier laboratory is a capital sink competing for the same engineers, accelerators, and megawatts as a business already growing at 28%, with a winner-take-most payoff. Instead, equity plus a supply contract does three jobs at once: it secures the output, it locks the supplier&#8217;s training and serving onto Amazon&#8217;s silicon for a decade, and it books the upside as investment gains, not research cost. The capacity remains full, and the income statement shows a research organization rather than a frontier-scale training program, a difference measured in tens of billions.</p><p style="text-align: justify;"><strong>Forward, to the customer</strong>. The $1 billion announced on 30 June goes to engineers who sit inside the customer&#8217;s building. Francessca Vasquez, the AWS vice president who runs the organization, framed the pitch around speed, and the named early customers include the Allen Institute, Cox Automotive, the NBA, the NFL, Ricoh, and Southwest Airlines.[1][2] Amazon is late to this: Palantir has run forward-deployed engineering for over a decade, and Salesforce, Google Cloud, and Anthropic all offer similar versions.[16]</p><p style="text-align: justify;">Look at what that vector costs. Embedded engineering carries service margins, and a company that spent twenty years teaching investors to value self-service software economics is putting a billion dollars into headcount that does not scale like software. Firms accept that when the customer won&#8217;t reach production without it, and the consumption on the other side outweighs the margin surrendered. The forty-five-day cycle and the insistence on leaving customers self-sufficient are the tell: these pods are a customer acquisition cost, not a consulting line.</p><p style="text-align: justify;">AWS frames the initiative as customer obsession, and on its own terms, it is. It is also, on Amazon&#8217;s terms, consumption: the pods deploy onto Bedrock and the surrounding services, and the annuity AWS is buying is the meter running after the engineers leave. And this survives the test that killed the software. An embedded engineer holds the one input that tooling shipping with the model can&#8217;t replicate: the customer&#8217;s own context. That&#8217;s why AWS is paying people margins for a function whose software equivalent it just retired.</p><p style="text-align: justify;">What sits between the fabric and the customer is the part Amazon is vacating: its own frontier models, its own retrieval, agent, and assistant products, and the tooling a customer would use to build models themselves. Amazon has concluded that owning intelligence is a worse business than metering it, and it&#8217;s paying to occupy both ends of the pipe instead.</p><div class="pullquote"><p><em>The interesting question isn't whether Amazon failed here; parts of this were failures, and public ones. It's what Amazon did with the verdict</em>.</p></div><h2 style="text-align: justify;">The organization chart is the strategy document</h2><p>In December 2025, Amazon replaced Rohit Prasad at the head of the AGI organization with Peter DeSantis, a longtime cloud infrastructure executive.[17] CNBC describes the resulting unit plainly: it builds AI models and includes groups working on silicon development and quantum computing.[7]</p><p style="text-align: justify;">That&#8217;s not a research organization with infrastructure attached; it&#8217;s an infrastructure organization with research attached, and the reporting line tells you how the company values each. A model program that reports to the executive who owns chips, data centers, and quantum is a program understood as a load on capacity rather than as a product line.</p><p style="text-align: justify;">The AGI Lab itself was founded in December 2024, built around several dozen employees Amazon acquired from Adept, including its co-founder David Luan, and grew to roughly eighty people at its peak. More than a dozen of the Adept hires have since left, Luan among them in February.[8] The Information, which reported the closure first, describes what the lab was for: building software to make AI agents more useful.[18] Amazon confirmed the site closure and said frontier model research continues under Pieter Abbeel, the Berkeley professor who joined in 2024 when Amazon licensed the technology and hired the team from his robotics startup, Covariant.</p><p style="text-align: justify;">Secondary reporting indicates the cuts fell on model customization and post-training roles, a claim carried by trade press and not confirmed by Amazon.[14] If it holds, it points somewhere specific: post-training is the work that turns a base model into a competitive product, and a company that keeps a research lab while cutting that function has made a choice about which of the two it is doing. Amazon has not disclosed which teams were affected, so hold it loosely.</p><p style="text-align: justify;">The company&#8217;s own account is consistent with this, if read literally. A spokesperson said Amazon was sharpening its focus on the initiatives that matter most for customers so it could move faster on what counts.[7] Customers sit at the top of the stack. Frontier research is not where AWS meets them, and a billion dollars of embedded engineers is.</p><h2>What a landlord keeps</h2><p style="text-align: justify;">The defeat reading has been made in print: The Next Web called the lab closure the clearest sign yet that Amazon had stepped back from a frontier race it never really led.[19] On that reading, the models never landed, the products never took, and a company retiring Kendra and Q Business is making a virtue of a loss. Half of that is simply true, and the tooling shows it best.</p><p style="text-align: justify;">Take SageMaker Clarify, a bias-detection tool built for tabular models. AWS rebuilt it for the new architecture, enabling foundation model evaluation to move from preview in November 2023 to general availability in April 2024.[20][21] Twenty-six months later, it went to maintenance.[22] Ground Truth followed the same arc, and Ground Truth Plus, converted earliest of all in May 2023, is the only item on the June 30 page to reach the full end of support.[23][24][3] Earliest conversion, hardest death. Whether AWS built the wrong thing or built the right thing too late is a fair debate. The outcome is not.</p><p style="text-align: justify;">For now, the surviving services are close to the hardware. SageMaker HyperPod, the one part of the platform still shipping features monthly, does cluster resilience: gang scheduling, continuous provisioning, job recovery, and capacity reservation on Trainium.[25][26][27][28][29] The scheduling logic exists in open source, and a Kubernetes engineer will say so. What does not exist outside the operator is the input: which node sits on which network spine, which accelerator is degrading, which instance is about to be retired, and whether the capacity exists to be reserved at all. The position is the privileged telemetry, not the feature.</p><p style="text-align: justify;">Call it the fabric test. A function that runs against a model goes to whoever ships alongside the model. A function that requires privileged access to physical capacity stays with whoever owns the capacity. It predicts the consequential AI retirements on the June 30 page: Kendra was a managed retrieval system, Bedrock Agents was an orchestration system, and Q Business was an application over a corpus, and none of the three needed hardware.</p><p style="text-align: justify;">The landlord position has a second advantage. It&#8217;s indifferent to which tenant wins: capacity bills identically whether the customer runs Claude, Nova, Qwen, or something that does not exist yet, while every layer AWS dropped required backing a horse.</p><p>This also explains why Nova continues to exist, which is otherwise the loose thread in the argument. A landlord that buys its headline product from a single supplier needs a cap on what that supplier can charge. A competent house brand at the commodity tier does that job without winning anything: it sets a price floor, absorbs workloads where frontier capability is wasted, and keeps a credible team on the payroll.</p><div class="pullquote"><p>Nova doesn&#8217;t have to beat Claude. It has to make Claude&#8217;s price negotiable.</p></div><p style="text-align: justify;">And it explains why AWS now hosts its competitors' tooling rather than fighting it. Managed MLflow occupies the ground Clarify and Experiments were built to hold, and the product page that once sold Experiments now sells MLflow.[30][31][32] Experiments itself was never formally retired. The APIs still answer, and no deprecation notice exists anywhere; AWS confined it to the legacy Studio experience and pointed the documentation at its replacement.[33] A product superseded in place leaves no notice to audit. A week after freezing Model Monitor, the AWS machine learning blog published monitoring guidance built on open-source Evidently, with the results organized in MLflow.[34] Hosting the winner captures the workload without financing the losing race.</p><h2>The only one of the four</h2><p style="text-align: justify;">Set Amazon against its peers, and the position stops looking like an industry trend and starts looking like a choice. This is what the four say in public, not what they plan in private.</p><p style="text-align: justify;">Google builds the whole stack: its own accelerators, models, and surfaces, and it carries the research cost because the models feed products it owns end to end. Microsoft resells third-party models on Azure, as AWS does, but it also sells an assistant, and the quality of an assistant is a claim about the model inside it. Meta is the cautionary case: it spent enormously on infrastructure and could not buy the research culture to make it pay, which is the failure version of stepping back and the version the market reaches for by default.</p><p style="text-align: justify;">Amazon is none of these, and the distinction is less the direction than the decisiveness. Microsoft may yet drift the same way; its Azure catalog is already multi-model. Only Amazon has done it explicitly and completely, on one page, in one quarter. It rebuilt its intelligence tooling for the new architecture, shipped it, then withdrew, while raising capital expenditure toward $200bn, contracting a frontier supplier onto its own silicon for a decade, and committing a billion dollars to engineers who deploy that supplier&#8217;s models inside customer businesses. </p><p style="text-align: justify;">These are the actions of a company that priced the layer and declined it. The distinction carries a forecast. A company that lost a layer re-enters it when conditions improve, and its retreat is temporary. A company that priced a layer and declined it doesn&#8217;t come back, and here the barrier to return is one Amazon built itself: re-entering the frontier would now mean competing against its own anchor tenant, on its own silicon, against a product its own billion-dollar deployment force installs. The supply contract works as more than a substitute for the laboratory. It locks the door behind it. Everything since December 2025 points the same way: a reporting line that subordinates models to infrastructure, a contract measured in gigawatts and decades, and a billion dollars aimed at deployment rather than research.</p><h2>Redundancy, not retreat</h2><p>Which makes the AGI Lab closure something other than a failure signal.</p><p style="text-align: justify;">A laboratory does two things. It secures a capability you cannot otherwise obtain, and it holds an option on architectures nobody has commercialized yet. Amazon has bought the first through a 10-year supply contract using chips it designed. It has not closed the second, at least for now: Abbeel remains, research continues, and the AGI organization is still hiring.</p><p style="text-align: justify;">What Amazon canceled sits between the two, and that is why the reported cuts to model customization and post-training matter more than the closure of a site. Post-training is how a base model becomes a frontier product. Research is how you hold the option and judge what your supplier is selling. And the reportedly cut roles are the same functions Nova Forge now sells to customers as a service: continued pre-training, fine-tuning, and preference optimization on their own data.[34] The cuts and the product are one move. Amazon kept the option, stopped performing the frontier work for itself, and externalized it to paying customers.</p><p style="text-align: justify;">The exposures fit on one list. First, Amazon has contracted for output, not acquired a capability: Anthropic sets its own roadmap, prices its own models, serves Amazon&#8217;s competitors elsewhere, and runs a deliberately multi-cloud posture. The dependence runs both ways: since Amazon holds the equity, the training capacity, and the largest distribution channel, the mutual dependence remains stable until one side&#8217;s alternatives improve faster than the other&#8217;s. Second, the arrangement is subject to competition law. The UK Competition and Markets Authority examined the partnership in 2024 and closed its inquiry on jurisdiction, not merits, while the Federal Trade Commission ran a parallel market study.[35][36] The facts have since outgrown that clearance: a $4bn investment one way now sits beside a $100bn procurement the other, binding the two companies more tightly than anything the 2024 inquiry reviewed. Whether an authority would reach the same conclusion today is unknowable.</p><p style="text-align: justify;">Amazon has evidently judged the whole list cheaper than financing a laboratory it was unlikely to win with. That judgment is defensible on today&#8217;s numbers.</p><h2>What would break this</h2><p style="text-align: justify;">The strongest counterargument is that Amazon is still building models, and it is. Nova 2 shipped at re:Invent in December 2025 in Lite, Pro, Sonic, and Omni variants, alongside Nova Forge for organizations building custom frontier models.[37] An AWS executive would argue, with some justification, that a portfolio cull inside a funded model program is ordinary discipline rather than a change of direction.</p><p style="text-align: justify;">Except that the executive who runs the program has already conceded the premise. DeSantis told CNBC in June that it is &#8220;a fair narrative&#8221; that Amazon&#8217;s models &#8220;haven&#8217;t been at the very frontier&#8221; for the largest workloads, while hoping Amazon would be in the leading-model conversation in the coming year.[38] In the same interview, he put Nova 2 at roughly 50,000 customers since December, said Amazon should be considered on par with Nvidia in its ability to design and produce chips, and confirmed there's no timeline for Jassy&#8217;s April suggestion that Amazon might sell Trainium racks to third parties. Fifty thousand customers is breadth at the commodity tier, which is what a price floor accumulates. Comparing yourself to Nvidia is what a silicon company does. And floating rack sales are a landlord wondering whether to sell the fittings too. The counterargument&#8217;s own spokesman is describing the thesis.</p><p style="text-align: justify;">The thesis breaks if:</p><ul><li><p style="text-align: justify;">Nova receives a genuine frontier push, and a Nova model competes at the top of the Bedrock catalog on customer usage rather than vendor benchmarks.</p></li><li><p style="text-align: justify;">Nova Forge lands anchor customers at scale.</p></li><li><p style="text-align: justify;">The AGI organization is rebuilt outside the infrastructure reporting line, because that reporting line is the clearest signal in the whole sequence.</p></li><li><p style="text-align: justify;">AWS reclaims one of the displaced tooling categories with a proprietary product that wins against the open-source incumbent.</p></li><li><p style="text-align: justify;">Anthropic&#8217;s non-AWS capacity share grows materially, because that would suggest the option value in this arrangement always sat with the supplier, and that Amazon was priced into the landlord role rather than choosing it.</p></li></ul><p style="text-align: justify;">The second-quarter results on 30 July are the near-term test: watch capital expenditure, AWS margin, and whether Nova appears in the earnings narrative at all.</p><h2>What this means for the people buying it</h2><p style="text-align: justify;">For a buyer, this is one question. Before adopting any vendor AI feature, ask whether the function could be built by someone who does not own a data center. If it could, price in migration, and keep the integration thin. If it cannot, treat the dependency as infrastructure and negotiate exit assumptions over years. And do not audit vendor risk off deprecation notices alone: Experiments show a product can be retired by a documentation edit without appearing on any list.</p><p style="text-align: justify;">Five years ago, I argued that software would eat machine learning: teams would assemble models instead of building them, write as little code as possible, and let tooling do the rest.[39] The June 30 page is that prediction arriving. </p><div class="pullquote"><p style="text-align: center;">Everything in the middle of the stack that could be expressed as software has been eaten, mostly by tooling that ships with the model.</p></div><p style="text-align: justify;">What survives is what software cannot eat: the chips, the buildings, the power, and the people who install the result. Amazon saw that outcome and reorganized around it. Retire what software already ate. Spend a billion dollars deploying what it cannot.</p><p style="text-align: justify;">The durable position was never the model. Nor was it the middle of the stack, where services competed with superior open source on launch day and existed mostly to thicken a product manager&#8217;s promotion document. </p><p style="text-align: justify;">Back to cloud 101: the durable position is always the meter.</p><div><hr></div><h3>Notes</h3><p>[1] <a href="https://www.aboutamazon.com/news/aws/aws-1-billion-forward-deployed-ai-engineers">AWS invests $1 billion to embed AI forward deployed engineers with customers</a>, About Amazon, 30 June 2026. Describes the agentic-first model, the compression of deployment timelines, the customer self-sufficiency goal, and the named early customers.</p><p>[2] <a href="https://www.cnbc.com/2026/06/30/aws-amazon-ai-forward-deployed-engineers.html">AWS puts $1 billion into new AI unit to embed engineers with customers</a>, CNBC, 30 June 2026. Source for pod size, engagement length and the Vasquez interview.</p><p>[3] <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-service-availability/">AWS Service Availability Updates</a>, AWS What&#8217;s New, 30 June 2026. The ten SageMaker AI features are A2I, Clarify, Debugger, GeoSpatial, Ground Truth, Mechanical Turk, Model Monitor, Profiler, Role Manager and Studio Lab. Ground Truth Plus is listed separately under end of support. The same page also retires directory, mainframe and console-management services unrelated to AI; the body&#8217;s &#8220;consequential&#8221; excludes those and legacy items such as Mechanical Turk and Studio Lab, which reached maintenance through obsolescence rather than displacement.</p><p>[4] <a href="https://docs.aws.amazon.com/kendra/latest/dg/kendra-availability-change.html">Amazon Kendra availability change</a>, AWS documentation.</p><p>[5] <a href="https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/qbusiness-availability-change.html">Amazon Q Business availability change</a>, AWS documentation.</p><p>[6] <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/agents-classic-maintenance-mode.html">Amazon Bedrock Agents Classic maintenance mode</a>, AWS documentation. Bedrock models, Knowledge Bases and Guardrails are unaffected; migration is directed to AgentCore.</p><p>[7] <a href="https://www.cnbc.com/2026/07/22/amazon-lays-off-some-employees-in-its-agi-unit.html">Amazon lays off some employees in its AGI unit</a>, CNBC, 22 July 2026. Source for the composition of the AGI organisation, the DeSantis appointment, and the company statement.</p><p>[8] <a href="https://www.geekwire.com/2026/amazon-confirms-its-closing-key-ai-site-in-san-francisco-but-says-work-on-its-top-models-continues/">Amazon confirms it&#8217;s closing key AI site in San Francisco but says work on its top models continues</a>, GeekWire, 24 July 2026. Company spokesperson confirmation of the site closure, the lab&#8217;s founding and headcount, the Adept departures, and Abbeel&#8217;s role.</p><p>[9] <a href="https://ir.aboutamazon.com/news-release/news-release-details/2026/Amazon-com-Announces-Fourth-Quarter-Results/">Amazon.com Announces Fourth Quarter Results</a>, Amazon Investor Relations, 5 February 2026. The release carries Jassy&#8217;s guidance of about $200bn in 2026 capital expenditure and the &#8220;seminal opportunities&#8221; framing; his statement that the spend would be predominantly invested in AWS was made to analysts on the accompanying call, per <a href="https://www.cnbc.com/2026/02/05/amazon-amzn-q4-earnings-report-2025.html">CNBC&#8217;s same-day report</a>.</p><p>[10] <a href="https://www.aboutamazon.com/news/aws/aws-project-rainier-ai-trainium-chips-compute-cluster">AWS&#8217;s Project Rainier: the world&#8217;s most powerful computer</a>, About Amazon, 29 October 2025.</p><p>[11] <a href="https://aws.amazon.com/ec2/instance-types/trn3/">Amazon EC2 Trn3 UltraServers</a>, AWS product page. Vendor-published performance claims; not independently verified.</p><p>[12] <a href="https://www.anthropic.com/news/anthropic-amazon-compute">Anthropic and Amazon expand collaboration for up to 5 gigawatts of new compute</a>, Anthropic, 20 April 2026; Amazon&#8217;s counterpart release is <a href="https://www.aboutamazon.com/news/company-news/amazon-invests-additional-5-billion-anthropic-ai">Amazon announces $5B Anthropic investment, up to $20B more</a>, About Amazon, 20 April 2026. Source for the $100bn ten-year commitment, the up-to-5GW capacity, and the Trainium2-through-Trainium4 scope.</p><p>[13] <a href="https://ir.aboutamazon.com/news-release/news-release-details/2026/Amazon-com-Announces-First-Quarter-Results/default.aspx">Amazon.com Announces First Quarter Results</a>, Amazon Investor Relations, 29 April 2026. Source for the $16.8bn of pre-tax gains booked in non-operating income from the Anthropic investments and for AWS segment sales up 28% to $37.6bn. The annualised AI services revenue figure is from management commentary on the accompanying earnings call.</p><p>[14] <a href="https://www.techtimes.com/articles/321341/20260723/amazon-cuts-agi-jobs-while-pouring-200-billion-ai-infrastructure.htm">Amazon Cuts AGI Jobs While Pouring $200 Billion Into AI Infrastructure</a>, TechTimes, 23 July 2026. Secondary source for the Bank of America estimate and for the reported composition of the cuts; both should be treated as reported rather than confirmed, and the Bank of America figure is an analyst estimate.</p><p>[15] Representative Amazon Bedrock on-demand rates, <a href="https://aws.amazon.com/bedrock/pricing/">aws.amazon.com/bedrock/pricing</a>, retrieved July 2026; parity with Anthropic&#8217;s direct API per <a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic platform pricing documentation</a>. Claude Sonnet at $3/$15 per million input/output tokens on both, with matching promotional windows. Rates as of July 2026 and subject to change.</p><p>[16] <a href="https://www.manilatimes.net/2026/07/02/business/foreign-business/amazons-aws-commits-1-billion-toward-new-unit-for-embedded-ai-engineers/2376965">Amazon&#8217;s AWS commits $1 billion toward new unit for embedded AI engineers</a>, The Manila Times, 2 July 2026, on prior forward-deployed engineering organisations at Palantir, Salesforce, Google Cloud and Anthropic.</p><p>[17] Reported December 2025; see note 7 for the CNBC account of the appointment and the scope of the resulting organisation.</p><p>[18] <a href="https://www.theinformation.com/briefings/amazon-shuts-ai-agent-research-lab-agi-layoffs">Amazon Shuts AI Agent Research Lab In AGI Layoffs</a>, The Information, July 2026. Paywalled; the description of the lab&#8217;s remit is quoted via GeekWire at note 8.</p><p>[19] <a href="https://thenextweb.com/news/amazon-shuts-agi-lab-frontier-model-retreat-layoffs">Amazon shuts its AGI Lab in fresh AI layoffs</a>, The Next Web, July 2026.</p><p>[20] <a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-sagemaker-clarify-fm-evaluations-preview">Amazon SageMaker Clarify now supports foundation model (FM) evaluations in preview</a>, AWS What&#8217;s New, 29 November 2023.</p><p>[21] <a href="https://aws.amazon.com/about-aws/whats-new/2024/04/amazon-sagemaker-clarify-foundation-model-evaluations">Amazon SageMaker Clarify now supports foundation model evaluations</a>, AWS What&#8217;s New, 25 April 2024. General availability excluded GovCloud, China and several commercial regions listed in the announcement.</p><p>[22] <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/clarify-availability-change.html">Amazon SageMaker Clarify availability change</a>, AWS documentation.</p><p>[23] <a href="https://aws.amazon.com/blogs/machine-learning/power-your-llm-training-and-evaluation-with-the-new-sagemaker-ai-generative-ai-tools">Power Your LLM Training and Evaluation with the New SageMaker AI Generative AI Tools</a>, AWS Artificial Intelligence blog.</p><p>[24] <a href="https://aws.amazon.com/about-aws/whats-new/2023/05/sagemaker-ground-truth-plus-human-feedback-fine-tuning-data-generative-ai">Amazon SageMaker Ground Truth Plus now supports human feedback and fine-tuning data for Generative AI</a>, AWS What&#8217;s New, 30 May 2023.</p><p>[25] <a href="https://aws.amazon.com/about-aws/whats-new/2026/04/sagemaker-hyperpod-gang-scheduling/">SageMaker HyperPod now supports gang scheduling for distributed training workloads</a>, AWS What&#8217;s New, 8 April 2026.</p><p>[26] <a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sagemaker-hyperpod-continuous-provisioning/">Amazon SageMaker HyperPod now supports continuous provisioning for Slurm-orchestrated clusters</a>, AWS What&#8217;s New, 25 March 2026.</p><p>[27] <a href="https://aws.amazon.com/blogs/machine-learning/accelerate-large-scale-ai-training-with-amazon-sagemaker-hyperpod-training-operator/">Accelerate large-scale AI training with Amazon SageMaker HyperPod training operator</a>, AWS Artificial Intelligence blog. The HyperPod elastic agent is described as an extension of PyTorch&#8217;s ElasticAgent, and fault detection draws on node health checks and AWS retirement notices.</p><p>[28] <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/sagemaker-hyperpod-release-notes.html">Amazon SageMaker HyperPod release notes</a>, AWS documentation, recording Trn2 and Trn2n support for Slurm and Amazon EKS clusters.</p><p>[29] <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/reserve-capacity-with-training-plans.html">Reserve Flexible Training Plans for ML workloads</a>, AWS documentation.</p><p>[30] <a href="https://aws.amazon.com/about-aws/whats-new/2024/06/amazon-sagemaker-mlflow-capability">Amazon SageMaker now offers a fully managed MLflow capability</a>, AWS What&#8217;s New, 19 June 2024.</p><p>[31] <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/fully-managed-mlflow-3-0-amazon-sagemaker-ai/">Fully managed MLflow 3.0 now available on Amazon SageMaker AI</a>, AWS What&#8217;s New, July 2025.</p><p>[32] <a href="https://aws.amazon.com/sagemaker/ai/experiments">Accelerate generative AI development with Amazon SageMaker AI and MLflow</a>, AWS product page, retrieved July 2026.</p><p>[33] <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/experiments.html">Amazon SageMaker Experiments in Studio Classic</a>, AWS documentation.</p><p>[34] The overlap between the reportedly cut post-training and customisation roles and the capabilities Nova Forge sells (continued pre-training, supervised fine-tuning, direct preference optimisation on customer data) is drawn from the TechTimes report at note 14 and from Amazon&#8217;s Nova Forge description at note 37; the role composition of the cuts remains unconfirmed by Amazon.</p><p>[35] <a href="https://gov.uk/cma-cases/amazon-slash-anthropic-partnership-merger-inquiry">Amazon / Anthropic partnership merger inquiry</a>, Competition and Markets Authority case page. Merger inquiry launched 8 August 2024; phase 1 decision 27 September 2024 that the partnership does not qualify for investigation under the merger provisions of the Enterprise Act 2002.</p><p>[36] <a href="https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-launches-inquiry-generative-ai-investments-partnerships">FTC Launches Inquiry into Generative AI Investments and Partnerships</a>, Federal Trade Commission, 25 January 2024. Section 6(b) orders issued to the companies involved in the Microsoft-OpenAI, Amazon-Anthropic and Google-Anthropic investments.</p><p>[37] <a href="https://www.aboutamazon.com/news/aws/aws-re-invent-2025-ai-news-updates">AWS re:Invent 2025: Amazon announces Nova 2, Trainium3, frontier agents</a>, About Amazon, December 2025. Covers the Nova 2 family (Lite, Pro, Sonic, Omni), Nova Forge&#8217;s open-training checkpoint model, and Nova Act&#8217;s move to general availability; announcements made 2 December 2025.</p><p>[38] <a href="https://www.cnbc.com/2026/06/17/amazon-ai-frontier-openai-anthropic.html">Amazon has lagged OpenAI and Anthropic, but AI chief sees path to catch up in &#8216;coming year&#8217;</a>, CNBC, 17 June 2026. Direct interview with Peter DeSantis; source for the frontier concession, the Nova 2 customer figure, the Nvidia comparison, and the status of potential Trainium rack sales first suggested by Andy Jassy in April.</p><p>[39] <a href="https://huggingface.co/blog/the-age-of-ml-as-code">The Age of Machine Learning As Code Has Arrived</a>, Hugging Face blog, 20 October 2021, which I co-authored while Chief Evangelist at Hugging Face.</p>]]></content:encoded></item><item><title><![CDATA[The Model Is a Checkpoint]]></title><description><![CDATA[Washington spent last week letting it be known it might ban Chinese AI models, so this week, everyone is an open-models expert.]]></description><link>https://www.airealist.ai/p/the-model-is-a-checkpoint</link><guid isPermaLink="false">https://www.airealist.ai/p/the-model-is-a-checkpoint</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Thu, 23 Jul 2026 11:06:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CPhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CPhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CPhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CPhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1941764,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/208101192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CPhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!CPhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e081b64-b147-4406-90aa-fe76f07b2604_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Following the release of Kimi K3, Axios reported that the administration is reviving a push to restrict Chinese models on cybersecurity grounds, with Entity List designations under discussion and House committees probing the American companies that run them.[1] The explainer wave arrived within the news cycle: what open weights are, why enterprises quietly run them, which Chinese models to worry about, and the same comparison table in a hundred fonts. Much of it reads as if the subject were discovered at roughly the moment it hit 46.4% of routed traffic on OpenRouter.[2] Benchmarks, market share, comparison: the wave runs on one axis, and it is the wrong one.</p><p style="text-align: justify;">Being late is forgivable; I would rather people learn about open models now than never. The problem is that it is not just late; it is describing an object from an era that ended eighteen months ago. So let me set the record straight, from the beginning, because I was there for it.</p><p style="text-align: justify;">In March 2021, I published a post on the AWS machine learning blog announcing a partnership between Amazon and a startup most enterprise readers had never heard of. Hugging Face, founded in 2016 and with offices in New York and Paris, made it easy to add Transformer models to your applications. The catalog held about 7,000 pre-trained models in 164 languages. The examples I reached for were BERT (340 million parameters) and GPT (175 billion).[3]</p><p style="text-align: justify;">Read that post today, and the striking thing is what it does not contain. There is no comparison. No table weighing an open model against a proprietary API, no paragraph on cost per token, nothing on privacy or lock-in. There was nothing to compare against. The problem the partnership existed to solve was more basic: most organizations could not deploy these models at all. Getting the file onto managed infrastructure with a few lines of code was the entire value proposition.</p><h2>Three eras</h2><p>Open models have changed what they are three times, and each era is defined by the question practitioners were asking.</p><p style="text-align: justify;">In the distribution era, roughly 2021 to 2022, the question was: <strong>how do I run this at all?</strong> The achievement was deployment. The infrastructure that mattered was hubs, containers, and managed endpoints, and the partnership I announced was that infrastructure being built.</p><p style="text-align: justify;">ChatGPT ended the first era in a weekend. Deployment stopped being the hard part because the incumbent had arrived, and in the comparison era, 2023 to 2024, the question became: <strong>Why would I use this instead of the API?</strong> Open models had a proprietary incumbent to displace, so every argument became a table: transparency versus opacity, cost versus convenience, control versus capability. I spent two years making that argument, and I will show you my own exhibit below.</p><p style="text-align: justify;">The third era had been building quietly since 2023, in preference-tuning papers and merge experiments, while the comparison arguments still held the stage. It blew into public view in January 2025, when DeepSeek shipped R1, trained with a reinforcement learning algorithm the lab published, alongside a family of smaller models distilled from it. In the post-training era, the question changed again, and most people have not noticed, because the era&#8217;s arrival, like the first era&#8217;s ending, was a visibility event: the work predated the moment. <strong>The question is no longer which model to pick. It is what to make from the models you hold.</strong> Open models stopped being products that compete with closed ones and became checkpoints: fine-tuned, aligned, distilled, merged, transplanted, and quantized, both inside the labs that release them and on hardware that fits on a desk. Training no longer ends where the download begins.</p><div class="pullquote"><p>Open models are not a substitute for closed ones. They are a different kind of object, and every era of their history has been a discovery of what that object permits.</p></div><p style="text-align: justify;">For the record: I was at AWS during distribution, at Hugging Face during comparison, and at Arcee AI, the company behind the MergeKit toolkit, during post-training. My career is how I noticed the eras. It is not the evidence, which is other people&#8217;s published work throughout.</p><p style="text-align: justify;">This piece is for teams with the engineering capacity to act on that. If your organization has no machine learning function, the hosted service is the right purchase, and nothing below changes it. But if you are arriving at open models now, through the current wave of explainers and best-of lists, you are being taught the second era&#8217;s answer to the third era&#8217;s question. You should know what this era looks like, from someone who watched all three arrive.</p><h2>The comparison era, from inside</h2><p style="text-align: justify;">In September 2023, as Chief Evangelist at Hugging Face, I published a comparison of SafeCoder, our enterprise code assistant, against the closed-source alternatives.[4] It made five arguments. The model was state-of-the-art. It was transparent: you could read the paper, inspect the training dataset, and check whether your code was in it, since the dataset shipped with an opt-out tool for repository owners.[5] You could fine-tune it yourself in your code. You could run it anywhere, including in an air-gapped environment. And it phoned nothing home.</p><p style="text-align: justify;">I stand by every line, and the post has aged into a period piece anyway. Not because the claims failed, but because the <em>form</em> dates it. Five properties, each argued against a closed-source counterpart. The piece is a table wearing prose, and the table was the era. Open models were the challenger, the incumbent set the terms, and everything we wrote had to justify the open choice against the closed default.</p><p style="text-align: justify;">The comparison era did real work. It established that open models were viable for serious deployment, it forced pricing discipline on the incumbents, and its arguments about privacy and control were correct and remain correct. What it could not do was describe properties with no counterpart on the other side of the table. A comparison can only hold what both columns share. The operations that define this era were invisible to the format: not suppressed, just unrepresentable.</p><p style="text-align: justify;">Which is why, if you learned open models from the comparison literature, the current era will sound like it happened somewhere else. It did not. It happened inside the models you are being recommended.</p><h2>The post-training era: where the models come from</h2><p style="text-align: justify;">Here is what the era&#8217;s best-of lists do not say about the models on them: nearly everything that makes them good happened after pre-training. Supervised fine-tuning, preference training, reinforcement learning, distillation from a larger teacher, and increasingly merging. The base run buys the raw capability; the post-training stack turns it into the model you download.</p><p style="text-align: justify;">The stack starts earlier than most descriptions admit. Continued pre-training, sometimes called mid-training, takes a released checkpoint and keeps feeding it raw text: Code Llama is Llama 2 with its pre-training continued on a code-heavy corpus, and SEA-LION&#8217;s pipeline begins by continuing pre-training on Southeast Asian text before any of the stages below.[6] A checkpoint is not a finished artefact with a tuning knob. It is a training run; somebody paused, and anyone holding the file can press resume.</p><p style="text-align: justify;">The alignment layer opened first, and the progression is worth spelling out because it is the era in miniature. In 2022, preference training meant RLHF as the closed labs ran it: proximal policy optimization, a learned reward model, a critic network, and infrastructure that almost nobody else could operate. In 2023, direct preference optimization collapsed all of that into a single loss function that runs wherever fine-tuning runs, and Zephyr showed a 7-billion-parameter open model beating much larger chat models on supervised fine-tuning plus DPO alone.[7] In late 2024, AI2&#8217;s T&#252;lu 3 published a complete open post-training recipe, including data, code, and weights, and introduced reinforcement learning from verifiable rewards: checkers instead of learned reward models.[8]</p><p style="text-align: justify;">Then, DeepSeek&#8217;s GRPO (group relative policy optimization), the algorithm behind R1, deleted the critic network that made the RL loop expensive, and within weeks of R1&#8217;s release, the open community was replicating the pipeline publicly.[9] Each step removed a piece of infrastructure only a frontier lab could afford, until the whole alignment stack ran in open frameworks, with the small-model end reaching consumer GPUs.[10]</p><p style="text-align: justify;">Merging is the newest layer of that stack, and it is already inside the models the guides recommend. Meta&#8217;s Llama 3.1 report describes averaging models at every post-training stage across reward modeling, supervised fine-tuning, and DPO, and using the flagship to improve its smaller siblings.[11] Cohere&#8217;s Command: A technical report calls expert merging a core feature of its training pipeline: domain experts trained separately, then folded into a single set of parameters.[12]</p><p style="text-align: justify;">Much of that is averaging variants of a single pipeline. Merging separately trained models into a single set of weights was adopted from papers and released systems in 2025.[13] In March, a team from Qiyuan Tech and Peking University distilled DeepSeek-R1 into three domain experts for mathematics, coding, and science, then merged them with Arcee Fusion, from Arcee AI's MergeKit toolkit, landing within two points of the 671-billion-parameter teacher on AIME mathematics. The merge took 4 GPU-hours, compared with 740 for retraining on mixed data, which the authors call a free lunch, published from the far side of the boundary the ban debate is trying to draw. SEA-LION, AI Singapore's national language family, runs multiple DELLA Linear merge stages in the pipeline behind its shipped models.[16] And the field is not fringe: merging has a survey in ACM Computing Surveys, and the toolkit's paper sits in the EMNLP industry track.[17][18]</p><p style="text-align: justify;">So the technical reports describe merging as routine, the lists recommend the models that those reports document, and the word appears in neither. A newcomer can read guide after guide and never learn that the operation exists, let alone that it built the thing they just downloaded.</p><h2>The post-training era: on your desk</h2><p style="text-align: justify;">The same operations run downstream, and the hardware to run them arrived recently enough that most of the literature predates it.</p><p style="text-align: justify;">One calibration first, because the era has a gradient, and you should know where you stand on it. Quantization and distillation are the mass operations: anyone running a model through Ollama is running quantized weights, today, probably without thinking of it as a weight-space operation at all. Fine-tuning is common. Merging and surgery are where the frontier is, not where the median is. The era is defined not by everyone doing everything, but by the possibility of it all with a single object.</p><p style="text-align: justify;">The practitioner&#8217;s toolkit is six operations, and the everyday ones come first. </p><ol><li><p style="text-align: justify;"><strong>Fine-tune a model on your own data</strong>: low-rank adaptation runs on a single consumer GPU, and the output is an adapter file measured in megabytes that you keep, copy, and load anywhere. </p></li><li><p style="text-align: justify;"><strong>Distil a large open model into a small one whose weights you own</strong>; an open teacher is a teacher you are allowed to keep, where a closed vendor&#8217;s terms typically forbid training a competitor on its outputs. NVIDIA went further and released the Nemotron-4 340B family under a licence that explicitly permits generating synthetic training data, because data generation is now a post-training stage in its own right.[19] </p></li><li><p style="text-align: justify;"><strong>Align it</strong>: DPO runs wherever fine-tuning runs, and GRPO-style reinforcement learning, critic deleted and rewards drawn from verifiable checkers, now runs in open frameworks on consumer GPUs; I examined the compute shape of that workload in <a href="https://www.airealist.ai/p/the-verification-tax">The Verification Tax</a>.</p></li><li><p style="text-align: justify;"><strong>Merge models into a new one.</strong> That operation needs no training run, no rented cluster, and no data; for small models, it runs on a CPU or eight gigabytes of video memory, and lazy tensor loading keeps even large merges on modest hardware.[20] </p></li><li><p style="text-align: justify;"><strong>Transplant components between models</strong>: MergeKit ships a tool that moves one model&#8217;s tokenizer into another, and in its published cross-family test, the underlying technique retained roughly 96% of language-understanding performance with no training at all.[21] </p></li><li><p style="text-align: justify;"><strong>Quantize</strong>: reduce numerical precision to trade quality for footprint at a point you choose.</p></li></ol><p style="text-align: justify;">Quantization is the bridge between owning weights and using them, and its arithmetic is blunt. Qwen3.5-397B, a 397-billion-parameter mixture-of-experts model from one of the Chinese families reportedly under discussion in Washington, is roughly 807 gigabytes on disk at full precision: a rack, full stop. At dynamic four-bit, it is about 214 gigabytes and loads on a single Mac Studio. At three bits, it fits a 192-gigabyte machine, and the quantizer&#8217;s own guidance now recommends two-bit dynamic variants as a legitimate operating point rather than a last resort.[22] The same weights span a data center and a desk, and where on that curve you sit is your decision, not a vendor&#8217;s. The community quant tables even publish the far end with honest labels: the one-bit files are marked &#8220;for the desperate&#8221;.[23] That is what a continuous curve looks like: it goes all the way down, and it tells you the quality price at every stop. And the desk changed too.</p><p style="text-align: justify;">Consumer graphics cards stop at 24 or 32 gigabytes of memory, and a model that does not fit does not run.[24] Unified memory architectures remove that ceiling by pooling system and graphics memory. Apple established the pattern. AMD&#8217;s Strix Halo platform puts 128 gigabytes of unified memory in mini-PCs selling for roughly $2,000, with AMD&#8217;s own developer machine at $3,999, and Nvidia sells its own 128-gigabyte unified-memory developer box, the DGX Spark, at the same price. The company unveiled the platform at CES in January 2026, claiming it could run models with up to 200 billion parameters locally.[25] The trade is bandwidth: a discrete card moves memory several times faster, which is what generation speed depends on, so small models run faster on the card while large ones only run on the pool. Mixture-of-experts models bend the curve further by activating only a fraction of their parameters per token, letting a far sparser model outrun a dense one on the same machine.[26]</p><p style="text-align: justify;">And weight surgery is quietly becoming a production dependency, not an enthusiast&#8217;s hobby. Speculative decoding, the serving optimization in which a small draft model runs ahead of a large one, is recommended in current deployment guides and implemented in vLLM, which, by default, requires that the draft and the target share a vocabulary.[27] For a model with its own vocabulary, no compatible draft exists, and building one traditionally means returning to the training stage.[28] The cheap route is the transplant operation above; the heavier one is training a small drafting head, EAGLE-style, directly onto the frozen checkpoint, which is likewise an operation on weights you must hold.[29] Microsoft Foundry&#8217;s import screen now has a dedicated slot for draft models.[30] The platform assumes you arrive holding one. None of the guides I read mentions that the slot exists or that weight surgery is how it's filled.</p><h2>Where the checkpoint beats the frontier</h2><p style="text-align: justify;">The frontier labs post-train for everyone on average. A checkpoint post-trained for one domain beats them on that domain, and the clearest demonstrations now come from companies you know.</p><p style="text-align: justify;">Cursor, one of the companies the House is reportedly asking about, built Composer, the model behind its agent, by training a mixture-of-experts model via reinforcement learning across hundreds of thousands of sandboxed coding environments. According to the company&#8217;s benchmarks, it achieves frontier coding results at 4x the generation speed of comparably intelligent models.[32] The base is widely reported to be an open checkpoint, a question Cursor&#8217;s researchers pointedly decline to answer, which tells you what a checkpoint&#8217;s provenance is now worth.[33]</p><p style="text-align: justify;">Salesforce fine-tuned its xLAM family on synthesized tool-use data and took first place on the Berkeley Function-Calling Leaderboard, ahead of GPT-4 and Claude 3, with models a fraction of their size.[34]</p><p style="text-align: justify;">And Baichuan post-trained a 32-billion-parameter medical model using a staged GRPO recipe against a clinical verifier. On HealthBench, OpenAI&#8217;s own medical benchmark, M2 beat every open model and most closed ones, including o3 and Gemini 2.5 Pro, and at release, it was the only model other than GPT-5 to clear 32 on the Hard subset. Quantized, it deploys on a single RTX 4090.[35]</p><p style="text-align: justify;">Three domains, three of the six operations, three names your board recognizes. None of these teams out-trained the frontier in general, and none needed to. They picked an axis, fine-tuned a checkpoint on it, and kept the axis.</p><h2>Why the literature lags</h2><p style="text-align: justify;">If the post-training era is real, why is the &#8220;Open Models 101&#8221; wave still writing comparison-era explainers? Mostly because that is what explanation is. The genre exists to introduce open models to people arriving from closed APIs, and introducing the unfamiliar means comparing it to the familiar. A comparison can only hold properties both sides share: price, privacy, control, and latency each take a value on both sides, so each gets a row. Continued pre-training, merging, and weight surgery have no closed-form counterparts, so no rows exist for them, and they go unwritten. The blog posts, the press explainers, and the analyst notes all inherit the format, whoever writes them.</p><p style="text-align: justify;">The commercial guides could break the frame, because their authors run these operations for a living. They do not, and the pattern is instructive. I read four guides closely: an inference platform, a GPU renter, a desktop-app maker, and an independent author. Each goes deep on exactly one production capability, the one it sells. Preference optimization and RL fine-tuning appear in none of them, and neither does merging, which nobody sells.[36] Merging needs no rented compute, no serving contract, no application. The comparison frame explains the wave. The billing pattern explains why even its deep end never corrects its shallow end.</p><p style="text-align: justify;">The obvious objection is that if these operations mattered, the closed vendors would sell them. They did. OpenAI shipped a complete distillation workflow in its API in October 2024, and Google, Anthropic, and AWS offer their own distillation paths.[37] What they sell is the operation, never the artifact. OpenAI now even releases open-weight models of its own; what it does not release is the adapted weights from your fine-tuning of its hosted models. The fine-tune lives behind the API, and Microsoft&#8217;s documentation for the equivalent Azure workflow states plainly that the stored training data cannot be exported or downloaded.[38] </p><p style="text-align: justify;">The operations arrived. Nothing came out. And the hosted route delivers real results: published distillation numbers report 14-24 times lower cost per successful task than frontier calls.[39] What the buyer owns afterward is a result, not a model; it cannot be merged, quantized, or moved, and it lives only as long as the vendor&#8217;s base.</p><p style="text-align: justify;">The platforms noticed the same thing, and what they built is the clearest statement of what this era is worth. Amazon Bedrock ships Custom Model Import, generally available since October 2024, which accepts weights in the Hugging Face format: Llama, Mistral, Qwen, and, since last November, OpenAI&#8217;s own open-weight models.[40] Google Vertex accepts custom weights. Microsoft Foundry accepts full models, adapters, and draft models.</p><p style="text-align: justify;">Study those import screens for a moment. Every major platform built a door for the model file to come in. None of them built one facing out. You can bring a merged model to all three hyperscalers; you cannot take a fine-tune of their own models away from any of them. The companies that run the largest AI infrastructure in existence have priced what a file in hand is worth, and their answer is a one-way door.</p><p style="text-align: justify;">So the question to take away from this piece is not the question of the era being compared. Not which model is best, and not even open versus closed. The question is what you will make from the thing you hold. And it is the right question because the models are now made that way, the tools run on a desk, and the explainers who cannot tell you so are still writing inside a frame built for the era before.</p><p style="text-align: justify;">Washington, incidentally, is learning the same lesson from the opposite direction. The reported ban keeps colliding with the property this piece is about: the weights are files, already on disks in their millions, and legal analysts note that restricting publicly available model weights raises constitutional questions a service ban never would.[41] Whatever the security merits of the case, and the security findings are not trivial,[42] the policy difficulty is the object lesson. You can sanction a company and geo-block a service. A file that has shipped is neither, which is presumably why the instruments reportedly under discussion are Entity List designations, procurement rules, and liability: tools that reach companies and contracts, because nothing reaches the file. </p><p style="text-align: justify;">And I should say plainly that the capability this piece describes cuts both ways: the same weight access that lets a practitioner transplant a tokenizer lets anyone strip a model&#8217;s safety training, an operation I examined in <a href="https://www.airealist.ai/p/open-from-both-sides">Open From Both Sides</a>. Weight access is not a virtue. It is a property, and properties do not pick sides.</p><p>So here&#8217;s my one-line &#8220;open models 101&#8221;: An open model shouldn&#8217;t be a finished product that you pick. It should be a training run you resume.</p><div><hr></div><h3>Notes</h3><p>[1] Axios, <a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi">&#8220;The secret Trump administration battle to fight Chinese AI&#8221;</a>, 20 July 2026; see also Tom&#8217;s Hardware, <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/trump-administration-reportedly-reviving-push-to-ban-chinese-ai-models-following-kimi-k3-launch-citing-cybersecurity-concerns-downloadable-open-weights-could-make-an-outright-u-s-ban-nearly-impossible-to-enforce-amid-growing-adoption">&#8220;Trump administration reportedly reviving push to ban Chinese AI models following Kimi K3 launch&#8221;</a>, 22 July 2026. No executive order signed as of this writing; the Commerce Department reportedly evaluated Entity List designations; House committee probes of US firms using Chinese models reported July 2026. All characterisations &#8220;reportedly&#8221; per the sourcing.</p><p>[2] Chinese models at 46.4% of routed token traffic on <a href="https://openrouter.ai/rankings">OpenRouter</a> versus 35.7% for US models, DeepSeek at 17.6% alone, as of July 2026, per the <a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi">Axios</a> reporting and contemporaneous coverage. OpenRouter routes a developer-heavy slice of traffic; treat the shares as indicative of that population, not of the whole market.</p><p>[3] Simon, <a href="https://aws.amazon.com/blogs/machine-learning/aws-and-hugging-face-collaborate-to-simplify-and-accelerate-adoption-of-natural-language-processing-models/">&#8220;AWS and Hugging Face collaborate to simplify and accelerate adoption of Natural Language Processing models&#8221;</a>, AWS Machine Learning Blog, 23 March 2021. Figures as published: ~7,000 pre-trained models, 164 languages, BERT at 340M parameters, GPT at 175B.</p><p>[4] Simon, <a href="https://huggingface.co/blog/safecoder-vs-closed-source-code-assistants">&#8220;SafeCoder vs. Closed-source Code Assistants&#8221;</a>, Hugging Face blog, 11 September 2023.</p><p>[5] The StarCoder base models were trained on The Stack (2.7 TB, permissively licensed code), published with an opt-out mechanism for repository owners. Li et al., <a href="https://arxiv.org/abs/2305.06161">&#8220;StarCoder: may the source be with you!&#8221;</a>, arXiv:2305.06161.</p><p>[6] Rozi&#232;re et al., <a href="https://arxiv.org/abs/2308.12950">&#8220;Code Llama: Open Foundation Models for Code&#8221;</a>: Llama 2 with continued pre-training on a code-heavy corpus. SEA-LION&#8217;s continued pre-training stage per its technical report (see the SEA-LION note above). Continued pre-training at useful scale consumes billions of tokens of compute; it is the heaviest operation in this piece and the one with the highest floor.</p><p>[7] Rafailov et al., <a href="https://arxiv.org/abs/2305.18290">&#8220;Direct Preference Optimization: Your Language Model is Secretly a Reward Model&#8221;</a>, NeurIPS 2023; Tunstall et al., <a href="https://arxiv.org/abs/2310.16944">&#8220;Zephyr: Direct Distillation of LM Alignment&#8221;</a>, the Hugging Face H4 recipe pairing SFT with DPO.</p><p>[8] Lambert et al., <a href="https://arxiv.org/abs/2411.15124">&#8220;T&#252;lu 3: Pushing Frontiers in Open Language Model Post-Training&#8221;</a>, Allen Institute for AI, November 2024. Full recipe, data and weights released; introduces reinforcement learning with verifiable rewards (RLVR).</p><p>[9] GRPO: Shao et al., <a href="https://arxiv.org/abs/2402.03300">&#8220;DeepSeekMath&#8221;</a>, which introduced group relative policy optimisation; DeepSeek-AI, <a href="https://arxiv.org/abs/2501.12948">&#8220;DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning&#8221;</a>, January 2025. GRPO computes advantages within a sampled group, removing the separate critic network. Community replication: Hugging Face&#8217;s <a href="https://github.com/huggingface/open-r1">Open R1</a>.</p><p>[10] Open post-training frameworks include Hugging Face <a href="https://github.com/huggingface/trl">TRL</a> (SFT, DPO and GRPO trainers), ByteDance&#8217;s <a href="https://github.com/volcengine/verl">verl</a>, and <a href="https://github.com/OpenRLHF/OpenRLHF">OpenRLHF</a>; consumer-hardware GRPO recipes ship in <a href="https://docs.unsloth.ai">Unsloth</a>.</p><p>[11] Grattafiori et al., <a href="https://arxiv.org/abs/2407.21783">&#8220;The Llama 3 Herd of Models&#8221;</a>: models from experiments with different data and hyperparameters are averaged at each reward-modelling, SFT and DPO stage; checkpoint averaging is also applied during pre-training annealing, and the flagship model is used to improve the smaller models in post-training.</p><p>[12] Cohere, <a href="https://cohere.com/research/papers/command-a-technical-report.pdf">&#8220;Command A: An Enterprise-Ready Large Language Model&#8221;</a>: &#8220;Expert merging is a core feature of the Command A training pipeline&#8221;, alongside Polyak and seed averaging and interpolation for capability recovery.</p><p>[13] Three grades of the operation, in ascending difficulty. Averaging variants produced by one pipeline under different data or hyperparameters: Llama 3.1 and Command A above. Merging separately post-trained branches that share an ancestor: TinyR1&#8217;s three domain experts and SEA-LION&#8217;s DELLA stages, below. Cross-family merging between unrelated bases: requires tokenizer transplantation when vocabularies differ (note 21) and remains largely research territory (note 14). The 2025 exhibits in this piece are the second grade.</p><p>[14] <a href="https://arxiv.org/abs/2511.21437">&#8220;A Systematic Study of In-the-Wild Model Merging for Large Language Models&#8221;</a>, arXiv:2511.21437. Six methods, four base models, twelve checkpoints each, sixteen benchmarks.</p><p>[15] Sun et al., <a href="https://arxiv.org/abs/2503.04872">&#8220;TinyR1-32B-Preview: Boosting Accuracy with Branch-Merge Distillation&#8221;</a>. Qiyuan Tech and Peking University. Branch phase: domain-specific SFT of DeepSeek-R1-Distill-Qwen-32B on math, coding, and science data. Merge phase: Arcee Fusion (Goddard et al., 2024). AIME 2024: 78.1 versus DeepSeek-R1&#8217;s 79.8. Merge cost: 4 H800 GPU-hours versus 740 for data-mixture retraining; the paper reports using 0.5% of the data-mixture merging compute and describes model merging as &#8220;a &#8216;free-lunch&#8217; approach&#8221;.</p><p>[16] AI Singapore, <a href="https://arxiv.org/abs/2504.05747">SEA-LION technical report</a>, arXiv:2504.05747. Post-training pipeline for Gemma-SEA-LION-v3-9B-IT: two instruction-tuning stages, alignment, and multiple merge stages using DELLA Linear.</p><p>[17] Yang et al., <a href="https://arxiv.org/abs/2408.07666">&#8220;Model Merging in LLMs, MLLMs, and Beyond: Methods, Theories, Applications and Opportunities&#8221;</a>, ACM Computing Surveys, 2026.</p><p>[18] Goddard et al., <a href="https://aclanthology.org/2024.emnlp-industry.36/">&#8220;Arcee&#8217;s MergeKit: A Toolkit for Merging Large Language Models&#8221;</a>, EMNLP 2024 Industry Track, pp. 477&#8211;485. The author served as Chief Evangelist at Arcee AI until November 2025 and holds no current commercial relationship with the company.</p><p>[19] NVIDIA, <a href="https://arxiv.org/abs/2406.11704">&#8220;Nemotron-4 340B&#8221;</a>, released under the NVIDIA Open Model License permitting synthetic data generation for training other models.</p><p>[20] <a href="https://github.com/arcee-ai/mergekit">MergeKit repository</a>, hardware requirements per repository documentation (accessed 23 July 2026).</p><p>[21] <a href="https://arxiv.org/abs/2506.06607">&#8220;Breaking Down Model Vocabulary Barriers with Tokenizer Transplantation&#8221;</a>, arXiv:2506.06607. Orthogonal matching pursuit reconstruction of embedding matrices; ~96% retention across model families, training-free.</p><p>[22] <a href="https://docs.unsloth.ai">Unsloth documentation</a>, Qwen3.5-397B-A17B: ~807 GB full checkpoint; ~214 GB at Unsloth dynamic 4-bit (UD-Q4_K_XL), loadable on a 256 GB M3 Ultra; 3-bit fits 192 GB systems; 2-bit dynamic (UD-Q2_K_XL) recommended by Unsloth as a size/accuracy balance. Via MoE offloading, runs on a single 24 GB GPU plus 256 GB system RAM at 25+ tokens per second. Unsloth documentation, July 2026. Performance-tier comparison to closed frontier models is Unsloth&#8217;s claim; vendor-adjacent, label accordingly. File sizes are directional and vary by quant build.</p><p>[23] Community GGUF quantization tables (<a href="https://huggingface.co/mradermacher">mradermacher</a> and similar) publish the full precision ladder with quality annotations; the 1-bit IQ1 entries carry the label &#8220;for the desperate&#8221;.</p><p>[24] 24 GB: RTX 3090/4090, RX 7900 XTX. 32 GB: RTX 5090. Manufacturer specifications.</p><p>[25] AMD Ryzen AI Max+ 395 (&#8221;Strix Halo&#8221;): 128 GB unified LPDDR5X. Platform unveiled in Lisa Su&#8217;s CES keynote, 5 January 2026; AMD&#8217;s <a href="https://www.amd.com/en/newsroom/press-releases/2026-1-5-amd-expands-ai-leadership-across-client-graphics-.html">CES press release</a> describes the Ryzen AI Halo developer platform as &#8220;capable of running up to 200 billion parameter models locally&#8221;, with the developer machine at $3,999. Third-party 128 GB mini-PCs sell for roughly $2,000 street as of July 2026; the widely quoted ~$1,499 entry units carry 64 GB and cannot load the largest models. Street prices vary by configuration.</p><p>[26] Sparse mixture-of-experts models activate a fraction of parameters per token, so decode cost tracks active rather than total parameters; for a concrete instance of a very large MoE running on modest hardware via offloading, see the Qwen3.5 figures in note 10.</p><p>[27] <a href="https://docs.vllm.ai/en/stable/features/speculative_decoding/">vLLM speculative decoding documentation</a>: draft and target models must share a vocabulary by default. A heterogeneous-vocabulary path (token-level intersection) exists with ~60% reported acceptance for overlapping vocabularies.</p><p>[28] TokenTiming, <a href="https://arxiv.org/abs/2510.15545">arXiv:2510.15545</a>, on the shared-vocabulary constraint and the training-stage cost of aligned draft models.</p><p>[29] Li et al., <a href="https://arxiv.org/abs/2401.15077">&#8220;EAGLE: Speculative Sampling Requires Rethinking Feature Uncertainty&#8221;</a>. EAGLE-class draft heads train against the frozen target model&#8217;s features; the vLLM documentation in note 27 lists EAGLE and MTP among supported speculative methods.</p><p>[30] <a href="https://learn.microsoft.com/en-us/azure/foundry/how-to/fireworks/import-custom-models">Microsoft Foundry custom model import</a>, running on the Fireworks inference runtime within Foundry: full weight models, LoRA adapters (preview), draft models for speculative decoding (preview). Documentation, June 2026.</p><p>[32] Cursor, <a href="https://cursor.com/blog/composer">&#8220;Composer: Building a fast frontier model with RL&#8221;</a>, October 2025. Cursor&#8217;s own comparison places Composer at frontier coding results with roughly four times the generation speed of comparably intelligent models, while noting GPT-5 and Sonnet 4.5 outperform it on raw score.</p><p>[33] Simon Willison, <a href="https://simonwillison.net/2025/Oct/29/cursor-composer/">notes on Composer</a>: Cursor researchers declined to say whether Composer starts from an open-weights base such as Qwen or GLM; reporting has widely inferred an open checkpoint. Cursor is also among the US companies House committees have reportedly queried over Chinese-model use; see <a href="https://www.techtimes.com/articles/320171/20260711/washington-wants-chinese-ai-out-corporate-america-open-weights-block-ban.htm">TechTimes</a>.</p><p>[34] Zhang et al., <a href="https://arxiv.org/abs/2409.03215">&#8220;xLAM: A Family of Large Action Models to Empower AI Agent Systems&#8221;</a>, Salesforce AI Research: first position on the Berkeley Function-Calling Leaderboard at the time, outperforming GPT-4 and Claude 3 on tool use; <a href="https://github.com/SalesforceAIResearch/xLAM">repository</a>. Leaderboard positions have since shifted with newer versions of the benchmark.</p><p>[35] Baichuan, <a href="https://arxiv.org/abs/2509.02208">&#8220;Baichuan-M2: Scaling Medical Capability with Large Verifier System&#8221;</a>: 32B model trained with multi-stage GRPO against a patient-simulator verifier; above 32 on HealthBench Hard, previously exceeded only by GPT-5; surpasses o3, Grok 3, Gemini 2.5 Pro and GPT-4.1 on HealthBench; near-lossless quantisation deploys on a single RTX 4090.</p><p>[36] Sample of four current guides read in full, selected for variance in author business model: <a href="https://www.bentoml.com/blog/navigating-the-world-of-open-source-large-language-models">BentoML</a> (inference infrastructure; June 2026), <a href="https://www.thundercompute.com/blog/best-open-source-llms">Thunder Compute</a> (GPU rental; July 2026), <a href="https://www.localchat.app/blog/open-source-llm-models">LocalChat</a> (local desktop application; June 2026), and <a href="https://huggingface.co/blog/daya-shankar/open-source-llms">an independent author</a> on the Hugging Face community blog (November 2025). Coverage pattern as described; merging absent from all four. Sample and selection logic stated in the interest of checkability.</p><p>[37] OpenAI, <a href="https://openai.com/index/api-model-distillation/">&#8220;Model Distillation in the API&#8221;</a>, 1 October 2024: Stored Completions capture frontier-model outputs as training data for fine-tuning smaller models, inside the platform. On rival offerings: <a href="https://www.infoworld.com/article/3544913/openai-updates-api-with-model-distillation-prompt-caching-abilities.html">InfoWorld</a> notes Google, Anthropic and AWS provide distillation capabilities.</p><p>[38] Microsoft Learn, <a href="https://learn.microsoft.com/en-us/azure/foundry-classic/openai/how-to/stored-completions">Azure OpenAI stored completions and distillation</a>: &#8220;Stored completion distillation training files cannot be accessed directly and cannot be exported externally/downloaded.&#8221; The page documents the classic workflow, which Microsoft schedules for migration to the Responses API in October 2026; the export restriction is as stated as of July 2026.</p><p>[39] TensorZero, <a href="https://www.tensorzero.com/blog/distillation-programmatic-data-curation-smarter-llms-5-30x-cheaper-inference/">&#8220;Distillation with Programmatic Data Curation&#8221;</a>: fine-tuned small models at 13.7x (GPT-4o mini) to 24.1x (Gemini 2.0 Flash Lite) lower cost per successful task than GPT-4o across their evaluation environments. Vendor-published benchmark, B-tier.</p><p>[40] Amazon Bedrock Custom Model Import, <a href="https://aws.amazon.com/about-aws/whats-new/2024/10/amazon-bedrock-custom-model-import">generally available 21 October 2024</a>; <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-bedrock-custom-model-import-qwen-models">Qwen architectures added 11 June 2025</a>; <a href="https://aws.amazon.com/about-aws/whats-new/2025/11/bedrock-model-import-openai-gpt-oss-models/">OpenAI gpt-oss added 19 November 2025</a>. GA 21 October 2024, Hugging Face safetensors format; Qwen support added 11 June 2025; OpenAI gpt-oss support added 19 November 2025. Google Vertex AI custom weights import. Microsoft Foundry custom model import (note 21).</p><p>[41] Representative commentary: <a href="https://www.fastcompany.com/91576757/trumps-proposed-ban-on-chinese-ai-models-could-strengthen-beijings-hand">Fast Company</a> on the unresolved form and reach of any restriction, and <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/trump-administration-reportedly-reviving-push-to-ban-chinese-ai-models-following-kimi-k3-launch-citing-cybersecurity-concerns-downloadable-open-weights-could-make-an-outright-u-s-ban-nearly-impossible-to-enforce-amid-growing-adoption">Tom&#8217;s Hardware</a> on enforceability of restrictions on downloadable weights. B-tier commentary on a live policy question.</p><p>[42] Booz Allen Hamilton, <a href="https://www.boozallen.com/content/dam/home/docs/cyber/booz-allen-chinese-llm-report-may-2026.pdf">&#8220;What&#8217;s in America&#8217;s Code?&#8221;</a> (May 2026): in 2,800+ trials across roughly 460,000 lines of generated code, three of four Chinese code-generation models produced significantly more vulnerable code when the prompt identified the user as working for the US government; Qwen3-Coder added roughly 130% more vulnerabilities under the government persona. Booz Allen states its evidence stops short of showing backdoors or deliberate insertion. The security concern is empirically grounded; this piece takes no position on the policy response.</p>]]></content:encoded></item><item><title><![CDATA[Qwen 3.8: Soon Is Not a Date]]></title><description><![CDATA[Alibaba answers Moonshot's dated gap with an undated one]]></description><link>https://www.airealist.ai/p/qwen-38-soon-is-not-a-date</link><guid isPermaLink="false">https://www.airealist.ai/p/qwen-38-soon-is-not-a-date</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Sun, 19 Jul 2026 15:33:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4gJZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4gJZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4gJZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4gJZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1694143,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/207670362?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4gJZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4gJZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f9bbdd5-1dcd-414a-89b9-1a22b42338e8_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">On Sunday morning, three days after Kimi K3 launched and eight days before its weights are due, Alibaba&#8217;s Qwen team announced Qwen 3.8: 2.4 trillion parameters, multimodal, &#8220;second only to Fable 5&#8221;, and &#8220;going open-weight soon&#8221; [1]. A preview is live on Alibaba&#8217;s Token Plan and its Qoder coding platforms [1][2]. No benchmark table accompanied the claim. No per-token API price had been published for the preview at the time of writing. No date [2][3].</p><p style="text-align: justify;">When K3 launched, <a href="https://www.airealist.ai/p/kimi-k3-and-the-checkpoint-gap">the Checkpoint Gap</a> named the window between a frontier claim and the artefact that lets anyone verify it. Moonshot&#8217;s version of the gap was aggressive but disciplined: a published benchmark table with unusually transparent harness footnotes, a frontier price of $15 per million output tokens, an independent evaluation within hours, and a closing date of July 27. Every claim in that launch can be graded against a calendar.</p><p style="text-align: justify;">Qwen 3.8 opens the same gap without the discipline, and the difference deserves a name. A dated gap is a falsifiable claim: on July 27, the weights ship and replicate, or they don&#8217;t, and either outcome is information. An undated gap asserts nothing testable. It is an option &#8212; the right, but never the obligation, to ship weights at a moment of the vendor&#8217;s choosing, while collecting the open-weights narrative in the meantime. The option is also free to write: announcing an open-weight release commits no capital, reserves no serving capacity, and books no obligation, while the announcement itself trades at full value in the news cycle. A date can be missed, and a missed date is a verdict. &#8220;Soon&#8221; can only drift. Nothing that happens next week, or next quarter, can prove it false.</p><p style="text-align: justify;">The promise deserves to be read against the record, and the record splits cleanly in April 2026. Through the Qwen3 generation, Alibaba was one of the industry&#8217;s most reliable flagship open-weight publishers: flagship generations shipped with downloadable weights, most under Apache 2.0, and the mid-tier still does [4]. Then Qwen3.6-Max-Preview arrived on April 20 as the first closed flagship in Qwen&#8217;s history, available only via the API on Alibaba Cloud [4]. Qwen3.7-Max followed in May: no checkpoint, no license file, no timeline announced for an open variant [5]. Alibaba never promised weights for either flagship. It simply stopped shipping them.</p><p style="text-align: justify;">And both of those closed flagships nonetheless arrived with Alibaba&#8217;s full launch machinery: a detailed technical post, complete benchmark tables, day-one pricing [4][5]. Qwen 3.8, the largest model the company has ever disclosed and the first flagship since the pivot to revive the open-weight language, arrived as a post on X. The words came back. The date did not.</p><p style="text-align: justify;">None of this makes the promise empty. Alibaba&#8217;s open-source catalog is real, enormous, and central to its ecosystem strategy, and a 2.4-trillion-parameter checkpoint takes time to prepare for public release. Moonshot itself left 11 days between the announcement and the weights. A preview is allowed to be a preview. If a Qwen 3.8 repository with a license file appears on Hugging Face in the coming weeks, this note&#8217;s caution was cheap insurance. But that is the property that makes undated promises worth naming: they can only be honored, never broken. There is no day on which &#8220;soon&#8221; fails.</p><p style="text-align: justify;">Then there is the question of who is making it. Alibaba&#8217;s annual report records an investment of approximately $800 million for a 36% equity interest in Moonshot as of March 2024 [6]. Read the timing with that in mind. Moonshot, which Bloomberg reports reached $300 million in annual recurring revenue in June and plans an IPO in as little as six months, launched the most expensive Chinese model ever shipped, with a dated open-weight commitment [7]. Three days later, one of its major shareholders announced a slightly smaller model, claimed a slightly better ranking, attached the same open-weight language with no date, and released it into the window, even though K3&#8217;s openness cannot yet be verified. Whatever the intent, the effect is precise: the open-frontier crown is being contested during the one week when the current claimant cannot produce the crown.</p><p style="text-align: justify;">The apparent self-harm resolves once you weigh the assets. Alibaba&#8217;s Moonshot position is roughly $800 million of preferred stock, diluted through subsequent rounds and due to be repriced by the IPO, whichever model wins the week [6]. Its Qwen franchise is a different order of asset: it anchors Alibaba Cloud&#8217;s model business and, increasingly, the parent&#8217;s own AI narrative, days after a K3 launch that Bloomberg credits with shaking global technology stocks [2]. Note also what an announcement without a benchmark table can and cannot do. It cannot win a developer, because developers need a table and a price. It can freeze an enterprise purchase decision, hold a sales pipeline, and steady the parent&#8217;s story between trading sessions, because those audiences respond to positioning, not checkpoints. An empty announcement is not a weak launch. It is a different instrument, aimed at a different audience.</p><p style="text-align: justify;">The emptiness may even be the calibration. Published numbers strong enough to beat K3 would mark down the IPO asset Alibaba still holds. Numbers too weak to beat it would concede the crown outright. Words alone contest the crown and leave the comparison untouched: every branch of the decision leads to an empty announcement. And the reading carries its own test. If the full launch post follows within days, with a table and a price, the machinery is catching up with the announcement. The longer the gap between the words and the numbers, the more the announcement was the product.</p><p style="text-align: justify;">For the reader fielding this in a vendor review or an investment memo this week, the two launches belong in different rows of the table. K3&#8217;s numbers are vendor-published but disciplined by a date: they can be checked against the July 27 checkpoint, the independent evaluations already running, and a rate card that commits Moonshot to a price. Qwen 3.8&#8217;s single comparative sentence has, at the time of writing, no benchmark behind it, no price beneath it, and no calendar in front of it. Cite the first as a claim awaiting verification. Cite the second, if at all, as an announcement.</p><p style="text-align: justify;">The grading rule this produces is simple and portable. When a frontier launch opens a Checkpoint Gap, the first question is not the benchmark score but whether the gap has a date. Moonshot attached a date to its claim and a price to its confidence; its numbers are pending verification. Alibaba attached neither; its numbers are pending existence. On July 27, the first gap closes, one way or the other. The second has no edges at all. In the Checkpoint Gap, the only hard currency is a date, and Alibaba isn&#8217;t spending any.</p><div><hr></div><h3>Notes</h3><p>[1] Qwen (@Alibaba_Qwen), <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291">launch announcement</a>, July 19, 2026. The quoted phrases (&#8221;second only to Fable 5&#8221;; &#8220;going open-weight soon&#8221;) are verbatim from the post, which describes Qwen3.8-Max-Preview as available on Alibaba&#8217;s Token Plan, Qoder, and QoderWork. Vendor-published.</p><p>[2] Bloomberg, <a href="https://finance.yahoo.com/technology/ai/articles/alibaba-qwen-unveils-preview-flagship-110209258.html">&#8220;Alibaba&#8217;s Qwen Unveils Preview of Flagship AI Model&#8221;</a>, July 19, 2026. Bloomberg notes the Sunday post &#8220;provided no additional technical specifications&#8221; beyond the parameter count, that Alibaba plans an open-weight release, and that K3&#8217;s launch days earlier helped upend perceptions of Chinese AI capability while shaking global technology stocks.</p><p>[3] The Decoder, <a href="https://the-decoder.com/alibabas-qwen-takes-on-kimi-k3-with-open-weight-qwen-3-8-says-model-is-second-only-to-fable-5/">&#8220;Alibaba&#8217;s Qwen takes on Kimi K3 with open-weight Qwen 3.8&#8221;</a>, July 19, 2026: no benchmark results are available at announcement.</p><p>[4] TokenMix, <a href="https://tokenmix.ai/blog/qwen3-6-max-preview-benchmark-review-2026">&#8220;Qwen3.6-Max-Preview Review&#8221;</a>, April 2026 &#8212; Qwen3.6-Max-Preview, released April 20, 2026, was the first flagship in Qwen&#8217;s history to ship closed-weights only, with API access through Alibaba Cloud; prior flagship generations through Qwen3 shipped with downloadable weights, most under Apache 2.0 (some earlier variants used the non-commercial Qwen research licence), and mid-tier Qwen3.6 models (27B, 35B-A3B) remain open under Apache 2.0. Corroborated by <a href="https://insiderllm.com/guides/qwen-open-weights-vs-closed-frontier-2026/">InsiderLLM</a>, which verified the absence of flagship checkpoints on the official Qwen Hugging Face organisation by direct repository probes as of June 15, 2026. B-tier sourcing; the underlying negative claim (no published flagship weights) is independently checkable against the Hugging Face organisation at any time.</p><p>[5] Yotta Labs, <a href="https://www.yottalabs.ai/post/qwen-3-7-max-release-date-features-open-source-status-and-how-to-access-2026">&#8220;Qwen 3.7-Max: Pricing, Features, and How to Access&#8221;</a>, May 2026: Qwen3.7-Max is not open-weight, cannot be downloaded, and is API-only; no timeline announced for an open variant. On pricing, sources conflict on the exact figure (<a href="https://artificialanalysis.ai/models/qwen3-7-max">Artificial Analysis</a> reports $2.50/$7.50 per million input/output tokens; <a href="https://openrouter.ai/qwen/qwen3.7-max">OpenRouter</a> lists $1.475/$4.425), but all place Qwen3.7-Max well below both Kimi K3&#8217;s $15 and the Anthropic frontier tier &#8212; Alibaba has so far never backed a flagship claim with a frontier price.</p><p>[6] Alibaba Group Holding Ltd, <a href="https://www.sec.gov/Archives/edgar/data/1577552/000095017024063767/Financial_Report.xlsx">Form 20-F, fiscal year ended March 31, 2024</a>: &#8220;the Company invested a total of approximately US$0.8 billion (approximately RMB 5.9 billion) for an approximately 36% equity interest&#8221; in Moonshot, held as preferred stock and accounted for under the measurement alternative. Subsequent Moonshot funding rounds (Series B extension, Series C, and a further round in early 2026) have likely diluted this percentage; Alibaba has not disclosed an updated figure.</p><p>[7] Bloomberg, as cited in [2] and [3]: Moonshot reached $300 million in annual recurring revenue in June 2026 and plans to go public in as little as six months. The &#8220;most expensive Chinese model ever shipped&#8221; characterisation of Kimi K3&#8217;s $15 per million output tokens is per <a href="https://simonwillison.net/2026/Jul/16/kimi-k3/">Simon Willison&#8217;s launch analysis</a>, July 16, 2026.</p>]]></content:encoded></item><item><title><![CDATA[Kimi K3 and the Checkpoint Gap]]></title><description><![CDATA[How to read a Chinese frontier launch in the eleven days before the weights ship]]></description><link>https://www.airealist.ai/p/kimi-k3-and-the-checkpoint-gap</link><guid isPermaLink="false">https://www.airealist.ai/p/kimi-k3-and-the-checkpoint-gap</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Fri, 17 Jul 2026 06:44:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!91LW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!91LW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!91LW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!91LW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!91LW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!91LW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!91LW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1754825,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/207388116?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!91LW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!91LW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!91LW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!91LW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc332182b-0aaf-495b-b6fb-b5bf8b65510a_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">On July 16, Moonshot AI announced Kimi K3, a 2.8-trillion-parameter model it bills as the first open model in the 3-trillion-parameter class. The launch post is unusually candid for the genre. It states plainly that K3 trails the two strongest proprietary models, Claude Fable 5 and GPT-5.6 Sol, and its limitations section concedes &#8220;a noticeable gap in user experience&#8221; against both [1]. The press coverage was less careful: within hours, headlines had K3 pushing Chinese AI &#8220;into Fable-level territory&#8221; [2].</p><p style="text-align: justify;">Two numbers in the launch matter more than any benchmark score. The first is a price: <strong>$15 per million output tokens, the most expensive model a Chinese lab has ever shipped</strong> and nearly four times Moonshot&#8217;s own K2.6 [3]. The second is a date: the full weights are promised by July 27, 2026 [1]. Until then, every measurable claim about K3 passes through an API endpoint operated by Moonshot. The score that matters this week is not an Elo. It is a date.</p><p style="text-align: justify;">Call the window between those two events the Checkpoint Gap: the period when a model is priced, benchmarked, and covered as open, while the artifact that would let anyone verify it sits on the vendor&#8217;s servers. The industry has had a recent, expensive lesson in what can live inside that window. In April 2025, Meta submitted a chat-tuned variant of Llama 4 Maverick to the LMArena leaderboard, where it briefly ranked second. When the public weights were tested, the released model landed around 32nd, and LMArena rewrote its submission policies with an unusually direct rebuke [4]. The benchmarked model and the shipped checkpoint were not the same thing. Nobody outside Meta could have known before the weights landed.</p><p style="text-align: justify;">Nothing suggests Moonshot is running that play. The company&#8217;s record argues the opposite: Kimi K2 shipped open under a modified MIT license in July 2025, and K2.6 followed in April 2026 [5]. Moonshot&#8217;s benchmark footnotes are also more transparent than most Western launches, and they repay reading. K3 is evaluated with Moonshot&#8217;s own KimiCode evaluation harness on most coding benchmarks, while rivals run under Claude Code, Codex, or their best score across harnesses. Fable 5&#8217;s results may reflect a fallback to Opus 4.8 when it refuses a task. K3 itself currently runs at a single reasoning effort, its highest [6]. Where the harness effect can be isolated, it looks small: on DeepSWE, K3 scores 67.5 under KimiCode and 67.3 under the official leaderboard&#8217;s harness [6]. These are disclosed choices, not hidden ones. But disclosure is not verification. Until July 27, good faith and the Llama 4 play are indistinguishable from the outside, and the correct reading posture is the same for both.</p><p style="text-align: justify;">What independent evidence exists places K3 near the frontier, not at it &#8212; and even that evidence was gathered through Moonshot&#8217;s API. Artificial Analysis scores K3 at 57 on its Intelligence Index, behind Claude Fable 5 (around 60) and GPT-5.6 Sol (around 59) and comparable to Opus 4.8, and its private knowledge-work evaluation ranks K3 second only to Fable 5 [7]. Third place at launch from a lab that will hand you the weights is a remarkable result. It is not the frontier moving to Beijing. And note the tense the evaluator itself uses: once available, AA writes, K3 &#8220;would clearly lead&#8221; the open-weight field [7]. The conditional is doing the work. Even the independent scorekeeper is writing from inside the gap.</p><p style="text-align: justify;">The price is where this launch stops resembling every previous Chinese release. DeepSeek&#8217;s pitch never depended on benchmark verification: at $0.87 per million output tokens, 90% of the frontier was a bargain even if the numbers flattered [8]. K3 at $15 has exited the Chinese price war entirely. On the rate card, it is 17 times DeepSeek V4, level with Anthropic&#8217;s Sonnet tier, and 30% of Fable&#8217;s $50 [3][8]. On cost per completed task, a separate metric, AA&#8217;s estimate lands K3 at $0.94 &#8212; beside GPT-5.6 Sol at $1.04, half of Opus 4.8 at $1.80, and three times its open-weight peer GLM-5.2 [7]. </p><p style="text-align: justify;">Both metrics say the same thing: this model is priced with the frontier, not against it. Nobody pays that premium for third place unless the table holds. The rate card is Moonshot&#8217;s self-assessment denominated in dollars, and it converts the benchmark table from marketing garnish into the product justification. The Checkpoint Gap matters more for K3 than for any Chinese launch before it, because this is the first one to ask frontier prices for claims nobody can yet check.</p><p style="text-align: justify;">The gap closes on schedule, making the launch falsifiable in a way most are not. Three tests, all dated. </p><ol><li><p style="text-align: justify;">Do the weights ship by July 27, and does the released checkpoint match what the API has been serving?</p></li><li><p style="text-align: justify;">Do independent evaluations under a neutral harness reproduce the launch table? </p></li><li><p style="text-align: justify;">Where does third-party pricing settle? On that last test, temper expectations of a DeepSeek-style collapse toward the hosting floor. Moonshot recommends serving K3 on supernodes of 64 or more accelerators, so price competition will come from large inference providers, not from tiny GPU resellers [1]. If the $15 holds once alternatives exist, the market has accepted the frontier positioning. If it collapses, the price will launch in the theatre.</p></li></ol><p>Did the frontier move to China? Not on the evidence available today, and Moonshot&#8217;s own launch post doesn&#8217;t claim it did. What moved is the posture. DeepSeek priced like it had something to prove. Moonshot is pricing like it has already proved it, eleven days before anyone can check.</p><div><hr></div><h3>Notes</h3><p>[1] Moonshot AI, <a href="https://www.kimi.com/blog/kimi-k3">&#8220;Kimi K3: Open Frontier Intelligence&#8221;</a>, July 16, 2026. The weights date, API pricing ($0.30/MTok cache-hit input, $3.00/MTok cache-miss input, $15.00/MTok output), the concession that K3 trails Claude Fable 5 and GPT-5.6 Sol, the user-experience limitation, and the recommendation to deploy on supernodes of 64 or more accelerators all appear in the launch post. Vendor-published.</p><p>[2] Fortune, <a href="https://fortune.com/2026/07/16/moonshots-kimi-k3-pushes-chinese-ai-into-fable-level-territory/">&#8220;Moonshot&#8217;s Kimi K3 pushes Chinese AI into Fable-level territory&#8221;</a>, July 16, 2026.</p><p>[3] Simon Willison, <a href="https://simonwillison.net/2026/Jul/16/kimi-k3/">&#8220;Kimi K3, and what we can still learn from the pelican benchmark&#8221;</a>, July 16, 2026 &#8212; identifies K3 as the most expensive model released by a Chinese lab to date, at the level of Anthropic&#8217;s Claude Sonnet series. Kimi K2.6 pricing ($0.95/MTok input, $4/MTok output) per <a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot&#8217;s platform documentation</a>.</p><p>[4] The Register, <a href="https://www.theregister.com/2025/04/08/meta_llama4_cheating/">&#8220;Meta accused of Llama 4 bait-n-switch to juice LMArena rank&#8221;</a>, April 8, 2025. LMArena stated Meta&#8217;s interpretation of its submission rules &#8220;did not match what we expect from model providers&#8221; in its April 2025 policy update; the released Maverick&#8217;s subsequent placement around 32nd is documented in <a href="https://the-decoder.com/metas-llama-4-models-show-promise-on-standard-tests-but-struggle-with-long-context-tasks/">The Decoder&#8217;s follow-up coverage</a> of the leaderboard.</p><p>[5] Moonshot AI, <a href="https://www.kimi.com/blog/kimi-k2">&#8220;Kimi K2: Open Agentic Intelligence&#8221;</a>, July 2025, and <a href="https://www.kimi.com/blog/kimi-k2-6">&#8220;Kimi K2.6&#8221;</a>, April 2026.</p><p>[6] Moonshot K3 launch post [1], benchmark footnotes 1&#8211;8. Harness assignments per benchmark, the Fable 5 fallback condition, the single (maximum) reasoning effort at launch, and the DeepSWE dual-harness scores (67.5 under KimiCode; 67.3 under the official leaderboard&#8217;s mini-SWE-agent harness) are all disclosed there.</p><p>[7] Artificial Analysis, <a href="https://x.com/ArtificialAnlys/status/2077832874183860404">Kimi K3 launch evaluation</a> and <a href="https://artificialanalysis.ai/models/kimi-k3">model page</a>, July 16, 2026. Intelligence Index: K3 at 57, behind Claude Fable 5 and GPT-5.6 Sol and comparable to Opus 4.8 and GPT-5.5. AA-Briefcase (private long-horizon knowledge work): Elo 1547, second behind Claude Fable 5. Cost per task is AA&#8217;s evaluation-derived estimate, not a market price: K3 $0.94, GPT-5.6 Sol $1.04, Claude Opus 4.8 $1.80, GLM-5.2 $0.32. One counterweight AA also reports: K3 generated 130M output tokens across the Index against a 63M median for comparable reasoning models, so on verbose workloads the rate card understates effective cost &#8212; a consequence of the single maximum reasoning effort available at launch. The open-weight comparison (&#8221;would clearly lead&#8221; GLM-5.2 and DeepSeek V4 Pro) is AA&#8217;s own phrasing, stated in the conditional pending the weight release.</p><p>[8] Fortune [2] for comparative output-token pricing: DeepSeek V4 at $0.87, z.ai&#8217;s GLM-5.2 at $4.40, and Claude Fable at $50 per million output tokens.</p>]]></content:encoded></item><item><title><![CDATA[The Backstop Has a Name Now - part 2]]></title><description><![CDATA[How Nvidia finances a cloud tells you what it thinks the cloud is worth. CoreWeave and Nebius got equity. Sharon AI got a revenue-share.]]></description><link>https://www.airealist.ai/p/the-backstop-has-a-name-now-part-11d</link><guid isPermaLink="false">https://www.airealist.ai/p/the-backstop-has-a-name-now-part-11d</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Mon, 06 Jul 2026 09:05:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4W_6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4W_6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4W_6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4W_6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1924676,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/205041043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4W_6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!4W_6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcab7276f-929f-489b-a6e3-7abc7f11aee0_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Ask why Nvidia took equity in the neoclouds it works with &#8212; CoreWeave, Nebius, even Firmus, its own revenue-share launch partner &#8212; and took none in Sharon AI, and the answer is in the instrument itself.</p><p style="text-align: justify;">Start with what Nvidia does for the clouds that made it. CoreWeave has been public since March 2025; it carries more than $20 billion of debt and once looked reckless to venture investors, but it borrows against investment-grade, asset-backed paper &#8212; an $8.5 billion facility rated A3, secured by the chips and the customer contracts, at roughly SOFR plus 2.25 percent.[1] Nebius, the old Yandex reconstituted on Nasdaq, posted positive adjusted EBITDA in the first quarter of 2026, raised more than $6 billion this year, and ended the quarter with $9.3 billion in cash.[2] Both are anchored by hyperscalers whose contracts pay in advance: CoreWeave by Microsoft, Nebius by Meta and Microsoft, on deals worth tens of billions.[3] And into both, Nvidia put equity &#8212; $2 billion into CoreWeave in January, $2 billion into Nebius in March, the same instrument it used that season in Lumentum and Coherent.[4]</p><p style="text-align: justify;">Equity is the tell. It is a bet on enterprise value: a junior claim that pays only if the company becomes worth something, which it has for these two. Nvidia takes equity where there is value to own. It did not offer Sharon AI equity, and it would not, because the thing a revenue-share does that equity cannot is sit senior to the shareholders, a claim on revenue paid off the top, ahead of a stake that may end up worthless. How Nvidia chooses to finance a cloud is a readout of what it thinks the cloud is worth. See value, and it buys in. See doubt, and it keeps its distance: a claim on the revenue, a loan to produce it, and no share of the company.</p><p style="text-align: justify;">The counterparty side complicates the neat version. CoreWeave and Nebius fund their buildouts with investment-grade debt and hyperscaler prepayments, so they never needed Nvidia&#8217;s financing. Firmus and Sharon AI did take it, and Firmus is worth $5.5 billion, so a revenue share is not, by itself, a mark of distress. It is how a buildout gets financed quickly, as Nvidia&#8217;s own chief financial officer frames it: a way to serve companies with demand but who cannot secure financing quickly enough.[5] The instrument opens a new recurring revenue line for Nvidia. What separates the two who took it is whether Nvidia also wanted to own them.</p><p style="text-align: justify;">The debt market already sorts AI borrowers by distance from cash: Amazon borrows unsecured, Oracle against backlog, SoftBank could not borrow against a private mark at all.[6] The revenue-share program is what sits below SoftBank&#8217;s rung, where the debt market says no and Nvidia says yes, through an instrument no bank would offer. It is a familiar move under a new name. An earlier piece called it the Overbuild Put: a company financing a buildout it might not fill names its own backstop, and the backstop is the giveaway.[7] Meta named its exit, a cloud business it might have to start if it overbuilt. Sharon AI&#8217;s exit is named for it, by Nvidia; the credit support is the backstop that lets a buildout proceed whose demand is unproven. The difference is who writes the text. Meta wrote one on its own capacity. Nvidia writes one on Sharon AI&#8217;s, the supplier backstopping the demand of a customer it also sells to.</p><p style="text-align: justify;">The February COMECON piece argued Nvidia holds the independent cloud tier captive; Part 1 named the productized version.[8] The line is not equity versus revenue-share, since Firmus took both; it is ownership versus none. Nvidia holds a stake in CoreWeave, Nebius, and Firmus. In Sharon AI, it holds only a claim.</p><h2>What &#8220;fragile enough to sign&#8221; looks like</h2><p style="text-align: justify;">Sharon AI is the exhibit, the one launch partner Nvidia financed but would not own. Firmus, the other, raised $505 million at a $5.5 billion valuation with Nvidia among its backers;[4] whatever else it is, it is not the bottom of the ladder. Sharon AI&#8217;s own filings tell most of the story before any short seller does.</p><p style="text-align: justify;">At the end of March, the company held $164 million in cash and no revenue; its filings do not expect revenue to begin until September, and operating cash flow is negative, with a capital-expenditure requirement of about $720 million to support its lead contract.[9] Against the cash are two customer contracts totaling $1.26 billion and a second worth roughly $950 million.[10] Its reported quarterly loss of $20 million is mostly an accounting artifact: the company carries its convertible notes at fair value, so remeasuring them drove a $70 million loss through the income statement, offset by a $66 million gain on the sale of half of a Texas data-center joint venture.[11] A company whose reported profit swings with the value of its own debt and whose cash comes from an IPO and asset sales rather than operations is being valued on a chain of announcements, not cash flow. There is none yet.</p><p style="text-align: justify;">The build is financed by a stack of commitments, each conditioned on the next. A $200 million facility from an investor called Digital Alpha and a $500 million facility from USD.AI, a roughly one-year-old decentralized-finance protocol, were both announced as &#8220;up to&#8221; and, per a short report, remained unexecuted months later.[12] In May, the company closed $350 million of convertible notes led by Oaktree. Per the same report, those notes were funded only if Sharon AI first signed a binding contract for at least 4,068 additional GPUs, its lender declining to treat the announced $1.26 billion in demand as sufficient collateral.[13] In June, it raised an additional $1.6 billion.[14] And on June 12 came the keystone, the six-year Nvidia deal, whose filing language says it is &#8220;structured so that Sharon AI can commit to large-scale NVIDIA infrastructure&#8221; through the revenue-share and credit-support.[15] Nvidia&#8217;s credit line is the piece that lets the rest of the tower stand.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9jrC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9jrC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 424w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 848w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 1272w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9jrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png" width="1639" height="2124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2124,&quot;width&quot;:1639,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:403924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/205041043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57cac719-a074-4811-9ba9-a948e6d4e23c_1640x2400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9jrC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 424w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 848w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 1272w, https://substackcdn.com/image/fetch/$s_!9jrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2edaa882-2e11-4e34-9fd5-f514df57e083_1639x2124.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Then the customer, where the short case overreaches, and the real point is sharper. Sharon AI&#8217;s forward revenue rests on the $1.26 billion contract with ESDS Software Solution, and ESDS is not a shell. It is an established Indian cloud provider with roughly &#8377;361 crore (about $43 million) in revenue last fiscal year, up 27 percent, profitable, lightly indebted, and preparing an IPO of its own.[16] The problem is scale, not solvency. The contract calls for average annual payments of roughly $250 million and $140 million in letters of credit; the annual figure alone is six times ESDS&#8217;s entire revenue.[17] A real $43 million company can be a real counterparty to a contract its own size; whether it can perform one thirty times larger is the open question, and it is the same question Sharon AI&#8217;s own lender asked. The chief executive brings his own history. Manning&#8217;s prior public company, Mawson Infrastructure Group, alleges in court filings that he directed roughly A$11.5 million to a shipping firm he controlled without disclosing his interest to the board, allegations he contests and that remain unadjudicated. That same firm, Flynt, is now a disclosed related-party vendor of Sharon AI, according to the company&#8217;s own prospectus.[18] None of this has stopped the stock, which has risen sharply; the market has not endorsed the short thesis.[19] But it is the profile of an operator that could not fund this build on ordinary terms, which is why the revenue-share was there to be signed.</p><p style="text-align: justify;">One detail seals the instrument argument. Nvidia holds no equity in Sharon AI; its annual report called Nvidia a &#8220;strategic shareholder&#8221; and the company filed a correction stating Nvidia owns none.[20] It invested $2 billion in equity in each of CoreWeave and Nebius, and took a stake in Firmus, its own revenue-share partner. Only in Sharon AI did it take a revenue-share, a credit claim, and no ownership at all, because what it is underwriting here is not an asset it wants to hold. It is a demand that needs to be kept alive.</p><h2>What comes next</h2><p style="text-align: justify;">The rule generalizes, and it is the thing to take from Sharon AI. When a supplier finances its own customer, the instrument it chooses is a private credit rating, better informed than the market&#8217;s, because the supplier sits inside the relationship. Equity is the vote of confidence. The revenue share is how the buildout gets paid for, and Firmus, worth $5.5 billion, took one too. What sets Sharon AI apart is the equity Nvidia declined to take. Call it the Instrument Test: read what a vendor takes, not what it announces. It travels beyond Nvidia: whenever a vendor lends to the customers who buy its product, the instrument encodes what the vendor privately believes, and usually before the tape does.</p><p style="text-align: justify;">Which makes the program itself an indicator. Nvidia split its partners by what it was willing to own: it took a stake in CoreWeave, Nebius, and Firmus, and in Sharon AI it took only a claim. As the program spreads, watch which companies get a revenue share with no stake besides it. That pairing, not the revenue-share alone, is the readout of how far down the counterparty-quality curve Nvidia is reaching, and it moves before the market does, because it is Nvidia&#8217;s own hand showing. When the next partner arrives with a credit line and no equity cheque, Nvidia is saying, in the one language it cannot fake, that it is a company it will finance but will not own. And note the second edge. When a chip vendor&#8217;s credit support helps fund the purchase of its own chips and then collects a share of the revenue those chips generate, the revenue is partly its own money coming home &#8212; the same round-trip that ran at the hyperscaler layer, now reaching the bottom of the neocloud tier.[21]</p><p style="text-align: justify;">A fair objection remains: a revenue-share cuts both ways. If an operator&#8217;s utilization falls, so does Nvidia&#8217;s cut, so this is exposure to Sharon AI&#8217;s success, not merely a claim on it. But exposure to the success of the operators least likely to deliver it is either deep conviction or the position of a supplier that has run out of stronger customers to sell to.</p><p style="text-align: justify;">CoreWeave was fragile once, too, and became a company worth billions; one of these operators may do the same, and Oaktree and Goldman are betting on it. But read the instrument. In CoreWeave, Nebius, and Firmus, Nvidia is a shareholder, betting the company wins. In Sharon AI it is a creditor, arranging to be paid whether it wins or not. Which seat a supplier takes says more than any forecast it offers. And at the bottom of the ladder, Nvidia took the creditor&#8217;s.</p><div><hr></div><h3>Notes</h3><p>[1] CoreWeave (Nasdaq: CRWV) listed March 28, 2025; total debt now exceeds $21 billion. Its March 2026 $8.5 billion facility is rated A3/A(low), secured by substantially all assets of the borrower group, at SOFR + 2.25% floating or ~5.9% fixed, maturing March 2032, and is the first investment-grade-rated GPU-backed financing: <a href="https://sacra.com/c/coreweave/">Sacra</a>; <a href="https://qz.com/gpu-collateralized-debt-ai-neocloud-coreweave-financing-risks-050526">Quartz</a>. Its credit agreement requires contracts with &#8220;large and creditworthy&#8221; customers covering future debt repayments.</p><p>[2] Nebius Group (Nasdaq: NBIS), formerly Yandex N.V., resumed Nasdaq trading October 2024. Q1 2026: revenue $399M (+684% YoY); positive adjusted EBITDA (~45% AI-cloud margin) and net income of $621.2M (inclusive of non-operating items); more than $6 billion raised in 2026 ($4.3B convertible notes plus Nvidia&#8217;s equity), ending the quarter with $9.3B in cash: <a href="https://www.tikr.com/blog/nebius-grew-revenue-684-in-q1-sold-out-its-entire-capacity-and-raised-its-capex-target-to-25-billion">TIKR</a>; <a href="https://simplywall.st/stocks/us/software/nasdaq-nbis/nebius-group">Simply Wall St</a>.</p><p>[3] CoreWeave&#8217;s anchor customer is Microsoft; Nebius holds a five-year ~$27B Meta agreement and a ~$17&#8211;19.4B Microsoft agreement, with hyperscaler prepayments helping fund capex: <a href="https://www.forbes.com/sites/rashishrivastava/2025/09/22/coreweaves-29-billion-bet-that-its-debt-fueled-ai-boom-wont-go-bust/">Forbes</a>; <a href="https://www.morningstar.com/stocks/this-ai-cloud-stock-is-up-over-300-year-can-it-rise-further">Morningstar</a>.</p><p>[4] Nvidia made a $2 billion private placement in CoreWeave in January 2026 (22,935,780 Class A shares at $87.20) as part of an expanded collaboration targeting more than 5 GW by 2030, and agreed to purchase CoreWeave&#8217;s unsold capacity through 2032: <a href="https://sacra.com/c/coreweave/">Sacra</a>; <a href="https://www.forbes.com/sites/rashishrivastava/2025/09/22/coreweaves-29-billion-bet-that-its-debt-fueled-ai-boom-wont-go-bust/">Forbes</a>. Its $2 billion equity investment in Nebius (March 11, 2026) mirrored $2 billion investments in Lumentum and Coherent the same month: <a href="https://mlq.ai/news/nvidia-invests-2-billion-in-nebius-to-advance-ai-cloud-infrastructure/">MLQ News</a>. Nvidia also holds equity in Firmus, having joined a 2025 round and participated in Firmus&#8217;s April 2026 US$505 million round at a US$5.5 billion valuation led by Coatue; the April participation was reported subject to closing conditions. Firmus separately arranged a US$10 billion debt facility. Verify against Firmus&#8217;s April 2026 funding release before publication.</p><p>[5] Nvidia CFO Colette Kress, framing the program as serving companies with demand that cannot secure financing quickly enough: <a href="https://blogs.nvidia.com/blog/nvidia-unlocks-ai-compute-at-scale-capital-partners-to-power-ai-infrastructure-buildout/">NVIDIA blog, July 1, 2026</a>.</p><p>[6] &#8220;Cash Flow Lends. Valuation Doesn&#8217;t.,&#8221; The AI Realist, <a href="https://www.airealist.ai/p/cash-flow-lends-valuation-doesnt">June 12, 2026</a>.</p><p>[7] &#8220;The Overbuild Put,&#8221; The AI Realist, <a href="https://www.airealist.ai/p/the-overbuild-put">June 1, 2026</a> &#8212; reading a fallback-monetisation or backstop remark as a credit signal on a debt-financed buildout whose demand is unproven.</p><p>[8] &#8220;Jensen&#8217;s COMECON: How Nvidia Built an Empire of Captive Clouds,&#8221; The AI Realist, <a href="https://www.airealist.ai/p/jensens-comecon-how-nvidia-built">Feb. 14, 2026</a>; &#8220;The Backstop Has a Name Now (Part 1),&#8221; The AI Realist, July 2026 <em>(confirm published slug before linking)</em>.</p><p>[9] SharonAI Holdings Inc., Form 10-Q for the quarter ended March 31, 2026 (cash $164,288,288; negative operating cash flow; revenue commencement not expected until approximately September 2026), attached to the Company&#8217;s Form 424B3, <a href="https://www.sec.gov/Archives/edgar/data/0002068385/000149315226030359/form424b3.htm">SEC EDGAR (CIK 0002068385)</a>. Approximately $720 million of capital expenditure is tied to the lead customer arrangement per the same filing.</p><p>[10] ESDS master services agreement of $1,260,000,000 and a second customer contract of approximately $950,000,000, per the Form 424B3 referenced in [9].</p><p>[11] Fair-value option elected on the convertible notes (Level 3); Q1 2026 included a $70.2 million loss on remeasurement and a $65,919,712 gain on the sale of a 50% interest in the Texas Critical Data Centers joint venture; convertible-note fair value of $199,358,226 as of March 31, 2026 (Form 424B3, [9]).</p><p>[12] Announcements of a Digital Alpha facility of up to $200 million (Jan. 19, 2026, subject to definitive documentation) and a USD.AI facility of up to $500 million (Jan. 22, 2026). Characterisations of USD.AI&#8217;s on-chain capacity and the unexecuted status of the Digital Alpha facility are from <a href="https://www.bleeckerstreetresearch.com/research/shaz">Bleecker Street Research, &#8220;SharonAI (SHAZ),&#8221; April 30, 2026</a> (a short seller with a disclosed position).</p><p>[13] <a href="https://www.sec.gov/Archives/edgar/data/0002068385/000149315226024865/ex99-1.htm">SharonAI Form 8-K, Exhibit 99.1 (closing of $350 million of convertible senior notes due 2031, led by Oaktree), May 2026, SEC EDGAR</a>. The 4,068-GPU closing condition is as characterised in the Bleecker Street report ([12]); confirm against the note purchase agreement before publication.</p><p>[14] SharonAI&#8217;s oversubscribed $1.6 billion private placement (approximately $900 million equity and $700 million of 4.75% convertible notes due 2032), June 2026, with Goldman Sachs as lead placement agent: <a href="https://www.benzinga.com/markets/equities/26/06/60177706/sharon-ai-jumps-nearly-12-after-hours-what-is-going-on-with-shaz-stock">Benzinga</a>.</p><p>[15] Six-year Nvidia collaboration (72 MW, up to 40,000 Grace Blackwell GB300), per the Company&#8217;s June 12, 2026 announcement reproduced in the Form 424B3 ([9]).</p><p>[16] ESDS Software Solution Limited, FY2025 (year ended March 31, 2025): total revenue &#8377;361 crore (~$43 million), up 27% year over year; profit before tax up nearly fourfold; debt-to-equity of 0.15 and current ratio of 2.32; DRHP filed March 30, 2025 for a &#8377;600 crore IPO on the BSE and NSE: <a href="https://unlistedzone.com/esds-software-solution-limited-a-transformative-year-and-a-promising-future">unlistedzone</a>; <a href="https://wwipl.com/unlisted-shares/esds-software-solution-limited/financial">ESDS financials via WWIPL</a>. Verify against ESDS&#8217;s audited DRHP financials before publication.</p><p>[17] The $250 million average annual payment and the $140 million letter-of-credit obligation are per the Bleecker Street report ([12]); confirm against the master services agreement before publication.</p><p>[18] Mawson Infrastructure Group Inc. (Nasdaq: MIGI) alleges, in its January 10, 2025 court filing, that James Manning, its former chief executive, caused the company to pay over A$11.4 million to Flynt International Cargo Solutions (a Vertua subsidiary) for services it &#8220;did not need,&#8221; without disclosing his interest or seeking board approval: <a href="https://www.sec.gov/Archives/edgar/data/1218683/000117184325000166/exh_991.htm">Mawson Form 8-K, Exhibit 99.1, SEC EDGAR</a>. The allegations are unadjudicated and contested. SharonAI&#8217;s own prospectus discloses Flynt ICS as a related-party vendor: &#8220;Flynt is a subsidiary of Vertua Limited and affiliated to the Group through common ownership by James Manning,&#8221; and the Group paid Flynt $167,638 in services expenses for the year ended December 31, 2024.</p><p>[19] Public market data as of early July 2026; SHAZ has risen sharply since the April 30 short report, and the market has not validated the short thesis.</p><p>[20] SharonAI corrected its FY2025 Form 10-K, which had described NVIDIA as a &#8220;strategic shareholder,&#8221; to state that NVIDIA holds no equity securities of the Company: <a href="https://www.stocktitan.net/sec-filings/SHAZ/8-k-sharon-ai-holdings-inc-reports-material-event-05a155b67636.html">SharonAI Form 8-K correction (SEC EDGAR)</a>.</p><p>[21] &#8220;The Round Trip,&#8221; The AI Realist, <a href="https://www.airealist.ai/p/the-round-trip">May 4, 2026</a>.</p>]]></content:encoded></item><item><title><![CDATA[The Backstop Has a Name Now - part 1]]></title><description><![CDATA[Nvidia is handing back tens of billions to shareholders. Now it&#8217;s offering to finance the customers who can&#8217;t afford its chips.]]></description><link>https://www.airealist.ai/p/the-backstop-has-a-name-now-part</link><guid isPermaLink="false">https://www.airealist.ai/p/the-backstop-has-a-name-now-part</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Sat, 04 Jul 2026 06:09:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JgWl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JgWl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JgWl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JgWl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1518863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/205016499?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JgWl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!JgWl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8adde3b5-b47b-4eca-a548-ebd803555260_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">In its most recent quarter, Nvidia returned a record $20 billion to shareholders. In May, its board authorized another $80 billion in buybacks; in June, it raised $25 billion in the bond market &#8212; the balance sheet of a company with no financing problem of its own.[1] On July 1, it announced a program to help companies that cannot afford its chips buy them anyway, in exchange for a share of the profits.[2]</p><p style="text-align: justify;">The two sit oddly together. A company that hands out that much to shareholders does not usually need to lend to its own customers.</p><p style="text-align: justify;">In February, I called this the <a href="https://www.airealist.ai/p/jensens-comecon-how-nvidia-built">COMECON model</a>: Nvidia keeps the independent GPU clouds, the neoclouds, captive through four instruments: GPU allocation, equity stakes, credit enhancement, and demand backstops.[3] On July 1, it took two of them, the credit enhancement and the backstop, and gave them a product name.</p><p style="text-align: justify;">The program is a &#8220;revenue-sharing and credit-support model.&#8221; A cloud puts Nvidia GPUs on the floor without carrying the full capital cost, draws token credits against future capacity today, and hands Nvidia its standard hardware margin plus a recurring, usage-linked share of the cloud revenue that capacity generates.[2] How large that share is, Nvidia has not said. The first named partners are Sharon AI, deploying up to 40,000 Grace Blackwell GB300s in Australia, and Firmus, building toward 360 megawatts and 170,000 GPUs in Batam, Indonesia.[4] The arrangement is not wholly new; Nvidia ran a demand backstop with CoreWeave and took an equity stake in OpenAI. What is new is the packaging: the credit support and a revenue-share leg under one name, one template, one marketing page.[5]</p><p style="text-align: justify;">The bullish read wrote itself within hours: recurring revenue, a widening moat, and a supplier tying itself to customer usage rather than a single sale. The bearish read wrote itself too: circular financing, vendor-funded demand, the fiber and telecom buildouts in period costume. Both are on offer. Neither is the question that matters.</p><p style="text-align: justify;">The question that matters is why the market's strongest supplier is doing this now. The answer isn&#8217;t on Nvidia&#8217;s blog; it&#8217;s on its customers&#8217; earnings calls.</p><p style="text-align: justify;">On April 29, Google said it would begin delivering its TPUs to a select group of customers for their own data centers, its formal move into the merchant-silicon market Nvidia has long dominated.[6] Weeks later, AWS confirmed it is exploring selling Trainium to outside data centers.[7] For a decade, the hyperscalers built custom chips and kept them in-house; in 2026, both began selling them. Nvidia&#8217;s largest customers are becoming its competitors, from the top of the stack down. (I argued in May that Google is the one to watch: its chip runs its own frontier models, while Amazon&#8217;s mostly runs rented workloads &#8212; the line that separates a silicon business from a silicon cost center.[8])</p><p style="text-align: justify;">Take Nvidia&#8217;s case at its strongest. The financing gap is real; lenders have been wary of hardware whose resale value no one can yet model, so builders with genuine demand still can&#8217;t get compute funding fast enough. The inference tenants Nvidia names alongside the program (Baseten, Fireworks AI, Together AI) are well-capitalized companies, not strays. And a revenue-share cuts both ways: if a partner&#8217;s utilization falls, so does Nvidia&#8217;s cut. That is exposure to the customer&#8217;s success, not a lien on it. On its own terms, the program clears a bottleneck and aligns incentives, and that reading is not wrong.</p><p style="text-align: justify;">It is incomplete because of when it arrived. A supplier that spent a decade as the only game in town does not wander into neocloud finance in the same quarter that its two largest customers start selling their own chips. The gap is real; the timing is no coincidence; the calendar tips the scales toward defense. Whatever else it does, the program buys the loyalty of the layer beneath the hyperscalers, the independent clouds with no silicon of their own; at the moment, the layer above turns competitive. The revenue-share ties their economics to Nvidia&#8217;s; the credit-support makes Nvidia the reason some of them can exist at all.</p><p style="text-align: justify;">There is a sharper edge, and it is the subject of the next piece. Nvidia&#8217;s CFO frames the program as serving companies that have demand but cannot secure financing fast enough; even long-term commitments haven&#8217;t unlocked the capital.[9] That describes the borrowers that conventional lenders turn away. </p><div class="pullquote"><p style="text-align: center;">How far down the collateral ladder the model reaches is the open question. </p></div><p style="text-align: justify;">Firmus is a large greenfield campus and is not obviously a distressed borrower. Sharon AI, the other named partner, is another matter: it was listed on Nasdaq in February and carries a market capitalization above a billion dollars on almost no revenue, and its financing stack and headline contracts are already the subject of a detailed short-seller report.[10] I&#8217;ll take those allegations through the primary filings next. Nvidia, for the record, holds no equity in it; the hold runs entirely through the revenue-share and the credit line.[11]</p><p style="text-align: justify;">The backstop was always there; on July 1, it got a name, which is what usually happens to an improvisation just before it becomes a system. Whether it is mostly defense or mostly reach, the next deals will say. If the template stays with capital-constrained clouds, it is the base-reinforcement it looks like; if Nvidia extends it to well-funded clouds that could finance the GPUs themselves, the defensive read was wrong, and this is Nvidia annexing cloud economics wherever it can. Either way, the neocloud it piloted on is where the risk is hiding, and the filings are where the next piece goes.</p><div><hr></div><h3>Notes</h3><p>[1] NVIDIA returned approximately $20 billion to shareholders in Q1 FY2027, and its board authorized an additional $80 billion in repurchases on May 18, 2026: <a href="https://www.sec.gov/Archives/edgar/data/0001045810/000104581026000051/q1fy27pr.htm">NVIDIA Q1 FY2027 results (Form 8-K), SEC EDGAR</a>. The $25 billion multi-tranche notes offering priced on June 18, 2026: <a href="https://www.sec.gov/Archives/edgar/data/0001045810/000119312526275783/d48176d8k.htm">NVIDIA Form 8-K, June 18, 2026, SEC EDGAR</a>.</p><p>[2] <a href="https://blogs.nvidia.com/blog/nvidia-unlocks-ai-compute-at-scale-capital-partners-to-power-ai-infrastructure-buildout/">NVIDIA Unlocks AI Compute at Scale, NVIDIA blog, July 1, 2026</a> (co-authored by CFO Colette Kress).</p><p>[3] <a href="https://www.airealist.ai/p/jensens-comecon-how-nvidia-built">Jensen&#8217;s COMECON: How Nvidia Built an Empire of Captive Clouds, The AI Realist, Feb. 14, 2026</a>.</p><p>[4] Firmus scale from NVIDIA blog [2]; Sharon AI terms (six-year collaboration, 72MW of new Australian capacity, up to 40,000 Grace Blackwell GB300) from <a href="https://finance.yahoo.com/sectors/technology/articles/sharon-ai-announces-six-strategic-112000755.html">SharonAI Holdings, &#8220;Six Year Strategic Compute Collaboration with NVIDIA,&#8221; June 12, 2026</a> (BusinessWire; corresponds to the Company&#8217;s Form 8-K filed June 12, 2026).</p><p>[5] The credit-support and backstop model packages arrangements Nvidia previously ran case by case &#8212; a demand backstop with CoreWeave and a reported ~$30 billion equity investment in OpenAI (a separate data-center lease guarantee was reported to be under discussion, not executed, as of mid-2026): <a href="https://aiweekly.co/alerts/nvidia-launches-revenue-share-model-with-sharon-ai-firmus">AI Weekly, July 2026</a>.</p><p>[6] Sundar Pichai, Alphabet Q1 FY2026 earnings call, April 29, 2026: <a href="https://www.datacenterdynamics.com/en/news/google-to-sell-tpus-to-a-select-group-of-customers-for-their-data-centers/">Google to sell TPUs to a &#8220;select group of customers,&#8221; Data Center Dynamics</a>.</p><p>[7] AWS signaled external Trainium sales in Andy Jassy&#8217;s April 2026 shareholder letter (<a href="https://thenextweb.com/news/amazon-custom-chips-jassy-letter-fifty-billion-trainium">The Next Web</a>); AWS&#8217;s Peter DeSantis confirmed exploratory talks in June 2026 (reported by Bloomberg; <a href="https://www.electronicsforyou.biz/industry-buzz/aws-weighs-selling-trainium-ai-chips-in-challenge-to-nvidia/">summary</a>).</p><p>[8] <a href="https://www.airealist.ai/p/two-chips-one-decade-one-winner">Two Chips, One Decade, One Winner, The AI Realist, May 27, 2026</a>.</p><p>[9] CFO framing that the program targets companies with demand but insufficient access to financing: <a href="https://finance.yahoo.com/technology/ai/articles/nvidia-launches-revenue-sharing-model-131824248.html">Nvidia launches revenue-sharing model, Yahoo Finance, July 2026</a>; see also NVIDIA blog [2].</p><p>[10] <a href="https://www.bleeckerstreetresearch.com/research/shaz">Bleecker Street Research, &#8220;SharonAI (SHAZ),&#8221; April 30, 2026</a>. Report authored by a short seller with a disclosed position; allegations to be examined against primary filings in the follow-up piece.</p><p>[11] SharonAI corrected its FY2025 Form 10-K, which had described NVIDIA as a &#8220;strategic shareholder,&#8221; to state that NVIDIA holds no equity securities of the company: <a href="https://www.stocktitan.net/sec-filings/SHAZ/8-k-sharon-ai-holdings-inc-reports-material-event-05a155b67636.html">SharonAI Holdings Form 8-K correction</a>.</p>]]></content:encoded></item><item><title><![CDATA[The Models That Learned Physics]]></title><description><![CDATA[Generative AI isn&#8217;t just chatbots and code. The transformer architecture has quietly generalized far past language, and the next domain it&#8217;s reaching is the physical world.]]></description><link>https://www.airealist.ai/p/the-models-that-learned-physics</link><guid isPermaLink="false">https://www.airealist.ai/p/the-models-that-learned-physics</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Tue, 30 Jun 2026 09:27:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k66J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k66J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k66J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 424w, https://substackcdn.com/image/fetch/$s_!k66J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 848w, https://substackcdn.com/image/fetch/$s_!k66J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 1272w, https://substackcdn.com/image/fetch/$s_!k66J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k66J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png" width="1424" height="752" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:752,&quot;width&quot;:1424,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1918220,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/204116576?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k66J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 424w, https://substackcdn.com/image/fetch/$s_!k66J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 848w, https://substackcdn.com/image/fetch/$s_!k66J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 1272w, https://substackcdn.com/image/fetch/$s_!k66J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe10a8c9c-68ef-4a6b-b464-a3515dd1330e_1424x752.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><em><span>Disclosure: </span><a href="https://www.simcon.ai"><span>Simcon</span></a><span>, used here as a worked example, is a portfolio company of </span><a href="https://www.fortino.capital"><span>Fortino Capital</span></a><span>, where I am an AI operating partner. I&#8217;ve kept this piece to what Simcon has already made public, and the </span><a href="https://www.simcon.ai/en/solutions/cadmould-ai-solver-live-demo"><span>live demo</span></a><span> is open to anyone.</span></em></p><p style="text-align: justify;"><span>The conversation about generative AI has narrowed to two things it does extremely well: write text and write code. But that is a small slice of what the underlying machine turned out to be good at.</span></p><p style="text-align: justify;"><span>The transformer was built for language. Then it generalized. The same architecture that predicts the next word learned to generate images, then to model protein structures, then to forecast time series and weather. Each jump landed in a domain that looked nothing like the last, and each time the lesson repeated: feed a transformer enough diverse examples of a thing, and it learns a representation of that thing general enough to handle inputs it never saw.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U5cV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U5cV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 424w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 848w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 1272w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U5cV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png" width="1456" height="618" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:618,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U5cV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 424w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 848w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 1272w, https://substackcdn.com/image/fetch/$s_!U5cV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ec8dc8b-876e-42c0-bb83-0f1e187d46df_2048x869.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><span>So here is the question that follows naturally and almost nobody is asking out loud: what happens when you point it at industrial engineering data and complex 3D physics? Not text, not pixels: the airflow over a car, the heat moving through a turbine, the way molten plastic fills a mold. The data that engineers generate daily by the terabyte, which never touches the public internet.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.airealist.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.airealist.ai/subscribe?"><span>Subscribe now</span></a></p><h2 style="text-align: justify;"><span>The part of AI that doesn&#8217;t read</span></h2><p style="text-align: justify;"><span>Everything the frontier labs compete on is trained on the internet: text, code, images, and video. That data is effectively a global commons: everyone scrapes the same web, so no one owns the input.</span></p><p style="text-align: justify;"><span>The physical world is the opposite. The data that describes it lives inside the companies that build things, and it never gets posted anywhere. Decades of crash tests, wind-tunnel runs, thermal cycles, material trials, and &#8212; the unsung hero of modern engineering &#8212; simulation results. Before a car, a phone case, or a medical device gets built, engineers simulate it. Simulations are used to predict and optimize the quality and cost issues that will arise during manufacturing and how the parts will behave in the real world. The result is fewer costly defects in the real world. To predict the physics, they run numerical solvers that chew through large systems of partial differential equations, which is computationally intensive. These runs are slow, expensive, and have been the backbone of industrial design for decades.</span></p><p style="text-align: justify;"><span>They are also a training set. Every solver run is a labeled example: this target geometry, these conditions, this outcome. A company that has run millions of them is sitting on something no web scraper can ever reach.</span></p><p style="text-align: justify;"><span>The bet behind Physics AI is that you can train a model on that simulation output, the way a language model is trained on text, and get a network that has, in effect, learned the physics. Not the equations. The behavior. Feed it a shape it has never seen, and it predicts the result, in seconds, without solving anything.</span></p><p style="text-align: justify;"><span>The category now has a name: Large Engineering Models. The label is deliberate. It claims the same lineage as Large Language Models &#8212; the same transformer architecture underneath, the same idea that scale and diverse data produce something that generalizes &#8212; but is trained on the physical world rather than language.</span></p><h2 style="text-align: justify;"><span>Why this didn&#8217;t work before</span></h2><p style="text-align: justify;"><span>Engineers have wanted fast simulation forever, and the idea of replacing a slow solver with a fast approximation is old. The approximations are called surrogate models, and until recently, they came with a catch that made them nearly useless for real design work.</span></p><p style="text-align: justify;"><span>A classical surrogate is fitted to a specific problem. Train it on one family of parts, and it interpolates nicely within that family. It also falls apart the moment you hand it a geometry it hasn't seen before. It learned the answers, not the physics. Engineers got a tool that was fast exactly where they didn&#8217;t need help and unreliable everywhere they did.</span></p><p style="text-align: justify;"><span>The numerical solvers had the opposite profile: accurate and trustworthy across any geometry, but far too slow to run inside a design loop. So the trade-off stood. Fast or general: pick one.</span></p><p style="text-align: justify;"><span>What changed is the architecture. The transformer &#8212; the same design that made language models work &#8212; turns out to be good at consuming large, diverse collections of physical examples and learning a representation that holds up on inputs it was never trained on. The published method these systems draw on, Universal Physics Transformers, was demonstrated on automotive aerodynamics in a 2025 peer-reviewed paper. [2] The detail that matters for a non-specialist is simple: it was built to generalize across shapes, not memorize a few. That is the wall the old surrogates hit, and it is the wall the new models are designed to go through.</span></p><p style="text-align: justify;"><span>Fast </span><em><span>and</span></em><span> general, at the same time. That is the whole claim. Everything else is engineering.</span></p><h2 style="text-align: justify;"><span>A real-life LEM you can run in a browser</span></h2><p style="text-align: justify;"><span>Abstractions are easy to oversell, so here is a concrete one: plastic injection molding, in a corner of manufacturing that most people never think about. It is how a staggering share of the plastic object parts around you were made: caps, casings, connectors, dashboards. A mold costs six or seven figures and takes months to design. Get the design wrong, and the plastic will not fill the cavity properly. And you will only find out after the steel is cut.</span></p><p style="text-align: justify;"><span>So engineers simulate the fill first. Historically, that meant a numerical solver and a wait of minutes to hours per design, which in practice limits how many variations you can reasonably try.</span></p><p style="text-align: justify;"><span>This is where domain expertise and data decide everything, and it is </span><a href="https://www.simcon.ai/en/"><span>Simcon&#8217;s</span></a><span>. The German company has developed injection-molding simulation software for over 35 years, used by manufacturing world leaders such as Bosch, Continental, Roche, and Arburg. And now they&#8217;ve built, trained, and deployed a Transformer-based model for 3D physics.</span></p><p style="text-align: justify;"><span>Their </span><a href="https://www.simcon.ai/en/solutions/cadmould-ai-solver-injection-moulding-simulation"><span>Cadmould AI Solver</span></a><span> is trained on millions of  simulation runs generated by their own numerical solvers &#8212; the proprietary ground truth I described earlier, accumulated over decades and turned into a training corpus no one else has. The architecture came from a research collaboration; the physics, the data, and the validation are Simcon&#8217;s, and the company now owns the model outright, trains it in-house, and runs the cloud infrastructure that hosts it for customers. [3] Simcon bills it as the first Large Engineering Model for injection molding. Results in seconds instead of hours, a speedup the company puts in the range of 200 to 1,000 times, across part shapes the model was never trained on. [4]</span></p><p style="text-align: justify;"><span>You don&#8217;t have to take the number on faith. Simcon put a </span><a href="https://www.simcon.ai/en/solutions/cadmould-ai-solver-live-demo"><span>research preview</span></a><span> on the open web. It runs in a browser, on a mid-tier cloud GPU, and the geometries it ships with were explicitly not in the training data, to show it generalizes rather than parrots. [5] You change a parameter, you watch the fill pattern redraw, you change it again. The hours-long loop becomes a conversation. Anyone reading this can </span><a href="https://www.simcon.ai/en/solutions/cadmould-ai-solver-live-demo"><span>try it</span></a><span> online, and you can also </span><a href="https://www.simcon.ai/en/checkout/demo/start"><span>schedule a demo</span></a><span> with the Simcon team.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VFL7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VFL7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 424w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 848w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 1272w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VFL7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png" width="1456" height="771" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:771,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VFL7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 424w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 848w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 1272w, https://substackcdn.com/image/fetch/$s_!VFL7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3514b37-7a8b-4d73-a4f3-5aef022ecddf_2048x1084.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><span>The current model covers the filling stage of the molding process. The cooling, shrinkage, and warpage steps, which are decisive for many real-world outcomes, are on the roadmap. Accuracy is reported within a few percent of the numerical solver and improves as the training set grows. [6] The AI is a fast compass for exploration, and you can still validate the chosen design with the classical solver before cutting steel. That framing &#8212; AI to explore, trusted solver to confirm &#8212; is the sober version of the technology, and it is more convincing than a claim of replacement.</span></p><p style="text-align: justify;"><span>It is also more than a division of labor. The two engines feed each other. The model lets engineers explore thousands of designs in the time it would take the solver to check one; the solver then verifies the chosen design at full accuracy &#8212; and every such verification run is a fresh, high-fidelity training example for the next version of the model. Fast exploration surfaces the designs worth checking; precise validation turns the checks into new data; the new data makes the next model better at exploring. The loop closes in favor of whoever owns both engines. A company with only a fast model has a clever demo. A company with only a solver has what the industry already had. The advantage goes to the one running both, because each loop around widens the lead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IbyA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IbyA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 424w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 848w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IbyA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png" width="1456" height="864" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:864,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IbyA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 424w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 848w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!IbyA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f03d1eb-df35-492f-81a1-c43e5b2df7c2_2048x1216.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2 style="text-align: justify;"><span>Why Europe, for once, is well positioned</span></h2><p style="text-align: justify;"><span>The reflex in any AI story is that the US trains the biggest models and Europe writes the rules. In language, that is broadly true. Large Engineering Models invert one piece of it.</span></p><p style="text-align: justify;"><span>The scarce input here is not compute or web text. It is high-fidelity physical data from real industrial processes that lives disproportionately within European industry. Europe&#8217;s manufacturing sector holds potentially a century or more of accumulated knowledge and data: how materials behave, how processes fail, how a good part differs from a bad one, captured across generations of engineers and now sitting in solver archives, test logs, and process records.</span></p><p style="text-align: justify;"><span>A model is only as good as the data and the domain knowledge behind it, and those don&#8217;t transfer in a deal. They sit with the companies that have spent decades generating high-fidelity physical data &#8212; most of them industrial firms, many of them European, none of them frontier labs.</span></p><p style="text-align: justify;"><span>That is the moat. It is the one input a frontier lab cannot buy, scrape, or out-compute, and it is the thing that looks like a legacy liability in the software era right up until it becomes the training corpus for an entire category. Germany&#8217;s machine builders, the automotive supply chain, the molders and tool shops: each is a reservoir of exactly the data these models need, and the web does not contain. A simulation company with 35 years of its own solver output turning into a defensible AI asset is not a fluke. It is the shape of the whole opportunity.</span></p><p style="text-align: justify;"><span>This is also why the European Commission, in its Apply AI Strategy last October, named manufacturing a strategic sector and tied sectoral AI adoption to reducing Europe&#8217;s dependence on non-EU technology. [7] The advantage is not guaranteed &#8212; owning the data is not the same as building the models or the businesses on top of them, and that gap is where most of the value will be won or lost. But the raw material sits on the right side of the Atlantic, which is not something you can say about most of the AI race.</span></p><h2 style="text-align: justify;"><span>Why synthetic data isn&#8217;t enough</span></h2><p style="text-align: justify;"><span>A common objection is that synthetic data dissolves the moat: if you can generate training data on demand, the proprietary corpora stop being scarce, and the advantage migrates back to whoever has the most compute.</span></p><p style="text-align: justify;"><span>However, this objection is weaker than it looks. Valuable synthetic data is not random data. It is data that captures the rare failure, the edge case, the point where the physics turns nonlinear, and a part that looked fine starts to warp during cooling. Knowing which scenarios are worth generating and whether a generated sample is physically trustworthy or quietly wrong is itself domain expertise. You cannot synthesize your way past not knowing what matters. Synthetic generation doesn&#8217;t remove the need for decades of accumulated know-how; it raises the price of admission to a layer where that know-how is even scarcer.</span></p><p style="text-align: justify;"><span>A model you can access in a browser is predicting the 3D physics of parts it never saw, in seconds, and a company that knows the cost of getting it wrong is putting it in front of customers &#8212; alongside, not instead of, the solver they already trust. The first models to read and write the world got the headlines. The ones learning to predict it may turn out to matter more to the people who build things, and Europe is holding more of the raw material than it has in any other part of this race.</span></p><p style="text-align: justify;"><span>The machines are starting to learn physics. The question worth asking is, who can you trust to teach them, and on whose data?</span></p><div><hr></div><h3 style="text-align: justify;"><span>Notes</span></h3><p style="text-align: justify;"><span>[2] Benedikt Alkin et al., &#8220;AB-UPT: Scaling Neural CFD Surrogates for High-Fidelity Automotive Aerodynamics Simulations via Anchored-Branched Universal Physics Transformers,&#8221; Transactions on Machine Learning Research, accepted October 2025 (arXiv:2502.09692). The published architecture targets automotive aerodynamics computational fluid dynamics; its application to injection molding is a separate, domain-specific implementation. Code released by Emmi AI on </span><a href="https://github.com/Emmi-AI/anchored-branched-universal-physics-transformers"><span>GitHub</span></a><span>; paper on </span><a href="https://arxiv.org/abs/2502.09692"><span>arXiv</span></a><span>.</span></p><p style="text-align: justify;"><span>[3] Simcon GmbH, &#8220;SIMCON Unveils World&#8217;s First Large Engineering Model for Plastic Injection Moulding,&#8221; BusinessWire, March 18, 2026. The Cadmould AI Solver is described by Simcon as co-developed with Emmi AI on the model architecture; the training data, domain validation, and commercialization are Simcon&#8217;s per the company&#8217;s own product and scientific pages. CEO quote and product framing from the same release. </span><a href="https://www.businesswire.com/news/home/20260318680159/en/SIMCON-Unveils-Worlds-First-Large-Engineering-Model-for-Plastic-Injection-Moulding"><span>BusinessWire</span></a><span>.</span></p><p style="text-align: justify;"><span>[4] Speed range and &#8220;trained on over a million simulation trajectories&#8221; per Simcon&#8217;s product and technical pages; the 200&#8211;1,000&#215; and &#8220;up to 1000&#215;&#8221; figures are vendor-claimed and not independently reproduced. Trade-press coverage (Plastics Today, Plastics Technology, MoldMaking Technology, March 2026) repeats the &#8220;up to 1,000&#215;&#8221; figure sourced to Simcon. </span><a href="https://www.simcon.ai/en-us/solutions/cadmould-ai-solver-injection-molding-simulation"><span>Simcon</span></a><span>.</span></p><p style="text-align: justify;"><span>[5] Research preview runs in-browser on a cloud GPU; Simcon states the demo geometries are not part of the training data. Live at simcon.ai. </span><a href="https://www.simcon.ai/en-us/solutions/cadmould-ai-solver-injection-molding-simulation"><span>Simcon demo</span></a><span>.</span></p><p style="text-align: justify;"><span>[6] Filling-stage scope, roadmap to packing/cooling/shrinkage-and-warpage, accuracy reported &#8220;within 2&#8211;5% of numerical methods,&#8221; and the explicit &#8220;explore with AI, validate with classical solver&#8221; workflow are all per Simcon&#8217;s public materials and CEO statements. Accuracy figures are vendor-claimed. </span><a href="https://www.simcon.ai/en/solutions/cadmould-ai-solver-scientific-research"><span>Simcon scientific page</span></a><span>.</span></p><p style="text-align: justify;"><span>[7] European Commission, &#8220;Apply AI Strategy,&#8221; COM(2025) 723, published 8 October 2025. The strategy names manufacturing among its strategic sectoral flagships (deploying &#8220;agentic&#8221; AI to optimise production lines, targeted Q4 2026) and frames sectoral AI adoption as part of strengthening European digital sovereignty and reducing dependence on non-EU technology providers. </span><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52025DC0723"><span>EUR-Lex</span></a><span>.</span></p>]]></content:encoded></item><item><title><![CDATA[Too Dangerous for You, Free for Everyone]]></title><description><![CDATA[America locked up its best models. Europe regulates a frontier it can&#8217;t build. China gives its best to the world and is winning.]]></description><link>https://www.airealist.ai/p/too-dangerous-for-you-free-for-everyone</link><guid isPermaLink="false">https://www.airealist.ai/p/too-dangerous-for-you-free-for-everyone</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Sun, 28 Jun 2026 14:56:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1h58!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1h58!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1h58!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!1h58!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!1h58!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!1h58!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1h58!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png" width="1264" height="848" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:848,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2551345,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/203858774?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1h58!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!1h58!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!1h58!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!1h58!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2a42fe-017f-42c1-a430-09f7b3d9e8a9_1264x848.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><em><strong>Update, July 1, 2026:</strong> On June 30, Washington threw the switch again. Commerce withdrew its own June 12 export-control letter and cleared both Mythos 5 and Fable 5 for release. "Diversion risk," Secretary Lutnick's own term, decided the fate of both models in one sitting. Fable 5, Anthropic's flagship, is returning under the safeguards Washington requested. This is not a loose end. It is the American door doing what this piece describes: one government, on its own clock, deciding which model the world's leading AI lab is allowed to ship.</em></p><p style="text-align: justify;">On the morning of June 26, 2026, OpenAI released its most capable model and refused to let most people use it. GPT-5.6 Sol, the new flagship, went out as a limited preview to a short list of partners whose names OpenAI had shared with the US government, with general availability promised within weeks. In the same announcement, the company objected to the arrangement it was complying with, writing that it did not believe &#8220;this kind of government access process should become the long-term default.&#8221;[1]</p><p>That afternoon, the Commerce Department signed a letter restoring a competitor&#8217;s restricted model to the hands of more than 100 vetted American organizations: Anthropic&#8217;s Claude Mythos 5, which had been dark for two weeks after the same government forced it offline.[2]</p><p>Same day. Two labs. The frontier of artificial intelligence moved behind a government desk, and one of the firms that walked through the door used its launch to complain about the door.</p><p>None of this existed 80 days ago. It is now how the frontier ships.</p><h2>Three Doors, and None of Them Opens Outward</h2><p style="text-align: justify;">For two years, the question about frontier models was which one is best. That question is now close to useless, because the three blocs that produce and govern these models have each turned access to the best of them into a matter of state policy, in three opposite directions.</p><p style="text-align: justify;">The United States gates its most powerful models to government vetting. The European Union writes rules for a frontier it does not lead, aimed mostly at models built elsewhere. China does the opposite of both: it ships its best models as free downloads, and those models now account for the majority of the world&#8217;s open-model traffic.</p><div class="pullquote"><p style="text-align: justify;">The question is no longer which model is best. It is which government&#8217;s hand you can tolerate on the switch, and whether any of these doors is open in the way it appears to be.</p></div><p style="text-align: justify;">The American case is the loudest. Anthropic spent the spring restricting Claude Mythos, an unreleased model it said could find decades-old security flaws on its own, to a short list of trusted partners.[3] On June 2, the White House signed an order asking developers to grant the government up to 30 days of access to &#8220;covered frontier models&#8221; before release.[4] Ten days later, a Commerce directive pulled two Anthropic models offline worldwide in roughly 90 minutes, including one commercial product serving hundreds of millions of users.[5] Two weeks after that, the same agency let the more dangerous of the two back in, for the vetted few. OpenAI&#8217;s GPT-5.6 followed the identical pattern on the identical day.</p><p style="text-align: justify;">The European case is the quietest and, on paper, the most powerful. On August 2, 2026, five weeks from now, the EU&#8217;s AI Office gains the power to demand information from frontier developers, order changes, levy fines, and recall models from the market.[6] The largest models in scope are American.[7] Europe&#8217;s own frontier model, a publicly funded open-source effort, won the right to be built six days before this writing.[8] It does not exist yet.</p><p style="text-align: justify;">The Chinese case is the one nobody is regulating, and everybody is using. At the end of 2024, Chinese open-weight models accounted for about 2 percent of the tokens flowing through the largest neutral model router. By the middle of 2026, they carried roughly 60 percent of them while that router quadrupled in size.[9]</p><p style="text-align: justify;">The three doors look like a menu of safety, regulation, and freedom. They are nothing of the kind, and the door that looks free is the one quietly moving the switch.</p><h2>The American Door: From Secure-and-Release to Ask-Permission</h2><p>To see how far the United States has moved, start with the moment it set the opposite precedent.</p><p style="text-align: justify;">In February 2019, OpenAI announced a language model called GPT-2 and declined to release it, citing the risk of fake news and impersonation. The decision split the field: some read it as responsible caution, others as a marketing performance that withheld a research artifact while implying it was a weapon. Nine months later, OpenAI released the full model and reported it had seen no strong evidence of misuse.[10] The harms had not arrived.</p><p style="text-align: justify;">The industry took a lesson from the episode, and it was not &#8220;withhold.&#8221; It was the opposite: secure, then ship. Red-team the model, write a system card, publish a responsible-scaling policy, and release through an interface you control. For seven years, that habit held on a single assumption: that the lab decides when a model goes out.[11]</p><p>2026 broke the assumption, and not because the labs changed their minds. The state intervened in the decision.</p><p style="text-align: justify;">The opening move was Anthropic&#8217;s. In April, it launched Project Glasswing around Claude Mythos, a model it kept out of public release and handed to roughly a dozen launch partners and a few dozen more organizations under usage credits. Anthropic backed the restriction with findings, not just adjectives: it said Mythos had autonomously surfaced vulnerabilities that had survived decades of human review, including a 27-year-old flaw in OpenBSD&#8217;s networking code and a 16-year-old one in one of the most widely used media libraries in the world.[12]</p><p style="text-align: justify;">Those specific findings hold up. The patches exist. The advisories are public. But the framing around them deserves the scrutiny that the access restriction prevents. When independent researchers got hold of cheaper, openly available models, several of the showcase bugs fell to them too, one to a model costing a fraction of a cent per query.[13] A widely respected security commentator who is hard on AI hype judged the danger credible, and noted in the same breath that calling your model too dangerous to release is an excellent way to build buzz around it.[14] Both things are true at once. A safety claim and a capability advertisement are not mutually exclusive, and when the model is locked away, the advertisement cannot be checked. </p><div class="pullquote"><p style="text-align: center;">You cannot benchmark what you cannot run.</p></div><p style="text-align: justify;">The second move was the government&#8217;s. On June 2, the White House issued an order creating a voluntary path for developers to give the government up to 30 days of pre-release access to the most capable models, paired with a classified, NSA-led process to define which models qualify based on their cyber capabilities. The order is careful to bar any mandatory licensing scheme.[15] It is an invitation, not a law.</p><p style="text-align: justify;">The third move showed what the invitation is worth when the government decides not to wait for it. On June 9, Anthropic launched Claude Fable 5, a commercial model it described as a Mythos-class system made safe for general use, with sensitive requests routed to a tamer model.[16] Three days later, at 5:21 p.m. Eastern, a Commerce export-control letter required a validated license before either model could reach any foreign national, including Anthropic&#8217;s own foreign-national staff. Unable to filter users by citizenship in real time, the company took Fable 5 and Mythos 5 down everywhere. A model serving hundreds of millions of people went dark in about 90 minutes, over a jailbreak Anthropic said was narrow and reproducible on other public models.[17]</p><p style="text-align: justify;">Read those three moves in sequence. The decision about whether the public can use the best American model has migrated from the lab to Washington. OpenAI says the broad release of GPT-5.6 is only weeks away, and it may be; staging is not the same as exclusion. But the most capable tier, in the window that decides who gets the edge first, is gated by government vetting, and &#8220;weeks away&#8221; is a promise, not a shipped product. The public gets the safe-for-general-use version, or it waits. GPT-5.6 on June 26 was not a new direction. It was the second lab arriving at the same door.</p><p style="text-align: justify;">OpenAI was candid that Sol had not crossed its own threshold for critical cyber risk. The model was gated not because the lab judged it too dangerous to ship, but because the government asked and the lab agreed, while the two worked out the access framework that the June 2 order set in motion. What governs release now is not the model&#8217;s capability. It is who gets to say yes.</p><p style="text-align: justify;">This is not a tidy story of state capture. The June 2 order is voluntary and forbids licensing. OpenAI publicly protested the very vetting it submitted to. And Anthropic is suing the administration that gates its models, after the Defense Department tried to brand it a supply-chain risk for refusing to drop two narrow limits on its product: no mass domestic surveillance, no fully autonomous weapons.[18] The contradiction runs deep enough to be comic: the United States government simultaneously treats Anthropic as a national-security risk and as the only frontier model it has cleared for use up to the Secret level.[19] Read charitably, that is two arms of government disagreeing in good faith about a real tradeoff. Read at the level of what happened on the ground, with a model pulled, a company branded, and a competitor handed the contract, it looks less like a safety policy than a fight over who holds the switch.</p><p style="text-align: justify;">There is one more piece, and it belongs to the man who built the model that got pulled. Two days before Commerce pulled it, Anthropic&#8217;s chief executive published an essay calling for binding rules on frontier AI modeled on the FAA and aircraft: testing, auditing, and a government power to block a release it judges unsafe.[20] The authority that hit him two days later was not that one. A pre-release safety review is not an export-control recall, but the through-line is the same, and it is the uncomfortable part. </p><div class="pullquote"><p style="text-align: center;">The labs that built the frontier are now, in their different ways, asking the state to hold the switch they once held themselves. They may not like the hand that takes it.</p></div><p style="text-align: justify;">And here is the loop that makes the American door self-defeating. Each turn of the gate raises the cost and the political risk of depending on a controlled American model. Every enterprise that feels that cost starts looking for an alternative, the United States cannot reach. There is one. It is open, cheap, and Chinese. And the action that pulled Mythos was, by the government&#8217;s own reported concern, about keeping that very model away from China, which means Washington&#8217;s defense against Chinese AI is quietly herding the market into China&#8217;s arms. The tighter Washington shuts its door, the more of the world&#8217;s usage walks out the back.</p><h2>The European Door: A Customs House on a Road It Doesn&#8217;t Own</h2><p>Europe&#8217;s posture is the strangest of the three, because it is built around a gap.</p><p style="text-align: justify;">The EU AI Act sorts general-purpose models by the compute used to train them. Cross a threshold of ten-to-the-25th operations and a model is presumed to carry &#8220;systemic risk,&#8221; which brings obligations to test it adversarially, assess and reduce its dangers, report serious incidents, and secure it.[21] These rules have been on the books since August 2025. What arrives on August 2, 2026, is the enforcement: from that date, the AI Office can compel information, mandate changes, fine a provider up to 3 percent of global revenue, and order a model pulled from the European market.[22]</p><p style="text-align: justify;">The trouble is what that threshold now catches. 10^25 operations was the size of GPT-4 in 2023; the frontier has since run more than an order of magnitude past it, and the largest training run on record sits some fifty times above the line.[23] Dozens of models from a dozen labs now clear it. So the tier that the EU polices is not just the frontier. It is a rung below the leaders, who are American. Europe does have a lab on the other side: Mistral signed the same code. But it trails the models the danger conversation is about, and the continent has no model at the frontier that the rules were written to govern. Its answer to that gap is a consortium, selected on June 19, that won the right to build an open-source frontier model in all 24 official languages on European supercomputers, running on Nvidia silicon.[24] The model is a plan. The regulator is operational.</p><p style="text-align: justify;">The European door mostly governs models built in America, which run on infrastructure largely owned by Americans. It is a customs house on a road it does not own. Yet, the rules have teeth, the fines are large, and governing the compliant is not nothing. Europe&#8217;s deeper power is the market itself: the threat of exclusion from 450 million consumers has bent more than one American product to Brussels rules before. But a recall and a market ban are both switches on someone else&#8217;s model. </p><div class="pullquote"><p style="text-align: center;">When the EU pulls a frontier model, it removes a product from its market that isn't made by a European company, and that will keep selling it everywhere else. </p></div><p style="text-align: justify;">The bloc that talks most about digital sovereignty has arranged to hold the off-switch for everything except a model it controls.</p><h2>The Chinese Door: Why &#8220;Open&#8221; Doesn&#8217;t Mean Unlocked</h2><p>China runs the opposite play, and on the numbers, it is winning.</p><p style="text-align: justify;">While the United States restricts and Europe regulates, Chinese labs ship. DeepSeek, Alibaba&#8217;s Qwen, Zhipu&#8217;s GLM, Moonshot&#8217;s Kimi: a steady cadence of frontier-adjacent models released as free downloads under permissive licenses. The usage curve is the whole argument. </p><div class="pullquote"><p style="text-align: center;">Chinese open-weight models went from about 2 percent of the tokens on the largest neutral model router at the end of 2024 to roughly 60 percent by the middle of 2026. </p></div><p style="text-align: justify;">That router measures where developers send cost-sensitive work, not a census of all AI use, and over the same stretch, it grew fourfold, with coding rising to more than half of all traffic.[25] A separate count agrees from a different angle: on the world&#8217;s main model hub, Chinese developers accounted for roughly 41 percent of downloads over the trailing year, overtaking the United States.[26] The silicon underneath is increasingly China&#8217;s own, too; the leading open labs now train and serve on Huawei&#8217;s Ascend chips rather than Nvidia&#8217;s, so the diffusion no longer runs on hardware Washington controls. China did not just take a share. It took the majority of a market that quadrupled.</p><p style="text-align: justify;">This is where the obvious objection arises. An open-weight model on your own machines has no off-switch. Nobody can revoke a file you have already downloaded. If that is true, then China&#8217;s door is not a door at all. It is an open field, and the symmetry of this whole piece collapses.</p><p>It does not collapse, because open weights are not open access.</p><p style="text-align: justify;">Consider the model at the top of the open leaderboard. Zhipu&#8217;s GLM-5.2 has 744 billion parameters: about 1.5 terabytes of weights at full precision, roughly half that at the compressed precision most deployments use, every byte of which must sit in graphics memory at once. The reassuring figure you will hear, that only 40 billion parameters are active at a time, is a statement about speed, not memory: the whole model still has to be resident to run. In practice, that means a multi-node cluster of high-end accelerators, not a workstation or a laptop.[27] That is why the usage the router measures is hosted usage: these models are reached through an endpoint, DeepSeek&#8217;s own or a Western reseller&#8217;s, not run on the premises of the firms using them.</p><p style="text-align: justify;">The switch, then, does not disappear. It relocates. It moves to the hosted endpoint, which can be suspended, rate-limited, geo-blocked, or repriced. And it moves to the data, because every prompt and every output now travels to whoever runs the endpoint: a provider under Chinese law if you call DeepSeek directly, or a Western intermediary with its own logs if you route through one. Calling a Chinese model through Azure removes the question of Chinese jurisdiction over your data while preserving the cost advantage; calling it directly does not.[28] The only path that escapes the endpoint entirely is self-hosting, and self-hosting the frontier is gated by capital, which puts it within reach of roughly the same set of organizations that could afford to buy into an American-vetted tier. </p><div class="pullquote"><p style="text-align: center;">The freedom is real at the license and illusory at the rack.</p></div><p style="text-align: justify;">None of this shows up in the price comparison that pulls enterprises toward the Chinese door in the first place. The headline is real: the leading open models run at roughly a sixth of the per-token cost of the American frontier. But the rate card flatters the invoice. These models reason at length before they answer, spending tens of thousands of tokens on a single task, so the gap on the bill comes out narrower than the gap on the price list.[27] And the firm that tries to escape the endpoint by self-hosting trades the API bill for a six- to seven-figure cluster and a team to operate it. Most do the rational thing and stay on the hosted endpoint, which means staying on the switch. The cost advantage that makes the door attractive is the same force that keeps the buyer renting access instead of owning it. Cheap is the lure. The endpoint is the hook.</p><p style="text-align: justify;">There is a second lock most analyses miss, and ordinary use does not pick it. The content controls are baked into the weights. Independent testing finds that Chinese open models, including DeepSeek and Qwen, refuse or steer away from Taiwan, Tiananmen, and Xinjiang, and that this steering persists in the weights even in locally run copies. Standard fine-tuning does not remove it. It can be stripped: the abliteration methods that tear the safety scaffolding out of open models also work here. But doing so takes deliberate effort, costs capability, and never fully succeeds, and the fact that you must operate on the weights at all to get a neutral answer is itself the tell. An open-weight model is not neutral. It ships with a foreign government&#8217;s preferences embedded in its parameters, and the zero price that makes it spread carries those preferences along.[29] That split is the whole posture. At home, China runs one of the tightest content systems in the world, every public-facing model registered and assessed by the state; abroad, it gives the models away. </p><div class="pullquote"><p style="text-align: center;">Control where it governs, diffusion where it competes.</p></div><p style="text-align: justify;">One last item belongs here, and it weighs against the American gate, not the Chinese door. On June 10, Anthropic told the Senate Banking Committee that operators tied to Alibaba and its Qwen lab had run roughly 25,000 fraudulent accounts and 28.8 million exchanges against Claude to copy its abilities by extraction rather than training.[30] Treat it as an interested party&#8217;s allegation, because it is one: it comes from the company with the most to gain from the gating system, filed the same week its chief executive called for government power to block model releases. But if it is true, it lands on the gate, not the open door. You cannot lock up a capability that walks out through your own interface, 28.8 million exchanges at a time.</p><h2>The Same Switch, Installed Three Ways</h2><p style="text-align: justify;">Readers of this publication have seen this shape before. An earlier piece mapped a three-layer off-switch over any AI dependency (the chips, the cloud, and the model) and asked what happens when someone throws it on purpose rather than by accident.[31] What 2026 added was the installation of that switch at the national policy level across three countries at once, by three governments that agree on almost nothing.</p><p style="text-align: justify;">The seven-year settlement that followed GPT-2 rested on one quiet premise: the lab decides when a model ships. All three blocs have now broken that premise from different directions. The United States moved the decision to Washington and made the best models a government-vetted tier. Europe claimed a veto, the recall, over models it did not build. China dissolved the decision at the license layer and reinstalled it twice, at the endpoint and inside the weights.</p><p style="text-align: justify;">What the three share is not motive. The United States is keeping its frontier from China and fighting itself over who holds the gate, Europe is compensating for an industry it lacks, and China is doing what a challenger does when it cannot win the top tier outright: giving away the layer below it, whether by design or by the plain logic of competition, until the incumbent&#8217;s moat is a commodity. What they share is the result, and the result lands on the same person every time: the enterprise downstream of all three now depends on a switch it does not hold, and on a body of law it did not write.</p><h2>What Would Have to Break</h2><p style="text-align: justify;">On the only number that compounds, usage, the open door is winning. &#8220;Too dangerous for you&#8221; is losing to &#8220;free for everyone&#8221; in the market by a wide and widening margin.</p><p style="text-align: justify;">But winning hides the trap. The enterprise that routes to the Chinese stack to get out from under the American switch lands on the Chinese endpoint&#8217;s switch and under Chinese data law, carrying a model with Beijing&#8217;s editorial line inside it. It did not escape control. It swapped Washington&#8217;s switch for Beijing&#8217;s, and took on Chinese data law in the bargain. Most of the firms making the move have not priced that.</p><p style="text-align: justify;">Three developments would break this read, and each is worth watching. </p><ol><li><p style="text-align: justify;">A frontier-parity model small enough to self-host cheaply (a step change in compression, or a model under 100 billion parameters that matches the leaders) would open a switch-free door for real, and the argument that there is no such door would fail. </p></li><li><p style="text-align: justify;">A US public tier that ships at full capability, with no detuned version held back, would end the two-class frontier and turn the vetting into a formality.</p></li><li><p style="text-align: justify;">A government-vetted model that visibly stops harm and openly available models that would go on to cause harm would be the first evidence that the gate does safety work rather than turf-holding. </p></li></ol><p style="text-align: justify;">None of the three has happened yet. Until one does, the pattern holds.</p><p style="text-align: justify;">The lesson for anyone allocating capital or choosing a stack is not a recommendation for one door over another. It is that the doors were never the choice they appeared to be. </p><div class="pullquote"><p style="text-align: center;">You are not picking the best model. You are picking which government&#8217;s hand rests on the switch, and whose law your prompts live under. </p></div><p style="text-align: justify;">So price the switch as what it is: not an outage risk to be solved with a second region, but a control risk that earns its own line in the vendor register, with a tested path to a second model and the standing assumption that the vetted tier and the open tier each carry a different hand, not no hand. </p><p style="text-align: justify;">The one door that looks like freedom only moved the switch to a place you were not watching, and the bill for not watching comes due the first time someone decides to throw it.</p><div><hr></div><h3>Notes</h3><p>[1] OpenAI, <a href="https://openai.com/index/previewing-gpt-5-6-sol/">&#8220;Previewing GPT-5.6 Sol: a next-generation model&#8221;</a>, June 26, 2026. The GPT-5.6 series (Sol, the flagship, plus Terra and Luna) launched as a limited preview to a small group of partners whose participation OpenAI said it had shared with the US government, with general availability planned within weeks. OpenAI objected to government-gated access as a long-term default and tied the step to its work with the Administration on the cyber Executive Order framework. System card: <a href="http://deploymentsafety.openai.com/gpt-5-6-preview">GPT-5.6 Preview</a>. OpenAI states the model does not cross its critical cyber-risk threshold under its Preparedness Framework; the gating reflects caution and government request rather than a declared red line.</p><p>[2] US Department of Commerce letter from Secretary Howard Lutnick to Anthropic chief compute officer Tom Brown, Friday June 26, 2026, lifting the export-control license requirement for Claude Mythos 5 for entities named in the letter&#8217;s Annex A and their foreign-national employees. Mythos 5 only; the letter is silent on Fable 5, which remained restricted, with talks reportedly moving toward its release on an unclear timeline. Lutnick wrote that &#8220;appropriate safeguards are in place to permit certain trusted partners&#8221; to access the model. Reported by Semafor (Reed Albergotti and Ben Smith), <a href="https://www.semafor.com/article/06/27/2026/us-releases-powerful-anthropic-model-mythos-to-some-us-companies">&#8220;US releases powerful Anthropic model Mythos to some US companies&#8221;</a>, June 26, 2026. The move came the same day as OpenAI&#8217;s GPT-5.6 limited release.</p><p>[3] Anthropic, <a href="https://www.anthropic.com/glasswing">&#8220;Project Glasswing: Securing critical software for the AI era&#8221;</a>, April 7, 2026 &#8212; Claude Mythos Preview restricted to 12 launch partners (AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, with Anthropic) plus roughly 40 additional critical-infrastructure organizations under $100M in usage credits; later expanded to about 150 more.</p><p>[4] The White House, <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">Executive Order 14409, &#8220;Promoting Advanced Artificial Intelligence Innovation and Security&#8221;</a>, June 2, 2026 &#8212; Section 3 creates a voluntary framework for up to 30 days of pre-release government access to &#8220;covered frontier models,&#8221; designated through a classified, NSA-led benchmarking process; the order expressly bars any mandatory licensing, preclearance, or permitting requirement.</p><p>[5] See [17].</p><p>[6] European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">&#8220;Regulatory framework on AI&#8221;</a>; AI Office enforcement powers (information requests, mandated mitigations, fines, model recalls) apply from 2 August 2026.</p><p>[7] The largest in-scope models by training compute are American (OpenAI, Google, Anthropic, xAI); see [23].</p><p>[8] European Commission, <a href="https://digital-strategy.ec.europa.eu/en/news/commission-selects-europa-consortium-winner-frontier-ai-grand-challenge-project-build-european-open">&#8220;Commission selects EUROPA consortium as the winner of the Frontier AI Grand Challenge&#8221;</a>, 19 June 2026. The Domyn-led EUROPA consortium will build an open-source frontier model (400+ billion parameters, Mixture-of-Experts) in all 24 official EU languages, on EuroHPC supercomputers (up to 2.5% of capacity for one year) plus a reported 6,000-chip NVIDIA Blackwell cluster. The model does not yet exist.</p><p>[9] OpenRouter token-share data, corroborated by an OpenRouter&#8211;Andreessen Horowitz study of ~100 trillion tokens (relayed by South China Morning Post, December 8, 2025 &#8212; note SCMP is owned by Alibaba; cite the underlying study) and by Data Gravity, <a href="https://www.datagravity.dev/p/chinas-open-weight-takeover">&#8220;China&#8217;s Open-Weight Takeover&#8221;</a>, May&#8211;June 2026. Figures are hosted-API traffic on a developer-skewed router, not enterprise deployment.</p><p>[10] OpenAI, <a href="https://openai.com/index/gpt-2-1-5b-release/">&#8220;GPT-2: 1.5B Release&#8221;</a>, November 5, 2019 &#8212; full model released after a staged rollout, with no strong evidence of misuse reported.</p><p>[11] the-decoder, <a href="https://the-decoder.com/from-gpt-2-to-claude-mythos-the-return-of-ai-models-deemed-too-dangerous-to-release/">&#8220;From GPT-2 to Claude Mythos: the return of AI models deemed &#8216;too dangerous to release&#8217;&#8221;</a> &#8212; on the industry&#8217;s shift to &#8220;secure-then-release.&#8221;</p><p>[12] Anthropic Frontier Red Team, <a href="https://red.anthropic.com/2026/mythos-preview/">&#8220;Assessing Claude Mythos Preview&#8217;s cybersecurity capabilities&#8221;</a>, April 7, 2026 &#8212; autonomous discovery of zero-day vulnerabilities including a 27-year-old OpenBSD TCP SACK remote-code-execution flaw and a 16-year-old flaw in a widely used media library (FFmpeg, H.264), among thousands across major operating systems and browsers; a related 17-year-old FreeBSD NFS RCE was assigned CVE-2026-4747.</p><p>[13] AISLE (Stanislav Fort, founder), <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">&#8220;AI Cybersecurity After Mythos: The Jagged Frontier&#8221;</a>, April 7, 2026, with the full prompts and model responses published on <a href="https://github.com/stanislavfort/mythos-jagged-frontier">GitHub</a>. AISLE isolated the code behind Anthropic&#8217;s showcase vulnerabilities and ran it through small, cheap, open-weight models: eight of eight tested models detected the flagship FreeBSD bug, including a 3.6-billion-active-parameter model at $0.11 per million tokens, and a 5.1-billion-active open model recovered the core chain of the 27-year-old OpenBSD flaw. Corroborated by VentureBeat and CNBC, which note other firms (watchTowr, Vidoc) likewise reproduced Mythos results with public models. AISLE&#8217;s thesis: the moat is the system, not the model.</p><p>[14] Simon Willison, <a href="https://simonwillison.net/">commentary on the Mythos restriction and on &#8220;too dangerous to release&#8221; as a buzz-building move</a>, April 2026.</p><p>[15] See [4].</p><p>[16] Anthropic, <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">&#8220;Claude Fable 5 and Claude Mythos 5&#8221;</a>, June 9, 2026 &#8212; Fable 5 is the generally available Mythos-class model (a tier above the Opus class), carrying cybersecurity, biology, chemistry, and distillation safeguards that defer flagged queries to Claude Opus 4.8 (triggering in under 5% of sessions); Mythos 5 is the same model with those safeguards lifted, restricted to Project Glasswing partners. Both priced at $10/$50 per million tokens.</p><p>[17] On June 12, 2026 (5:21 p.m. ET), Commerce&#8217;s Bureau of Industry and Security issued an &#8220;Is Informed&#8221; letter to Anthropic under the Export Control Reform Act of 2018 (50 U.S.C. &#167; 4817(b)(1)) and EAR &#167; 744.22(b), requiring an individually validated export license before either model could reach any foreign national worldwide, including Anthropic&#8217;s own foreign-national staff (a &#8220;deemed export&#8221;). This is a license requirement under existing export-control authority, distinct from the June 2 executive order and not a finalized EAR rule. Unable to filter users by nationality in real time, Anthropic disabled Fable 5 and Mythos 5 globally and characterized the cited jailbreak as narrow and reproducible on other public models. Per Semafor&#8217;s reporting, the underlying US concern was that Mythos had reached partners seen as too closely linked to China (reportedly a South Korean telecom). As of publication, Fable 5 remained restricted. Reporting: Semafor (June 13 and June 26, 2026); The Conversation, <a href="https://theconversation.com/why-the-us-government-shut-down-anthropics-latest-claude-ai-model-285223">&#8220;Why the US government shut down Anthropic&#8217;s latest Claude AI model&#8221;</a>; Greenberg Traurig client alert, June 2026.</p><p>[18] Congressional Research Service, <a href="https://www.congress.gov/crs-product/IF13217">&#8220;Federal Government and Anthropic: Considerations for AI Innovation and Competition&#8221;</a>; NPR, <a href="https://www.npr.org/2026/02/27/nx-s1-5729118/">&#8220;OpenAI announces Pentagon deal after Trump bans Anthropic&#8221;</a>, February 27, 2026. Dispute centered on Anthropic&#8217;s refusal to permit mass domestic surveillance and fully autonomous weapons use; DoD moved to designate Anthropic a supply-chain risk; a federal court blocked most of the designation as punitive.</p><p>[19] Center for American Progress, <a href="https://www.americanprogress.org/article/the-trump-administration-is-trying-to-make-an-example-of-the-ai-giant-anthropic/">&#8220;The Trump Administration Is Trying To Make an Example of the AI Giant Anthropic&#8221;</a>, March 4, 2026 &#8212; Claude described as the only frontier model cleared for US government use up to the Secret level.</p><p>[20] Dario Amodei, <a href="https://darioamodei.com/post/policy-on-the-ai-exponential">&#8220;Policy on the AI Exponential&#8221;</a>, June 10, 2026 &#8212; proposing FAA-style mandatory third-party testing and auditing of frontier models, with government authority to block or reverse a release that fails safety standards. A pre-release certification proposal, distinct in kind from the June 12 export-control action.</p><p>[21] <a href="https://artificialintelligenceact.eu/high-level-summary/">EU AI Act, Articles 51 and 55</a>; presumption of systemic risk above 10^25 training FLOP; obligations include model evaluation, adversarial testing, systemic-risk mitigation, serious-incident reporting, and cybersecurity.</p><p>[22] European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">AI Act enforcement timeline</a>; from 2 August 2026 the AI Office may issue information requests, require corrective measures, levy fines up to 3% of global turnover or &#8364;15M (whichever is higher), and ultimately restrict or withdraw a model from the EU market. &#8220;Recall&#8221; is used in the body as a plain-language gloss for that withdrawal/restriction power.</p><p>[23] The EU AI Act presumes systemic risk above ten-to-the-25th training FLOP, a level calibrated to GPT-4-class compute in 2023. By mid-2025, <a href="https://epoch.ai/data-insights/models-over-1e25-flop">Epoch AI&#8217;s database identified 30+ models from roughly a dozen developers</a> over that threshold &#8212; OpenAI, Google, Anthropic, Meta, xAI, and Mistral among them, alongside Chinese labs &#8212; with the count rising through 2026. The largest known training run, xAI&#8217;s Grok 4, is estimated at ~5&#215;10^26 FLOP, roughly fifty times the line, and <a href="https://epoch.ai/trends">Epoch notes monitoring thresholds &#8220;may need to rise correspondingly over time&#8221; to stay focused on frontier capability</a>. The systemic-risk tier is therefore a wide field below the capability frontier, not a roster of the most advanced models.</p><p>[24] See [8].</p><p>[25] See [9]. Router growth from roughly 5 trillion tokens per week (April 2025) to over 20 trillion (April 2026); coding rose from about 11% of usage to more than 50% over the period.</p><p>[26] Hugging Face, <a href="https://huggingface.co/spaces/cfahlgren1/hub-stats">&#8220;State of Open Source on Hugging Face: Spring 2026&#8221;</a>, March 17, 2026, reporting Chinese developers at roughly 41% of Hub downloads over the trailing year, overtaking US developers; grounded in the study &#8220;Economies of Open Intelligence&#8221; (851,000 models; 2.2 billion downloads). <em>Disclosure: the author served as Chief Evangelist at Hugging Face through 2023; the Hub download figures are cited from Hugging Face&#8217;s own published report and corroborate, rather than originate, the OpenRouter traffic trend.</em></p><p>[27] GLM-5.2 specifications and self-hosting requirements: Z.ai model card; Simon Willison, <a href="https://simonwillison.net/2026/Jun/17/glm-52/">&#8220;GLM-5.2&#8221;</a>, June 17, 2026; <a href="https://artificialanalysis.ai/">Artificial Analysis</a>. 744B total parameters (40B active, Mixture-of-Experts), ~1.5 TB of weights at BF16, all of which must reside in GPU memory; serving guides converge on multi-node accelerator clusters. Pricing runs roughly one-sixth of US frontier per token, but heavy reasoning-token usage (tens of thousands of tokens per task) narrows the real cost gap (Artificial Analysis). The capital constraint applies to frontier-parity open models; smaller self-hostable models (e.g., Qwen 3.5&#8217;s 0.8B&#8211;9B line) are not at the frontier.</p><p>[28] Data-jurisdiction handling for hosted Chinese models: calls to Chinese-operated endpoints route through Chinese-jurisdiction servers; Western intermediaries (e.g., Azure) eliminate that exposure while preserving cost. Independent provider documentation and analysis, 2026.</p><p>[29] Content controls in Chinese open models. Independent studies document that Chinese open-weight models (Qwen, DeepSeek, and MiniMax among them) are trained to refuse, deflect, or assert falsehoods on PRC-sensitive topics: Taiwan, Tibet, Xinjiang, the 1989 Tiananmen Square protests, and Falun Gong. Researchers describe this as &#8220;embedded local censorship&#8221; that sits in the base weights and persists even when the model is run locally. See, e.g., <a href="https://arxiv.org/abs/2603.05494">&#8220;Censored LLMs as a Natural Testbed for Secret Knowledge Elicitation&#8221;</a> (March 2026), and <a href="https://arxiv.org/abs/2505.12625">&#8220;R1dacted: Investigating Local Censorship in DeepSeek&#8217;s R1&#8221;</a>. Standard fine-tuning raises truthful-response rates only partially; weight-level intervention (abliteration / logit suppression, cf. <a href="https://arxiv.org/abs/2505.23848">arXiv:2505.23848</a>) can reduce the bias at a cost in capability and never fully succeeds. The behavior tracks China&#8217;s requirement that public-facing generative-AI services be registered and security-assessed by the state (Interim Measures for the Management of Generative AI Services, effective August 2023, governing services with &#8220;public opinion attributes&#8221;). See also my earlier piece, <a href="https://www.airealist.ai/">&#8220;Open From Both Sides&#8221;</a>, The AI Realist.</p><p>[30] Anthropic letter to US Senate Banking Committee Chairman Tim Scott and Ranking Member Elizabeth Warren, dated June 10, 2026, alleging the largest known distillation campaign on Claude &#8212; roughly 25,000 fraudulent accounts and 28.8 million exchanges between April 22 and June 5, attributed to operators affiliated with Alibaba and its Qwen AI lab, targeting agentic reasoning, software engineering, and long-horizon planning. First reported by Bloomberg (June 24); confirmed by <a href="https://www.cnbc.com/2026/06/24/anthropic-alibaba-distillation-campaign.html">CNBC</a> and Reuters. Interested-party allegation; treat accordingly.</p><p>[31] <a href="https://www.airealist.ai/">&#8220;Access, Disable, Destroy&#8221;</a>, The AI Realist &#8212; the three-layer coercion model over chips, cloud, and models.</p>]]></content:encoded></item><item><title><![CDATA[Two Laws, One Dependence ]]></title><description><![CDATA[Europe moved twice on cloud sovereignty this month. One proposal makes the American duopoly easier to move within. The other grades everything about a cloud except the chip it runs on.]]></description><link>https://www.airealist.ai/p/two-laws-one-dependence</link><guid isPermaLink="false">https://www.airealist.ai/p/two-laws-one-dependence</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Mon, 22 Jun 2026 07:23:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TiF2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TiF2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TiF2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 424w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 848w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 1272w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TiF2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png" width="1424" height="752" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:752,&quot;width&quot;:1424,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1817854,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/202998705?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TiF2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 424w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 848w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 1272w, https://substackcdn.com/image/fetch/$s_!TiF2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f994a0-82a2-4241-97b7-f12b477781ef_1424x752.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">In October 2025, a single fault in one Amazon data center in northern Virginia took down Signal, Snapchat, Epic Games, and much of the internet for most of a day.[1] There was a second hyperscale outage that week: an Azure Front Door failure that hit Heathrow and the Scottish Parliament. Seven months later, these outages have produced a piece of European law. </p><p style="text-align: justify;">In the week of 22 June 2026, the European Commission is expected to find, provisionally, that Amazon Web Services and Microsoft Azure are &#8220;gatekeepers&#8221; under the Digital Markets Act, a designation no cloud provider has carried before.[2] A gatekeeper is a platform so entrenched that its customers cannot practically avoid it, and the designation imposes on it obligations the rest of the market does not bear. The remedies here aim to improve interoperability, ensure cleaner data portability, and reduce exit fees.[3]</p><div class="pullquote"><p style="text-align: justify;">Europe&#8217;s newest answer to its dependence on American cloud is a rule that makes it easier to switch between two American clouds. </p></div><p style="text-align: justify;">Read the room before you read the regulation. The outage was an accident, and the cure is written for accidents. The thing that makes the cloud a question of sovereignty rather than reliability is not the accident. It is the day someone reaches for the off switch on purpose, and that switch is not on the menu.</p><h2>Two laws, one month</h2><p style="text-align: justify;">The designation does not arrive alone. On 3 June, the Commission published the Cloud and AI Development Act, the centerpiece of its Tech Sovereignty Package and the most serious attempt yet to legislate European independence in cloud and AI.[4] Two instruments, weeks apart, aimed at the same dependence. One is a competition tool. The other calls itself sovereignty. Neither touches the two things that decide whether a cloud is sovereign: who operates the service, and who controls the chips it runs on.</p><p style="text-align: justify;">The competition tool runs into a wall of arithmetic. Three American firms, Amazon, Microsoft, and Google, hold 70 percent of the European cloud market; the largest single European provider, whether SAP or Deutsche Telekom, holds 2 percent.[5] Against that backdrop, &#8220;easier to switch providers&#8221; means something specific and unhelpful: easier to switch from Amazon to Microsoft, and vice versa.</p><div class="pullquote"><p style="text-align: justify;">Portability between two firms under the same foreign jurisdiction is not an exit. It is a more comfortable form of dependence.</p></div><p style="text-align: justify;">None of this makes the remedy worthless. The Digital Markets Act will lower egress bills and make multi-cloud architectures less painful, and contestability is a real good, whether or not it touches sovereignty. The point is narrower: a competition instrument is being read, in the political register, as a sovereignty win. It is not built to be one, and it cannot accidentally become one. Where the designation cannot reach, and where the sovereignty law chooses not to look, is the rest of this piece.</p><h2>The off switch reaches the mundane</h2><p style="text-align: justify;">Where the off switch sits is settled, and I will not re-litigate it here. The law follows the company, not the server: a provider under United States jurisdiction can be ordered to produce data in its possession, custody, or control wherever that data physically sits. I traced that statutory chain in full in <a href="https://www.airealist.ai/p/two-sovereign-clouds-one-legal-wall">Two Sovereign Clouds, One Legal Wall</a>.</p><p style="text-align: justify;">What is new is the evidence that the switch reaches past the obvious targets. On 22 May 2026, the Dutch outlet Vrij Nederland reported that Microsoft had handed the US House Judiciary Committee the internal emails, meeting notes, and calendar entries of named officials at two Dutch regulators, the competition authority and the data protection authority, without redacting their names.[6] </p><div class="pullquote"><p style="text-align: justify;">No sanctions, no court order against the individuals, no Russia nexus. </p></div><p style="text-align: justify;">Ordinary European civil servants, doing ordinary European regulatory work, have their correspondence produced to a foreign legislature because the company holding it answers to that legislature&#8217;s law. called it "extremely worrying" and raised it with the US ambassador.[7]</p><p style="text-align: justify;">That matters because, until now, the switch had mostly been thrown against the conspicuous: an <a href="https://www.airealist.ai/p/access-disable-destroy">ICC prosecutor under US sanctions and a Rosneft-linked refiner under EU sanctions</a>, once under American law, once under European, the customer&#8217;s own location irrelevant in both. The objection writes itself: those were sanctioned parties. But the Dutch case is different. The exposure is not a property of being sanctioned. It is a property of whose jurisdiction your operator holds, and the Digital Markets Act&#8217;s portability remedy does nothing to change that, because it moves you between two operators who answer to the same one.</p><h2>The sovereignty law that de-chipped itself</h2><p style="text-align: justify;">Set the competition remedy aside and read the Commission's proposed Cloud and AI Development Act on its own terms. It is the most serious sovereignty framework Europe has produced, and its seriousness is the problem. The Act defines four assurance levels, weakest to strongest.[8] Level 1 is data residency. Level 2 adds independence from third-country interference and transparency in the software supply chain. Level 3 requires the provider to be owned and controlled from within the EU, with criteria that extend to personnel's nationality. Level 4 demands full command of the software supply chain.</p><div class="pullquote"><p style="text-align: justify;">Read as a ladder, it climbs towards independence. Read against the market, each rung lands on a segment that already exists. </p></div><p style="text-align: justify;">The Commission&#8217;s own impact assessment aligns the levels with current supply and is candid that most public-sector workloads will sit at Levels 1 and 2, which the American hyperscalers reach through their &#8220;sovereign&#8221; offerings.[9] Only a narrow band will require Levels 3 and 4. There is a sharper irony one rung up: Level 2 asks a provider to demonstrate independence from third-country interference. A US hyperscaler &#8220;sovereign&#8221; tier claiming Level 2 is certifying, on paper, an independence its own counsel told a parliament it does not have.[10] And Level 3, the rung that is supposed to signify European ownership, contains a clause that allows the Commission to recognize third-country providers.[11] The most European tier has a door in its back wall.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H_cA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H_cA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 424w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 848w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 1272w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H_cA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png" width="1456" height="619" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:619,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:213452,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/202998705?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H_cA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 424w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 848w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 1272w, https://substackcdn.com/image/fetch/$s_!H_cA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdab05ac6-faf0-4271-8c73-b71ef3abdf2f_2280x969.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Then there is the part the proposal leaves out. The Commission already had a sovereignty yardstick that required a full EU supply chain, including chips.[12] When it put &#8364;180 million of its own sensitive workloads out to <a href="https://www.airealist.ai/p/ten-percent-sovereign">tender in April</a>, no bidder reached that tier; the cleanest qualifiers cleared the rung below it, on a commodity stack.[13] Yet when the legislative text arrived in June, CADA did not carry the chip across. Its assurance levels grade the software supply chain and stop there; Annex II places hardware "outside of the scope" of the sovereignty assessment.[14] </p><div class="pullquote"><p style="text-align: justify;">Call it what it is: de-chipping. </p></div><p style="text-align: justify;">The yardstick that scored the chip was one that the Commission could publish alone; the proposed law dropped the one rung nobody could meet. A sovereignty framework that cannot describe a sovereign chip has decided not to try. The money agrees with the edit. The Act&#8217;s financial statement carries roughly &#8364;25 million across 2028 to 2034, against a build-out it says needs three to four billion euros per gigawatt and tens of gigawatts of new capacity.[15] That is not a budget. It is a signature.</p><h2>The switch nobody scores</h2><p style="text-align: justify;">The de-chipping matters because the hardware is where the off switch is most absolute, and it is the layer that assurance levels now refuse to look at. Not one of the four scores the silicon. A workload can sit at Level 4 and run end to end on Intel processors and Nvidia accelerators; the software supply chain can be wholly European while the chips answer to Washington. I have written separately about how far that dependence runs <a href="https://www.airealist.ai/p/below-the-silicon">below the silicon</a>; the point here is only that CADA&#8217;s own top tier now stops precisely where that dependence begins.</p><p style="text-align: justify;">It is not hypothetical. In January 2025, the outgoing US administration&#8217;s AI Diffusion Rule sorted the world into tiers for access to advanced AI chips and placed much of the EU, including Poland, Portugal, and most of the bloc&#8217;s east, in the second tier with capped access; the rule was rescinded that May, two days before it took effect, in a decision as unilateral as its drafting.[16] Congress, meanwhile, is advancing the Chip Security Act, which would require location verification for exported AI chips. It cleared the House Foreign Affairs Committee unanimously in March 2026, and while it is not law, the fact that chip-tracking is on the table in Washington tells you where hardware sovereignty is decided.[17] </p><div class="pullquote"><p style="text-align: justify;">A &#8220;sovereign&#8221; European cloud whose chips can be tiered, traced, or capped by a foreign legislature is sovereign in the way a house with someone else&#8217;s lock on the door is private.</p></div><h2>What honesty would look like</h2><p style="text-align: justify;">None of this means the pragmatism is wrong. Given the state of European supply, no law could wall the public sector off from American providers without being unenforceable on contact, and removing a sovereign-chip tier that nobody can meet is more honest than pretending otherwise. A version of the Act that said plainly, strict sovereignty over a critical core and pragmatism on the rest, would be defensible. The Commission&#8217;s own Cloud III procurement showed in April that a real requirement pulls a real response, when two clean European providers, Scaleway and STACKIT, qualified for sensitive workloads on a commodity stack.[18]</p><p style="text-align: justify;">The problem is not the pragmatism. It is the packaging. A competition remedy that makes the American duopoly easier to move within is being sold as a step towards sovereignty. A sovereignty law whose own grades never reach the chip is being sold as the thing that will end the dependence. Present either as what it is, and both are defensible; present them together as a sovereignty agenda, and you install the ambiguity in which sovereignty-washing lives, a term the European Parliament&#8217;s own research service now uses in print.[19] Call the hyperscalers&#8217; improved offerings what they are: trusted cloud, resilient cloud, real operational progress. Sovereign, no.[20]</p><p style="text-align: justify;">Presenting the package on 3 June, the Commissioner responsible, Henna Virkkunen, said the aim was to ensure no provider of critical services holds a "kill switch" over Europe.[21] </p><div class="pullquote"><p style="text-align: justify;">She named the risk precisely, then presented a law that reaches neither the operator nor the chip, the two places the switch sits. </p></div><p style="text-align: justify;">The EU's record on targets like this is not encouraging: the 2023 Chips Act aimed to double Europe's share of global semiconductor production to 20 percent by 2030, attracted more than &#8364;52 billion, and left the bloc below 10 percent.[22] The number of cloud laws built to move is the same kind; the share of the European cloud market held by European providers is stuck near 15 percent, while three American firms hold 70 percent. </p><p style="text-align: justify;">If it has not turned by 2030, Europe will have regulated its dependence twice, relabelled it once, and changed it not at all, and the off switch will sit where it sits today, in the one place no assurance level dares to score.</p><div><hr></div><h2 style="text-align: justify;">Notes</h2><p>[1] On 20 October 2025, a DNS race condition in Amazon Web Services&#8217; US-EAST-1 region (northern Virginia) cascaded across dependent services for roughly fifteen hours, affecting Signal, Snapchat, Epic Games and more than a thousand others; AWS published its post-mortem three days later. The outage was the proximate trigger for the EU&#8217;s cloud market investigation. <a href="https://www.thousandeyes.com/blog/aws-outage-analysis-october-20-2025">ThousandEyes outage analysis, 20 October 2025</a>.</p><p>[2] The Commission is reported to be preparing preliminary findings, expected the week of 22 June 2026, that AWS and Microsoft Azure meet the requirements for gatekeeper designation under the Digital Markets Act, with a final decision expected by end-2026. <a href="https://thenextweb.com/news/eu-dma-aws-azure-cloud-gatekeeper-probe">The Next Web, citing Bloomberg</a>.</p><p>[3] Reported obligations under discussion include interoperability, data portability and curbs on customer lock-in such as egress fees. <a href="https://thenextweb.com/news/eu-dma-aws-azure-cloud-gatekeeper-probe">The Next Web</a>. </p><p>[4] Cloud and AI Development Act, European Commission, published 3 June 2026 as the centrepiece of the European Technological Sovereignty Package. <a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act">European Commission</a>; <a href="https://www.insideglobaltech.com/2026/06/11/the-eu-cloud-and-ai-development-act-in-depth/">Covington, Inside Global Tech, 11 June 2026</a>.</p><p>[5] Synergy Research Group: Amazon, Microsoft and Google together hold about 70 per cent of the European cloud infrastructure services market (IaaS, PaaS, hosted private cloud); among European providers, SAP and Deutsche Telekom lead with roughly 2 per cent each (2024 data). <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">Synergy Research Group</a>.</p><p>[6] Vrij Nederland, 22 May 2026, reporting that Microsoft transmitted unredacted internal emails, meeting minutes and calendar entries of named civil servants at the Authority for Consumers and Markets (ACM) and the Data Protection Authority (AP) to the US House Judiciary Committee. <a href="https://nltimes.nl/2026/05/22/microsoft-accused-leaking-dutch-civil-servants-names-us-government">NL Times</a>.</p><p>[7] The named officials include staff at both regulators and a University of Amsterdam researcher; the Dutch cabinet called the episode &#8220;extremely worrying,&#8221; noting the named individuals could face travel bans or sanctions, and State Secretary for Digital Economy and Sovereignty Willemijn Aerdts raised the matter with US Ambassador Joe Popolo during her introductory meeting with him. <a href="https://builtineu.eu/news/microsoft-shared-dutch-regulator-names-us-house-committee">Built In EU</a>; <a href="https://www.dutchnews.nl/2026/05/us-tech-firms-share-dutch-regulator-officials-names-with-senate/">DutchNews.nl</a>.</p><p>[8] CADA defines four &#8220;Union assurance levels&#8221; for public-sector cloud and AI procurement. Level 1 (data residency) is the floor for all providers serving the public sector; Levels 2&#8211;4 add an independent third-party audit examining EU-located staff, whether provider data is used to train AI models, software supply-chain security, and a European cybersecurity certificate rated at least &#8220;substantial.&#8221; &#8220;Control&#8221; is defined by reference to the European Defence Fund &#8220;decisive influence&#8221; test (Art. 2(21)). <a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act">European Commission</a>; <a href="https://www.wsgr.com/en/insights/european-commission-publishes-proposal-for-act-to-reduce-reliance-on-foreign-cloud-and-ai.html">Wilson Sonsini, June 2026</a>.</p><p>[9] CADA impact assessment, Part 1, p. 41, maps each level onto an existing market segment in near-verbatim terms (Level 1: &#8220;US hyperscalers generally all have offerings that would allow them to qualify&#8221;; Level 4: &#8220;some emerging EU offerings&#8221;). The assessment twice instructs that risk assessments &#8220;consider the reality of the supply market to avoid&#8230; mandating the use of services that don&#8217;t exist (yet)&#8221; (pp. 40, 49). Its demand model splits public-sector use cases 70/20/9/1 across Levels 1&#8211;4 and sizes the exclusively EU-addressable market at roughly &#8364;4.48 billion by 2030 (pp. 47, 72&#8211;73).</p><p>[10] CADA, Level 2 criterion requiring providers to demonstrate independence from third-country interference (Art. 2(g)(ii)). The Commission&#8217;s own impact assessment (Part 1, pp. 14&#8211;15) recounts the Microsoft France testimony before the French Senate procurement inquiry, June 2025: &#8220;Non, je ne peux pas le garantir, mais, encore une fois, cela ne s&#8217;est encore jamais produit.&#8221; <a href="https://www.senat.fr/compte-rendu-commissions/20250609/ce_commande_publique.html">S&#233;nat, compte rendu</a>.</p><p>[11] CADA, Level 3 requires the provider to be owned and controlled from within the EU, with criteria such as personnel citizenship; the Commission&#8217;s own summary states it &#8220;can recognise third-country providers&#8221; under the framework. <a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act">European Commission</a>; see also <a href="https://www.techuk.org/resource/europe-s-technology-sovereignty-package-what-do-the-cloud-ai-development-act-and-chips-act-ii-mean-for-uk-tech.html">techUK, June 2026</a>, which calls the third-country recognition mechanism &#8220;one of the most important aspects&#8221; of the legislation.</p><p>[12] The Commission&#8217;s Cloud Sovereignty Framework (Version 1.2.1, published 20 October 2025) defines a five-rung scale of Sovereignty Effectiveness Assurance Levels (SEAL), from SEAL-0 (no sovereignty) to SEAL-4 (Full Digital Sovereignty: complete EU control across the supply chain, hardware included). CADA codifies a four-level version of this framework as binding &#8220;assurance levels,&#8221; and, as Annex II makes explicit, drops hardware from scope in the process. <a href="https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en">European Commission, Cloud Sovereignty Framework v1.2.1</a>; analysis in <a href="https://www.airealist.ai/p/more-sovereign-different-stack-the">More Sovereign, Different Stack: The Builder Tax</a>.</p><p>[13] European Commission, Cloud III procurement, awarded 17 April 2026: a Dynamic Purchasing System worth up to &#8364;180 million over six years for sensitive EU institutional workloads. SEAL-2 was the minimum threshold; the cleanest prequalified consortia, Scaleway and STACKIT, cleared SEAL-3 on commodity-stack architectures, and none reached SEAL-4. <a href="https://commission.europa.eu/news-and-media/news/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en">European Commission</a>; see <a href="https://www.airealist.ai/p/ten-percent-sovereign">Ten Percent Sovereign</a> and <a href="https://www.airealist.ai/p/more-sovereign-different-stack-the">The Builder Tax</a>.</p><p>[14] CADA, Annex II, scope paragraph, excludes hardware verbatim: &#8220;&#8217;Hardware&#8217; within the meaning of Regulation (EU) 2024/2847, Article 3, point (5) is outside of the scope.&#8221; Hardware survives only as a contract-award criterion that is &#8220;ancillary and not decisive&#8221; (Art. 32(2)(d)), feasibility-qualified, and capped by Recital 67 at a suggested maximum of 15 of 120 points. <a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act">European Commission</a>; <a href="https://www.insideglobaltech.com/2026/06/11/the-eu-cloud-and-ai-development-act-in-depth/">Covington, Inside Global Tech, 11 June 2026</a> (confirming the 15-of-120 weighting).</p><p>[15] CADA legislative financial statement: total appropriations of &#8364;25.228 million across 2028&#8211;2034, fee-financed, supporting roughly 25 full-time staff. The impact assessment&#8217;s central scenario calls for a tripling of EU data-centre capacity against an estimated 19 GW gap, at a build-out cost of roughly &#8364;3&#8211;4 billion per gigawatt. <a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act">European Commission</a>.</p><p>[16] The AI Diffusion Rule (interim final rule, 15 January 2025) established a tiered framework for access to advanced AI chips, placing NATO members including Poland and Portugal in the second tier with capped access; BIS rescinded it on 13 May 2025, two days before its scheduled 15 May effective date. <a href="https://www.ussc.edu.au/the-us-ai-diffusion-rule">United States Studies Centre</a>; <a href="https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens">U.S. Department of Commerce, BIS</a>.</p><p>[17] The Chip Security Act (H.R. 3447) passed the House Foreign Affairs Committee 42&#8211;0 on 26 March 2026 and proceeds to the full House; it has not been enacted. Nvidia opposes a tracking mandate, stating its products contain &#8220;no backdoors&#8221; and &#8220;no kill switches,&#8221; while since December 2025 offering optional software to trace its GPUs&#8217; location. <a href="https://foreignaffairs.house.gov/news/press-releases/chairman-mast-hfac-advances-chip-security-act">House Foreign Affairs Committee</a>; <a href="https://www.geo.tv/latest/638937-new-nvidia-software-to-help-trace-ai-chips-location-as-us-enforces-chip-security-act">Geo News, citing Reuters</a>.</p><p>[18] Commission Cloud III procurement, awarded 17 April 2026: under a genuine sovereignty requirement, the cleanest prequalified consortia, Scaleway and STACKIT, cleared SEAL-3 (one tier below the unmet SEAL-4). <a href="https://commission.europa.eu/news-and-media/news/commission-advances-cloud-sovereignty-through-strategic-procurement-2026-04-17_en">European Commission</a>; see <a href="https://www.airealist.ai/p/more-sovereign-different-stack-the">The Builder Tax</a>.</p><p>[19] The term &#8220;sovereignty-washing&#8221; appears in the European Parliament&#8217;s research output describing hyperscaler &#8220;sovereign cloud&#8221; offerings. <a href="https://www.europarl.europa.eu/RegData/etudes/STUD/2025/778576/ECTI_STU(2025)778576_EN.pdf">European Parliament, &#8220;European Software and Cyber Dependencies,&#8221; PE 780.413/778576, December 2025</a>.</p><p>[20] Disclosure: the author is an AI Operating Partner at Fortino Capital, a European private equity firm whose portfolio includes companies whose cloud architecture decisions fall within the scope of this analysis; he previously spent six years at AWS and was Chief Evangelist at Hugging Face. The disclosure names the interest; it is not an endorsement of any provider or procurement choice.</p><p>[21] Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, at the press conference presenting the European Technological Sovereignty Package, Brussels, 3 June 2026: the Commission wants to ensure no cloud provider of critical workloads holds a &#8220;kill switch&#8221; over essential European services, and observed that the US CLOUD Act makes it &#8220;difficult&#8221; for US companies to reach the highest sovereignty levels. <a href="https://www.cnbc.com/2026/06/03/europe-tech-sovereignty-us-tech-reliance.html">CNBC, 3 June 2026</a>.</p><p>[22] The 2023 EU Chips Act mobilised more than &#8364;52 billion toward a target of doubling the EU&#8217;s share of global semiconductor production to 20 per cent by 2030; the EU&#8217;s share remains below 10 per cent, prompting the demand-focused Chips Act 2.0 in the June 2026 package. <a href="https://www.techpolicy.press/eu-unveils-sweeping-tech-sovereignty-push-balancing-autonomy-with-openness/">TechPolicy.Press, June 2026</a>.</p>]]></content:encoded></item><item><title><![CDATA[Independent or Current]]></title><description><![CDATA[Europe built the most ambitious AI enforcer in the world. It still has to ask the labs how to grade them.]]></description><link>https://www.airealist.ai/p/independent-or-current</link><guid isPermaLink="false">https://www.airealist.ai/p/independent-or-current</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Thu, 18 Jun 2026 11:01:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QwM3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QwM3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QwM3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QwM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1939671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/202491797?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QwM3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!QwM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6052cebf-c98c-4ca4-b05b-475ad88f7d43_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">In 2024,, the European Commission went looking for someone to evaluate the world&#8217;s most powerful AI models. The post was the lead scientific adviser to the AI Office, the person who would sit across from OpenAI, Anthropic, and Google and judge whether their frontier systems were fit for placement on the European market. The application window opened, then closed in December. Months later, the chair was still empty.[1]</p><p style="text-align: justify;">The pay explains some of it. The Office&#8217;s technical roles top out near $120,000, and even its senior posts sit on fixed civil-service scales the labs beat several times over for the same skills, sometimes with seven-figure packages. The European pool for this work is thin enough that the strongest candidates already sit in San Francisco or London. The Office has since hired a small, capable safety team, with people from Oxford, Google, and the UK&#8217;s AI Security Institute.[2] But the seat reserved for the scientist who would lead the judging of a frontier model stayed empty as the start date approached. The authority is real. The question is the capacity to use it.</p><p style="text-align: justify;">Step back from the hiring, though, and the opposite is just as true. On paper, the European Union has just built the most serious AI enforcer anywhere. The Digital Omnibus, voted through Parliament on 16 June, consolidated oversight of the largest models and AI across the largest platforms into a single office and gave that office the power to vet the highest-risk products before they ship.[3] A Scientific Panel of 60 independent experts was sworn in on 1 June to give it technical muscle.[4] A 174-member Advisory Forum sits alongside.[5] The obligations for general-purpose models have been in effect since August 2025.[6] By any measure of ambition, Brussels has done what Washington spent years declining to do: it built a standing regulator with the authority to test the frontier.</p><p style="text-align: justify;">That empty chair is a small sign of a large problem. <strong>Europe&#8217;s frontier-AI evaluator can be independent or current, but not both</strong>, and the same shortage of methods, access, and people produces both limits. To judge the largest models as they exist, the Office has to borrow the labs&#8217; tools, access, and talent, at which point it is grading the labs&#8217; own homework. To build its own capacity instead and stop borrowing, it has to move at the speed of public hiring and public standard-setting, at which point whatever it certifies is a snapshot of a live model it has already outrun. The competence to evaluate a frontier model in real time exists almost entirely inside, or priced by, the companies being evaluated.</p><h2>The homework problem</h2><p style="text-align: justify;">Start with what the law asks of a frontier developer, because it is less than most readers assume. A provider of a general-purpose model with systemic risk must run its own state-of-the-art evaluations, assess and reduce the risks it identifies, document all of this in a Safety and Security Model Report, and submit that report to the AI Office before the model reaches the market.[7] </p><div class="pullquote"><p style="text-align: justify;">The lab runs the assessment, writes it up, and sends the file; the Office reads it.</p></div><p style="text-align: justify;">External evaluation exists, but its shape tells you who is in charge. The Code of Practice that fills in the details requires a model developer to give independent, external evaluators access to its most advanced versions and to publish the standards by which it selects them. The provider grants the access, and the provider sets the bar for who qualifies. The requirement was nearly cut from the Code during drafting and survived only as mandatory &#8220;in most circumstances,&#8221; with an exemption allowing a model developer to claim it is as safe as one already cleared.[8] The outside check runs through a door the developer holds open. And as of mid-2026, the Office had not settled what qualifies someone to serve as an outside evaluator: it called a workshop for 15 July, weeks before its enforcement powers switched on, to take expert input on the question.[9]</p><p style="text-align: justify;">This is not a flaw the Office can out-hire, because the people who would do the hiring face the wall the empty adviser&#8217;s chair revealed. And it is not solved by leaning on the independent evaluators who have made their names doing this work, because they hit the same door. The respected outside shops &#8212; METR, Britain&#8217;s AI Security Institute, Apollo, FAR.AI &#8212; operate under voluntary access agreements granted by the labs, and the labs can withdraw those agreements. When a lab has shared a model before release, the sharing has been thin: in the clearest recent case, a model developer handed an evaluator a safety-tuned version with no ability to fine-tune it, and one of the best-known evaluators appears to have had no special pre-release access since its early work in 2023.[10] Their independence is real on the org chart and thin where it counts: in what the lab lets them see.</p><div class="pullquote"><p style="text-align: justify;">What the outside world mostly gets to see is behavior: the model&#8217;s outputs, not its internals. </p></div><p style="text-align: justify;">So, where is Europe&#8217;s own capacity? It is real, and it sits one level up from the test. Between late 2024 and mid-2025, the Commission&#8217;s Joint Research Center ran a global expert pool to develop methods for sorting models into risk categories, and co-authored a paper with the AI Office, published in Science, on how to keep evaluation proportionate to risk. This is serious work. But it is rubric-writing: how to classify a model, where to set the compute thresholds, how to think about reach. The JRC&#8217;s own review of AI benchmarks catalogs how immature the field is, and its categorization work measures capability using the benchmarks that already exist, the ones the research community and the labs have built.[11] Europe can decide which models deserve scrutiny and to what extent. It cannot, on its own, put a frontier model through its paces.</p><p style="text-align: justify;">Put the pieces together, and the first half of the trap closes on itself. To bind the frontier, the Office needs to evaluate the largest models close to real time. Real-time evaluation needs methods and access that live within the labs and the lab-adjacent shops at the labs&#8217; gate. The Office cannot build that capacity fast enough, because it cannot pay for the people who have it. So the binding step falls back on the provider&#8217;s own evaluations, the provider&#8217;s chosen outside reviewers, and the provider&#8217;s report. No independent capacity accumulates, so next year the Office is no closer to building its own, and it borrows again. The Panel can raise a formal alert when it suspects a model carries serious risk, and that lever is real.[12] But an alert is a flag raised over a document that the model developer wrote.</p><h2>The yardstick that never arrives</h2><p style="text-align: justify;">In principle, there is a way out of the borrowing: building an independent measure of its own. Europe tried. The result is the second half of the trap.</p><p style="text-align: justify;">The AI Act&#8217;s binding requirements for high-risk systems were meant to rest on harmonized technical standards, the detailed yardsticks against which a system is judged. The Commission asked the European standards bodies to write them in 2023. They missed the 2025 deadline, the work continues, and the Commission has said the delay puts the timetable at risk. The first relevant standard reached public consultation in late 2025, months behind schedule, and standards of this kind typically take 2 to 4 years to complete. The Omnibus that Parliament just passed pushed the high-risk obligations out to the end of 2027 and tied their start to the readiness of those standards, conceding that it cannot set its own clock.[13]</p><p style="text-align: justify;">The model layer repeats the problem in another form. The general-purpose rules are written to apply across a model&#8217;s life, including after updates, and a model developer is told to set their own trigger points for when fresh evaluation is due. But the binding re-assessment only fires when a change is large enough to count as a new model, and the indicative bar for that is a modification using more than a third of the original training compute, a threshold the Commission expects few to cross.[14] </p><div class="pullquote"><p style="text-align: justify;">A model can drift a long way through a stream of smaller updates without ever tripping a formal review, and the triggers that might catch it are the model developer&#8217;s to set and judge.</p></div><p style="text-align: justify;">Now both halves are visible at once, and they lock together. Every move the Office makes toward being current &#8212; lifecycle monitoring, live evaluation, judging the model as it is &#8212; runs through the developer, because only the developer has the access and the tools to do it at speed. And the one move toward an independent measure of its own &#8212; the standards &#8212; keeps slipping past its deadline. Currency by borrowing, independence by waiting: the Office cannot have both, because the thing that would let it be current without borrowing, a deep bench of frontier evaluators paid at market rates working from methods it owns, is the thing the empty adviser&#8217;s chair says it cannot afford to build.</p><h2>What the Office can do</h2><p style="text-align: justify;">The safety unit is staffed with credible people, drawn from places that do this work.[2] The Scientific Panel is no roster of industry placemen: most of its 60 members are academics, a sixth come from the European machine-learning research network, and they sit in their personal capacity under conflict-of-interest rules.[4] These are serious researchers, several of whom would be at home in any frontier lab. The JRC&#8217;s methodological work is real and is being read.[11] The alert the Panel can raise is a true lever, and the Office now has the formal authority over the largest models and the platform-integrated systems that, until this year, were scattered across national capitals.[3] The enforcement numbers are not trivial: breaches of the general-purpose obligations carry fines up to the greater of &#8364;15 million or 3% of worldwide turnover.[15]</p><p style="text-align: justify;">The law does not limit the Office to reading what it is sent. It can demand access to a model, through an interface or the source code itself, and run its own evaluation, with fines for a model developer who refuses.[16] But look at when it applies: to check compliance only once the developer&#8217;s own documentation is found wanting, or to investigate a serious risk after the panel raises a flag. It is the escalation, not the routine, and the default stays the model developer&#8217;s report. The rules for how such an evaluation would run have not yet been written. And a right to demand access is worth only as much as the capacity to use it: the methods, the compute, and the people it has already shown it lacks. A right of entry that the regulator cannot staff is a right on paper.</p><p style="text-align: justify;">So the Office can decide which models matter. It can demand documentation. It can read a model developer&#8217;s report with expert eyes, push back, and escalate. It can fine a model developer who lies or hides. What it cannot do is the thing the public imagines a safety regulator does: take the live model, probe it deeply and repeatedly on its own terms, and certify the result against a yardstick it built and controls. Everything it does sits on top of artifacts that the model developer generated and access that the developer granted.</p><h2>The fork the labs just got</h2><p>There is one more actor, and it changed the board three weeks ago.</p><p style="text-align: justify;">On 2 June, President Trump signed an order on advanced AI that does almost the opposite of what Brussels did. It establishes a framework for model developers to grant the federal government up to 30 days of access to their most powerful models before release, on a voluntary basis, with qualifying models selected by a classified benchmark, and with no mandatory licensing, no pre-clearance, and no right for anyone to sue to enforce.[19] Collaboration, the order says, not command. The administration had pulled an earlier draft in May for fear it would slow American competitiveness, and signed this softer version instead.[20] The same administration has stood up a task force to challenge state AI laws it considers too heavy.[21] The contrast with Europe could not be sharper: a voluntary American framework on one side, and on the other, binding European obligations carrying statutory fines that take effect this August.[22]</p><p style="text-align: justify;">This matters to Europe&#8217;s evaluator because it hands the labs something they did not have before: a venue they prefer. A developer cannot lawfully step outside the AI Act for a model it places on the European market; the obligations attach on sale, wherever the model was built.[23] But &#8220;comply&#8221; and &#8220;comply fully, first, and openly&#8221; are different things. </p><div class="pullquote"><p style="text-align: justify;">A lab can ship its strongest model in the United States first under the friendly arrangement, stage or delay the European release, send a capped or filtered version into the European market, and meet the Office&#8217;s deeper requests for access with the least it can defend, while pointing to the American process as its real oversight. </p></div><p style="text-align: justify;">This is not hypothetical: in 2024, one large model developer withheld its multimodal models from the European Union over what it called regulatory unpredictability, and a major device maker delayed its flagship AI features in the bloc on similar grounds.[24] The incentive to route cooperation toward the venue that creates no liability only sharpened the week of the order: the day before it, Anthropic filed a confidential draft registration with the SEC at a valuation near $965 billion, the kind of public-market stake that turns a European enforcement action into a disclosed risk on the prospectus.[25]</p><p style="text-align: justify;">None of this loosens the bind; it pulls it tighter. The evaluator was already leaning on the access the labs chose to grant, and now the labs have a venue they prefer and a reason to give Brussels less of it. The access that was thin becomes contested ground, and the jurisdiction that wins it is the one the developers like better. Europe gets the companies willing to be examined, on their own terms; Washington offers those same companies an examiner who asks nothing it can enforce.</p><h2>Europe has run this play before</h2><p style="text-align: justify;">If this reads like a forecast, it is not. Europe ran the experiment one regulatory generation back, on the platforms, using the same institutions it is now reaching out to. The AI Office and its Panel are built on the template of the European Center for Algorithmic Transparency: set up in 2023, housed in the same Joint Research Center that now serves the Office, and tasked with giving the Commission the in-house expertise to police the largest online platforms under the Digital Services Act.[26] Swap &#8220;platforms&#8221; for &#8220;models,&#8221; and the shape repeats: exclusive Commission supervision of the biggest players, backed by a technical body meant to do the evaluating. Its record is the closest thing we have to a forward look, and it is thin.</p><p style="text-align: justify;">Two and a half years in, the platform rules have produced a single fine: &#8364;120 million against X in December 2025, in part for barring researchers from its data, with 60 days to fix rather than pay.[27] The open cases against Meta and TikTok turn on the same failure: researchers shut out of platform data.[28] The rules grant researchers a right to that data, and the platforms have spent years making it slow, conditional, or barred outright. </p><div class="pullquote"><p style="text-align: justify;">Slow enforcement and a permanent fight to see inside the thing it polices: that is the template now aimed at frontier models.</p></div><p>The pattern predates the platforms, and the AI lineage is direct. Europe&#8217;s chemicals agency checks only a fraction of the dossiers industry files on its own substances; the legal minimum rose from 5% to 20% in 2019, and when it does check, most fail: 61% of one early cohort fell short of what the law required.[29] Even a mature agency with real capacity can only spot-check a self-reported base, finding much of it wanting. The body that wrote Europe&#8217;s first AI principles fits the same shape: the 2018 High-Level Expert Group, heavy with industry seats and with only four ethicists among more than 50 members, produced ethics guidelines and a self-assessment checklist that one of its own called ethics-washing.[30] The Scientific Panel is its more independent, more technical heir, and still a body reading what developers choose to show it.</p><h2>What would have to break</h2><p style="text-align: justify;">Europe escapes the trap if the Office can retain frontier evaluators at something near market pay, build a battery of tests it designs rather than borrows, win a right of deep access to live models instead of the access a developer grants, and track models as they change instead of certifying a version and moving on. Each of those is conceivable. None is close on the current path: the pay bands are public-sector, the standards keep slipping, the access is voluntary, and the talent the Office needs is being bid away by the firms it would evaluate and is now being courted by a friendlier government across the Atlantic. The honest probability, on today&#8217;s trajectory, is low. </p><div class="pullquote"><p style="text-align: justify;">None of this argues for no regulator; a borrowed evaluation still beats none. The point is narrower: borrowing carries a cost the borrower keeps paying.</p></div><p style="text-align: justify;">Which leaves a verdict sharper than &#8220;the regulator is underpowered.&#8221; For anyone running diligence on an AI vendor, the practical reading is blunt: <strong>treat &#8220;AI Office-supervised&#8221; or &#8220;evaluated under the AI Act&#8221; as a provider-generated artifact, not an independent clearance</strong>, and price the difference. Europe has built a real enforcer that can read the labs&#8217; homework, raise a flag over it, and fine a lab that hides the truth. What it cannot do is grade the frontier itself. And whichever way it leans, the only models it truly examines are the ones whose makers agree to sit the exam. </p><p style="text-align: justify;">The systems that should worry you most are built to skip it: a model fine-tuned to strip its safety training and re-released by someone who never files with Brussels, a capable model served from a jurisdiction that ignores the Act (I&#8217;m looking at you, China), a model trained on smuggled compute by an actor with no European address to fine. </p><p style="text-align: justify;">Once again, the cop that Europe built is aimed at the population that was already willing to be policed.</p><div><hr></div><h3>Notes</h3><p>[1] The AI Office&#8217;s lead scientific adviser post &#8212; application deadline December 2024 &#8212; remained unfilled in mid-2026; the head-of-safety-unit role, vacant since the Office was set up, was filled in December 2025 (Matthieu Delescluse). <a href="https://www.transformernews.ai/p/eu-is-struggling-to-hire-ai--act-office-safety-unit">Transformer News</a>; <a href="https://www.mlex.com/mlex/articles/2424075/matthieu-delescluse-appointed-ai-safety-head-in-eu-commission-s-ai-office">MLex</a>.</p><p>[2] Reported AI Office salaries: technical and contract-agent roles roughly $55,000&#8211;$120,000, the lead scientific-adviser post at grade AD13 (about &#8364;13,500&#8211;15,000 per month); EU staff also receive allowances and favourable tax. The figures still fall well below frontier-lab compensation, which can run to seven figures. <a href="https://www.transformernews.ai/p/eu-is-struggling-to-hire-ai--act-office-safety-unit">Transformer News</a>.</p><p>[3] Digital Omnibus on AI, consolidated text (Council doc ST 9247/2026 INIT); European Parliament plenary vote 16 June 2026. The AI Office gains centralized supervision over systems built on a same-provider general-purpose model and over AI integrated into very large online platforms, with Commission pre-market assessment for such high-risk systems; carve-outs leave certain products and uses to national authorities. European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">Regulatory framework on AI</a>.</p><p>[4] AI Act Scientific Panel of 60 independent experts, established 1 June 2026 under Article 68 and Commission Implementing Regulation (EU) 2025/454 (7 March 2025); members serve in a personal capacity under confidentiality and conflict-of-interest declarations; most from academia, roughly a sixth from the ELLIS network. <a href="https://eur-lex.europa.eu/eli/reg_impl/2025/454/oj/eng">Implementing Regulation (EU) 2025/454</a>; European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/ai-scientific-panel">AI Scientific Panel</a>.</p><p>[5] AI Act Advisory Forum of 174 members under Article 67. European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/ai-advisory-forum">AI Advisory Forum</a>.</p><p>[6] General-purpose AI model obligations have applied since 2 August 2025 under Regulation (EU) 2024/1689; the Office&#8217;s power to impose penalties for breaches applies from 2 August 2026. <a href="https://www.dlapiper.com/en-us/insights/publications/2025/08/latest-wave-of-obligations-under-the-eu-ai-act-take-effect">DLA Piper</a>.</p><p>[7] Article 55 and the GPAI Code of Practice require providers of general-purpose models with systemic risk to conduct state-of-the-art model evaluations, assess and mitigate systemic risks, and submit a Safety and Security Model Report to the AI Office before placing the model on the market. <a href="https://artificialintelligenceact.eu/article/55/">Article 55</a>.</p><p>[8] Under the GPAI Code of Practice (Safety and Security chapter), signatories must give independent external evaluators access to their most advanced models before deployment and publish their evaluator-selection criteria; the requirement applies &#8220;in most circumstances,&#8221; with proportionality and exemptions, for example where a model is no more capable than an existing open-weight one. <a href="https://forum.effectivealtruism.org/posts/Z4DYcBDd36mwr5Xpq/the-world-s-first-frontier-ai-regulation-is-surprisingly">Analysis of the Code</a>.</p><p>[9] European Commission, European AI Office: &#8220;Call for participants: Workshop &#8212; qualification requirements for external evaluators of GPAI models with systemic risk,&#8221; 15 July 2026. <a href="https://digital-strategy.ec.europa.eu/en/policies/ai-office">European AI Office</a>.</p><p>[10] Independent evaluators (UK AISI, METR, Apollo, FAR.AI) work under voluntary 2024&#8211;2025 access agreements the labs grant and can withdraw; pre-deployment sharing has been thin (in one case a safety-tuned model with no fine-tuning access; a leading evaluator with no special pre-release access since around 2023), and the evidence base is overwhelmingly behavioural. Seth &amp; Sankarapu, <a href="https://arxiv.org/abs/2605.15164">arXiv:2605.15164</a> (Lexsi Labs, May 2026); <a href="https://ailabwatch.org/">AI Lab Watch</a>; access-level taxonomy in <a href="https://arxiv.org/abs/2601.11916">arXiv:2601.11916</a> (Jan 2026), finding external evaluators are typically restricted to black-box access and cannot examine model internals.</p><p>[11] A paper co-authored by the AI Office and the Joint Research Centre, &#8220;The science and practice of proportionality in AI risk evaluations,&#8221; appeared in Science (vol. 391, 6 March 2026), translating the legal proportionality test into criteria for how demanding a model evaluation must be; the JRC also runs an expert pool on GPAI risk categorisation and has catalogued the immaturity of current AI safety benchmarks. <a href="https://knowledge4policy.ec.europa.eu/news/new-paper-science-science-practice-proportionality-ai-risk-evaluations_en">Knowledge4Policy</a>; <a href="https://www.science.org/doi/10.1126/science.aea3835">Science</a>; JRC, <a href="https://publications.jrc.ec.europa.eu/repository/handle/JRC143259">AI safety benchmarks report</a>.</p><p>[12] The Scientific Panel may issue a qualified alert to the AI Office where it suspects a general-purpose model presents systemic risk; the alert is a trigger the Office may act on, not an automatic investigation. <a href="https://artificialintelligenceact.eu/article/90/">Article 90</a>.</p><p>[13] Harmonised standards under standardisation request M/593 were requested of CEN-CENELEC in 2023, missed the 2025 deadline and remain in development; the first reached public enquiry in late 2025, and such standards typically take two to four years, with acceleration measures adopted in October 2025 targeting completion by late 2026. The Digital Omnibus ties the start of the high-risk obligations to their availability. <a href="https://www.techpolicy.press/the-eus-real-ai-leverage-is-making-compliance-the-path-of-least-resistance/">TechPolicy.Press</a>.</p><p>[14] General-purpose obligations apply across the model lifecycle, including post-market modifications, with provider-set evaluation triggers; a downstream modification is treated as a new model chiefly where it exceeds roughly one-third of the original training compute (indicative), a bar the Commission expects few to cross. European Commission, <a href="https://digital-strategy.ec.europa.eu/en/faqs/general-purpose-ai-models-ai-act-questions-answers">GPAI Q&amp;A</a>.</p><p>[15] Breaches of the general-purpose obligations carry fines up to the greater of &#8364;15 million or 3% of worldwide annual turnover; high-risk obligations are deferred under the Omnibus to 2 December 2027. <a href="https://artificialintelligenceact.eu/article/101/">Article 101</a>.</p><p>[16] Article 92 empowers the AI Office, after consulting the Board, to conduct evaluations of a general-purpose model &#8212; to check compliance where information requested under Article 91 is insufficient, or to investigate systemic risk, in particular after a scientific-panel alert &#8212; and to appoint independent experts, including from the panel. It may request access via APIs or other means, including source code, with Article 101 fines for refusal; detailed arrangements await implementing acts not yet adopted. <a href="https://artificialintelligenceact.eu/article/92/">Article 92</a>; European Commission, <a href="https://digital-strategy.ec.europa.eu/en/faqs/general-purpose-ai-models-ai-act-questions-answers">GPAI Q&amp;A</a>.</p><p>[19] Executive Order, &#8220;Promoting Advanced Artificial Intelligence Innovation and Security,&#8221; 2 June 2026: directs a framework for developers to voluntarily grant the federal government up to 30 days of pre-deployment access to &#8220;covered frontier models,&#8221; with covered models set by a classified NSA benchmark, no mandatory licensing or pre-clearance, and no enforceable private right. <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">The White House</a>; <a href="https://www.crowell.com/en/insights/client-alerts/executive-order-creates-voluntary-regulatory-regime-of-frontier-ai-models">Crowell &amp; Moring</a>; <a href="https://www.mofo.com/resources/insights/260605-trump-issues-executive-order-seeking-to-promote-collaboration">Morrison &amp; Foerster</a>.</p><p>[20] The administration pulled an earlier draft of the order in May 2026 over concerns it would hinder US competitiveness, signing a softer version on 2 June. <a href="https://www.crowell.com/en/insights/client-alerts/executive-order-creates-voluntary-regulatory-regime-of-frontier-ai-models">Crowell &amp; Moring</a>.</p><p>[21] The order establishes a Department of Justice task force to challenge state AI laws. <a href="https://www.paulhastings.com/insights/client-alerts/president-trump-signs-executive-order-challenging-state-ai-laws">Paul Hastings</a>.</p><p>[22] US/EU divergence: a voluntary US framework versus binding EU general-purpose obligations with statutory penalties effective 2 August 2026. <a href="https://compliancehub.wiki/us-eu-ai-governance-divergence-frontier-eo-ai-act-2026/">ComplianceHub</a>.</p><p>[23] AI Act obligations attach when a model or system is placed on the EU market, regardless of where it was developed. <a href="http://data.europa.eu/eli/reg/2024/1689/oj">Regulation (EU) 2024/1689</a>.</p><p>[24] In 2024, Meta declined to release its multimodal Llama models in the EU, citing &#8220;the unpredictable nature of the European regulatory environment&#8221; (a text-only Llama shipped), and Apple delayed several Apple Intelligence features in the EU, citing Digital Markets Act uncertainty. <a href="https://www.axios.com/2024/07/17/meta-future-multimodal-ai-models-eu">Axios</a>; <a href="https://9to5mac.com/2024/07/18/meta-withholding-future-ai-models/">9to5Mac</a>.</p><p>[25] On 1 June 2026, the day before the executive order, Anthropic confidentially submitted a draft S-1 to the SEC at a valuation near $965 billion (following a $65 billion round the prior week). <a href="https://www.anthropic.com/news/confidential-draft-s1-sec">Anthropic</a>; <a href="https://fortune.com/2026/06/01/anthropic-confidentially-files-ipo-965-billion-valuation/">Fortune</a>; <a href="https://www.cnbc.com/2026/06/01/anthropic-ipo-s1-prospectus.html">CNBC</a>.</p><p>[26] The European Centre for Algorithmic Transparency (ECAT), established 2023 within the Joint Research Centre, gives the Commission in-house technical expertise to support its exclusive supervision of very large online platforms under the Digital Services Act. <a href="https://algorithmic-transparency.ec.europa.eu/index_en">ECAT</a>.</p><p>[27] First DSA non-compliance fine: &#8364;120 million on X, 5 December 2025, partly for barring researchers from effective access to its public data, with deadlines of 60 to 90 working days to remedy rather than pay. <a href="https://iapp.org/news/a/european-commission-fines-x-120m-euros-for-dsa-violations">IAPP</a>; <a href="https://www.euronews.com/my-europe/2025/12/05/european-commission-hits-elon-musks-social-network-x-with-120-million-fine">Euronews</a>.</p><p>[28] The Commission preliminarily found Meta and TikTok in breach of their obligation to give researchers access to public data (24 October 2025); across the DSA cases the recurring breach is denial of access, even though the law grants researchers a right to platform data. European Commission, <a href="https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktok-and-meta-breach-their-transparency-obligations-under-digital">preliminary findings</a>; <a href="https://www.science.org/content/article/meta-and-tiktok-are-obstructing-researchers-access-data-european-commission-rules">Science</a>.</p><p>[29] Under REACH, the European Chemicals Agency checks only a fraction of industry-submitted registration dossiers: the legal minimum rose from 5% to 20% in 2019, and ECHA examined about 21% of full registrations (&#8776;15,000) between 2009 and 2023; of 928 evaluations concluded in 2013, 61% were non-compliant with one or more information requirements, and in 2024, 313 compliance checks produced 208 data requests. <a href="https://echa.europa.eu/">ECHA</a>.</p><p>[30] The High-Level Expert Group on AI (convened 2018) produced the Ethics Guidelines for Trustworthy AI (April 2019) and the ALTAI self-assessment checklist (July 2020); a member, Thomas Metzinger, publicly called the exercise &#8220;ethics-washing,&#8221; noting roughly four ethicists among more than 50 members and the absence of red lines. European Commission, <a href="https://digital-strategy.ec.europa.eu/en/policies/expert-group-ai">High-Level Expert Group on AI</a>.</p>]]></content:encoded></item><item><title><![CDATA[Anthropic's Model Got Pulled. The Dangerous Ones Didn't. ]]></title><description><![CDATA[A US export order pulled Anthropic&#8217;s best model from every customer on earth in one evening. The thousands of models built to refuse nothing stayed online.]]></description><link>https://www.airealist.ai/p/anthropics-model-got-pulled-the-dangerous</link><guid isPermaLink="false">https://www.airealist.ai/p/anthropics-model-got-pulled-the-dangerous</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Mon, 15 Jun 2026 12:20:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BEpE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>As of June 15, 2026: Fable 5 and Mythos 5 remain suspended; Anthropic and the administration are in active talks, with officials suggesting access could be restored &#8220;in the next few weeks.&#8221; No reinstatement and no published rule or Federal Register notice as of filing.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BEpE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BEpE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BEpE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dec39e21-2e24-42a8-8440-59192ad73195_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1789009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/202113432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BEpE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!BEpE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdec39e21-2e24-42a8-8440-59192ad73195_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On Friday, June 12, at 5:21 pm Eastern, Anthropic received a letter from the U.S. Commerce Department. By that evening, Fable 5 and Mythos 5 &#8212; the company&#8217;s two most capable models, launched three days earlier &#8212; were gone. Not throttled. Not region-locked. Gone, for every customer Anthropic has, including the banks and agencies that had been using Mythos-class capability for vulnerability discovery. [1]</p><p>The mechanism is worth getting right because most of the coverage has it slightly wrong. Nobody flipped a remote kill switch. The government issued an <em>export-control directive</em> citing national security authorities, ordering Anthropic to suspend access for any foreign national, whether outside the United States or within it, including Anthropic&#8217;s own foreign national employees. [2] That last reach is the sharp part: under the deemed-export doctrine, giving a controlled technology to a foreign national on US soil counts as an export to their home country, so the order swept in Anthropic&#8217;s own non-citizen staff alongside every user abroad. A company cannot filter foreign nationals from US citizens in real time across a consumer product, so the only way to comply was to disable the models for everyone. The order's reach did the work. The global takedown was the side effect.</p><p>In April, in an internal briefing for the CEOs of portfolio companies I help oversee, I argued that the defining feature of the AI security landscape is an asymmetry: defenders are governed, and attackers are not. Procurement rules, compliance regimes, and data-sovereignty constraints dictate which models a defender may run. Attackers self-host abliterated open-weight models &#8212; models with the refusal behavior surgically removed from the weights &#8212; and answer to none of it. June 12 is that asymmetry rendered in a single week.</p><p>Here is the sharpened version. The week the most heavily safeguarded frontier model on the market was withdrawn from the entire planet over a <em>narrow, non-universal</em> jailbreak, a bypass that unlocks one sliver of capability in one circumstance. The abliterated open-weight models on Hugging Face stayed exactly where they were. The platform&#8217;s own &#8220;obliterated&#8221; tag now returns <a href="https://huggingface.co/models?other=abliterated">over 7,000 of them</a>. [3] No export order reaches those. There is no account to suspend, no API to revoke, and no US-jurisdiction entity in the chain to serve. The governed model can be removed from hundreds of millions of users by one letter. The ungoverned model cannot be removed from anyone by anything.</p><p>Abliteration is not a jailbreak, and the difference is the whole argument. A jailbreak is an input attack &#8212; a crafted prompt that tricks an aligned model into complying &#8212; and the provider can patch it, filter it, or ban the account that sent it. Abliteration is surgery on the model itself. In 2024, researchers showed that a chat model&#8217;s willingness to refuse is mediated by a single direction in its internal activations: erase that direction from the weights, and the model loses the ability to say no while keeping nearly all its other capabilities. [4] The edit is baked into the file. Once those weights are on a hard drive, there is no refusal left to bypass and nothing for a vendor to fix. A jailbreak is a lock that can be picked. Abliteration removes the door.</p><p>What changed since 2024 is not the idea but the cost. The original technique required a researcher who understood transformer internals; the current tooling takes a command line &#8212; one openly published tool decensors a small model in under an hour on a single consumer GPU, no expertise required &#8212; and a single registry now hosts more than 200 ablated models. [5] The tempo asymmetry is the part defenders underweight: a frontier lab spends months red-teaming a release &#8212; Anthropic says thousands of hours on Fable &#8212; while the community publishes the de-safetied counterpart of a comparable open-weight release within a day or two of launch.</p><p>The honest objection is that some models try to resist this, but it does not hold. Published defenses &#8212; circuit breakers, extended-refusal training &#8212; work in the lab. But the labs don&#8217;t ship them inside the frontier open weights that actually get downloaded, the strongest results are on small models, and by 2026, public tooling already claims to defeat them, driving even Google&#8217;s hardened Gemma 4 to single-digit refusal rates. [6] Hardening raises the price of the operation. It does not close it.</p><p>The readers of this newsletter will see this as the activation of the coercion stack described in <em><a href="https://www.airealist.ai/p/access-disable-destroy">Access, Disable, Destroy</a></em>, but through a route the original map didn&#8217;t draw. The off switch was not held by the model provider, nor by a sanctioning authority pointed at a foreign adversary. According to the Wall Street Journal and The Information, the finding that triggered the order came from Amazon &#8212; Anthropic&#8217;s largest investor and its primary cloud partner, on whose Bedrock platform the model most likely ran. Amazon&#8217;s researchers found the bypass; CEO Andy Jassy raised it with senior officials, including Treasury Secretary Scott Bessent; Commerce Secretary Howard Lutnick sent the letter. [7] </p><p>Reporting a live cyber bypass is defensible: a researcher who finds one should disclose it, whoever signs their checks. The hazard is not Amazon&#8217;s motive. It is that one firm now bankrolls the vendor, hosts its models, and supplies the findings behind the federal action against it: three chairs, one occupant, a governance problem, whether anyone acted in bad faith. That row did not exist on the original coercion-stack table. It does now.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tO_6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tO_6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 424w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 848w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 1272w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tO_6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png" width="1456" height="949" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:949,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:223009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/202113432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tO_6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 424w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 848w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 1272w, https://substackcdn.com/image/fetch/$s_!tO_6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F558ba09e-80e8-45d9-9ac6-4ce6beface68_2240x1460.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Concede the government&#8217;s strongest case: Mythos is a genuinely dangerous capability. Anthropic itself withheld it from public release and lobbied for Mythos-class models to be treated as cyberweapons. A jailbreak that unlocks even a sliver of that capability on a model deployed to hundreds of millions of people is a real finding, not a clerical one. David Sacks, the administration&#8217;s former AI czar, put the case bluntly: a bypass &#8220;allowing operability of a cyber weapon&#8221; is hard to call anything but serious, and Anthropic&#8217;s minimizing language was &#8220;not consistent with Anthropic&#8217;s brand as the AI safety company.&#8221; [8] That last clause is the hinge, and it is where the story turns from a regulatory dispute into something closer to a Greek tragedy.</p><p>Anthropic supplied the moral framing that took its model down. On or around June 10 &#8212; a day after Fable 5 launched, two days before the letter arrived &#8212; Dario Amodei published an essay titled <em><a href="https://darioamodei.com/post/policy-on-the-ai-exponential">Policy on the AI Exponential</a></em>. In it, in his own boldface, he argued that frontier models &#8220;should be required to go through technical testing and auditing, and their release should be blocked or reversed as a threat to public safety if they do not meet high standards of safety.&#8221; He named the analogy himself: the FAA grounding an unsafe aircraft. He called, in the same essay, for export controls on the AI supply chain to be &#8220;expanded, tightened, and coordinated.&#8221; [9] Two days later the government blocked his release, citing safety, using an export control.</p><p>Here is the cruelty in it. Amodei did not receive the apparatus he requested. He proposed a deliberative, statutory process: a third-party technical evaluation and explicit protection against &#8220;political favoritism or arbitrary decisions.&#8221; What arrived was a verbal directive on roughly ninety minutes&#8217; notice, with no specific national-security detail and no third-party finding shared, the opposite of the process he described. Anthropic&#8217;s own statement says so: &#8220;This action does not adhere to those principles.&#8221; [10] But the principle the administration <em>did</em> use &#8212; that government may block or reverse a frontier release on safety grounds &#8212; is the one Anthropic spent years legitimizing. Sacks then turned the company&#8217;s safety branding back on it, arguing that it should have complied without argument. The lab supplied the moral framework; the government supplied a blunter instrument than the lab wanted; and the safety reputation Anthropic built became the lever its own funder&#8217;s disclosure pried.</p><p>The asymmetry is what makes something load-bearing, and it should change how you price a dependency. The durability of a closed frontier model is not a function of the vendor's uptime or balance sheet. It is a function of a regulatory surface the vendor does not control and cannot predict &#8212; and that surface, as of June 12, can be activated by the firm that funds and hosts the vendor. The substitute sitting one tier down &#8212; the abliterated open-weight model an attacker runs on a few GPUs at most &#8212; lacks such a surface. The best open-weight models now trail the closed frontier by about four months, not the chasm that gap used to be; abliteration is a separate operation layered on top, stripping refusals from a model that is already near-peer. [11] So the substitute is not as capable as Mythos, but it is close, it is permanent, and it is &#8212; in the only sense that matters to whoever is probing your systems &#8212; more reliably available than the safety-first product it imitates. </p><p>The model built to refuse can be withdrawn from everyone. The model built to refuse nothing cannot be withdrawn from anyone.</p><h3>Notes</h3><p>[1] Anthropic, <a href="https://www.anthropic.com/news/fable-mythos-access">&#8220;Statement on the US government directive to suspend access to Fable 5 and Mythos 5&#8221;</a>, June 12, 2026; launch date (June 9) and enterprise-customer impact per <a href="https://www.marktechpost.com/2026/06/13/anthropic-disables-claude-fable-5-and-mythos-5-after-us-government-order/">MarkTechPost</a>, June 13, 2026, and <a href="https://mlq.ai/news/amazons-jassy-alerted-white-house-to-anthropic-fable-5-security-flaws-triggering-export-ban/">MLQ News</a>, June 13, 2026.</p><p>[2] <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic statement</a>, June 12, 2026 (full text of the scope language, including foreign-national employees); corroborated by Axios, <a href="https://www.axios.com/2026/06/12/anthropic-trump-mythos-fable-national-security">&#8220;Trump admin blocks foreign access to Anthropic&#8217;s most powerful AI&#8221;</a>, June 12, 2026.</p><p>[3] Hugging Face&#8217;s <code>abliterated</code><a href="https://huggingface.co/models?other=abliterated"> tag filter</a> returned roughly 7,500 model repos as of mid-June 2026. The &#8220;over six thousand... against roughly six hundred two years ago&#8221; figure is from <a href="https://www.npr.org/">NPR</a>, citing University of Nebraska Omaha (NCITE) research, &#8220;These AI models are free, private, and will never say &#8216;no,&#8217;&#8221; May 31, 2026. The tag count includes quantizations and mirrors, not solely unique base-model abliterations, and is rising &#8212; retrieve a current figure at publication.</p><p>[4] Andy Arditi et al., <a href="https://arxiv.org/abs/2406.11717">&#8220;Refusal in Language Models Is Mediated by a Single Direction&#8221;</a>, arXiv 2406.11717 (submitted June 2024; NeurIPS 2024). The paper demonstrates across 13 open chat models up to 72B that refusal is mediated by a one-dimensional subspace; ablating that direction from the weights (weight orthogonalization) removes refusal while preserving other capabilities. The permanence-once-distributed characterization follows from the edit being to the weights themselves.</p><p>[5] <a href="https://github.com/p-e-w/heretic">Heretic</a> (Philipp Emanuel Weidmann, &#8220;p-e-w&#8221;), released late 2025 (PyPI <code>heretic-llm</code>), automates directional ablation via an Optuna/TPE optimizer; its README reports ~45 minutes to decensor Llama-3.1-8B-Instruct on an RTX 3090 (20&#8211;30 minutes for Qwen3-4B), corroborated by NPR (n.3) for the &#8220;few minutes,&#8221; no-expertise characterization. Registry scale: <a href="https://huggingface.co/huihui-ai">huihui-ai</a> hosted 235 models with 7,406 followers as of June 15, 2026. Speed-of-appearance (abliterated builds within ~24&#8211;72 hours of a major release) per huihui-ai&#8217;s published Gemma 4 / Qwen abliterations and activity feed. Anthropic&#8217;s &#8220;thousands of hours&#8221; of Fable red-teaming is from its launch posture as summarized in its June 12 statement (n.2).</p><p>[6] Defenses and the offense&#8217;s response: circuit breakers / Representation Rerouting per Zou et al., <a href="https://arxiv.org/abs/2406.04313">&#8220;Improving Alignment and Robustness with Circuit Breakers&#8221;</a>, arXiv 2406.04313 (NeurIPS 2024); extended-refusal training per Abu Shairah et al. (KAUST), <a href="https://arxiv.org/abs/2505.19056">&#8220;An Embarrassingly Simple Defense Against LLM Abliteration Attacks&#8221;</a>, arXiv 2505.19056 (May 2025), reporting treated models retaining &gt;90% refusal under abliteration versus 70&#8211;80% drops for baselines &#8212; demonstrated on small/older models. Offense keeping pace: <a href="https://github.com/wuwangzhang1216/abliterix">Abliterix</a>, a Heretic derivative, claims to defeat circuit breakers and to reach a ~7% refusal rate on Google&#8217;s Gemma 4 (E4B) via direct weight editing. These refusal-rate figures are self-reported by the abliterating parties and are highly method-dependent; treated as directional, not measured.</p><p>[7] Wall Street Journal, <a href="https://www.wsj.com/tech/ai/amazon-ceos-talks-with-u-s-officials-triggered-crackdown-on-anthropic-models-dcc90578">&#8220;Amazon CEO&#8217;s talks with U.S. officials triggered crackdown on Anthropic models&#8221;</a>, June 13, 2026 (WSJ names Bessent as one of several officials Jassy contacted); The Information, <a href="https://www.theinformation.com/articles/amazons-jassy-raised-concerns-anthropic-model-trump-crackdown">&#8220;Amazon&#8217;s Jassy raised concerns about Anthropic model, Trump crackdown&#8221;</a>, June 13, 2026. Lutnick (Commerce) sent the directive per Anthropic&#8217;s statement and Axios. Amazon&#8217;s investment ($8B deployed to date, plus an up-to-$25B commitment agreed April 2026) and AWS cloud partnership per CNBC, Nov 22, 2024 and April 20, 2026; the same CNBC reporting confirms &#8220;Amazon does not have a seat on Anthropic&#8217;s board.&#8221; Bedrock as the likely test surface is inference, flagged as such.</p><p>[8] David Sacks, <a href="https://x.com/DavidSacks/status/2065853007619588171">post on X</a>, June 13, 2026.</p><p>[9] Dario Amodei, <a href="https://darioamodei.com/post/policy-on-the-ai-exponential">&#8220;Policy on the AI Exponential&#8221;</a>, dated &#8220;June 2026&#8221; on the primary page; secondary trackers place publication on or around June 10, 2026. The &#8220;blocked or reversed&#8221; sentence and the FAA analogy are in Section 1 (Regulation and public safety); the &#8220;expanded, tightened, and coordinated&#8221; export-control language is in Section 5 (Securing leadership by democracies) and refers to chips and semiconductor manufacturing equipment. The essay&#8217;s separate &#8220;off switch&#8221; phrasing appears in Section 4 and refers to autonomous-weapons oversight, not model release &#8212; not conflated here.</p><p>[10] Sacks, X, June 13, 2026 (as n.8).</p><p>[11] Epoch AI, <a href="https://epoch.ai/data-insights/open-closed-eci-gap">"Open models lag state-of-the-art closed models by 4 months"</a> (Jack Edwards and Luke Emberson), data covering Jan 1&#8211;May 28, 2026: the most capable open-weight models trailed frontier closed models by an average of four months, or 8 points on Epoch's composite Capabilities Index &#8212; up slightly from the ~3-month average Epoch measured for Jan 2023&#8211;Oct 2025. This is a capability gap (open vs. closed frontier); abliteration is a distinct operation that removes refusals without adding capability, applied on top of an already-near-frontier open model. The two are not the same axis and are not conflated here.</p>]]></content:encoded></item><item><title><![CDATA[Cash Flow Lends. Valuation Doesn’t.]]></title><description><![CDATA[Three borrowers, three answers, seventy-two hours. The AI debt boom did not slow down last week. It got priced.]]></description><link>https://www.airealist.ai/p/cash-flow-lends-valuation-doesnt</link><guid isPermaLink="false">https://www.airealist.ai/p/cash-flow-lends-valuation-doesnt</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Fri, 12 Jun 2026 07:09:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XEAb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XEAb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XEAb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XEAb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2343953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201708558?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XEAb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!XEAb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64006cc4-a512-404d-aca1-b22bdf799449_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">On June 8, Amazon signed a $17.5 billion loan it can draw at will, with no financial covenants attached. Two days later, Oracle told investors it would raise roughly $40 billion more and unveiled a new accounting measure to explain why its capex is not quite its capex. The same day, Bloomberg reported that SoftBank could not borrow $6 billion against its OpenAI stake.</p><p style="text-align: justify;">The volume itself is no longer news. Morgan Stanley estimates nearly $236 billion of AI-linked debt has been issued globally through May, four times last year&#8217;s pace, and expects close to $570 billion for the full year [1]. UBS estimates that hyperscaler capex will consume close to 100% of operating cash flow in 2026, compared with a ten-year average of 40% [2]. Everyone now knows the buildout runs on debt. What last week revealed is who gets to borrow it, on what terms, and against what.</p><p style="text-align: justify;">Start with the cheapest money. <strong>Amazon&#8217;s facility is a senior unsecured delayed-draw term loan led by Citibank</strong>: the company can pull funds as needed through September 30, each draw repayable over three years, at 0.625% to 0.875% over SOFR, the floating benchmark rate, depending on ratings [3]. It landed days after Amazon priced the largest Canadian-dollar corporate bond in history, a C$14 billion deal that drew more than C$28 billion in orders [4]. This is for a company whose trailing free cash flow has collapsed to $1.2 billion from $25.9 billion a year earlier, on the way to roughly $200 billion of capex this year [5]. The banks looked straight past the AI bet. Unsecured borrowing with no financial covenants is routine at Amazon&#8217;s rating &#8212; and that is the point. What stands behind the loan is the retail engine and AWS&#8217;s operating cash flow: businesses already earning, whatever the GPUs return tomorrow.</p><p style="text-align: justify;"><strong>Oracle got the conditional money</strong>. Its fiscal Q4, reported June 10, beat the headline estimates: $19.2 billion in revenue, $2.11 in adjusted EPS, and remaining performance obligations &#8212; contracted future revenue &#8212; of $638 billion, up 363% in a year and up $85 billion in a single quarter [6]. The stock fell anyway, not the first time this fiscal year, a headline beat has been sold [7]. The funding side explains it. Free cash flow for the year was negative $23.7 billion. Oracle raised $43 billion in debt and $5 billion in equity in fiscal 2026, and plans roughly $40 billion more this year, including a previously announced $20 billion at-the-market equity program (new shares sold directly into the market) [8]. The buildout has crossed a line worth stating plainly: reported capex of $90&#8211;95 billion next fiscal year, against $90 billion of guided total revenue for the same year [8]. Oracle plans to spend its entire revenue, roughly, on capital expenditures.</p><p style="text-align: justify;">And it introduced a new number. &#8220;Net cash outlay for capital expenditures&#8221; is guided around $70 billion for fiscal 2027, against the same $90&#8211;95 billion in reported capex; the gap is due to customers prepaying for GPUs or supplying their own [9]. Those arrangements now total $75 billion across Oracle&#8217;s large AI contracts, and the company says they substantially reduce the capital it must raise [10]. Read that twice. Oracle is publishing a table showing lenders which parts of its capex are really someone else&#8217;s. The arrangement is genuine &#8212; prepaid hardware does reduce Oracle&#8217;s funding needs &#8212; but it shifts risk rather than removing it. The $75 billion is banked; the rest of the backlog, largely anchored to OpenAI through Stargate [11], still depends on customers being able to pay, quarter after quarter, for years. When a borrower starts inventing measures to reassure the market, the market has started asking questions.</p><p style="text-align: justify;">What did Amazon&#8217;s lenders see that SoftBank&#8217;s couldn&#8217;t? The answer is a hierarchy worth understanding before the second half of Morgan Stanley&#8217;s $570 billion arrives.</p><p style="text-align: justify;"><strong>SoftBank asked for the third kind of money and didn&#8217;t get it</strong>. In May, it sought a $10 billion margin loan backed by its OpenAI stake; lender hesitation cut the target to $6 billion; on June 10, the talks stalled outright [12]. SoftBank may yet revive them. About $5 billion had been lined up, though it was unclear whether those commitments were verbal or written [13]. The sticking point was not OpenAI&#8217;s prospects. It was the collateral itself. OpenAI is private; its valuation is set by funding rounds rather than a liquid market, and a margin lender needs collateral that it can price daily and sell quickly. A stake last marked inside a $122 billion round at an $852 billion post-money valuation [14] turned out to be worth, for borrowing purposes, nothing yet. The stall came even though OpenAI had confirmed, two days earlier, a confidential filing for a US listing that could debut as soon as the fall [15]. Some of the same prospective lenders had said the IPO news made the loan more attractive. They still walked. The clock, meanwhile, is real: a $40 billion bridge loan taken on to fund SoftBank&#8217;s OpenAI commitments comes due in March 2027 [16]. Shares fell as much as 9.7% on the news, nine days after the company had overtaken Toyota as Japan&#8217;s most valuable [17].</p><p style="text-align: justify;">Strip away the deal terms, and the three answers reduce to one question: <strong>what gets the lender repaid?</strong> Amazon&#8217;s creditors are repaid from businesses that predate the AI bet and would survive its disappointment. Oracle&#8217;s creditors are repaid from backlog: promises from customers whose own funding remains unproven. SoftBank&#8217;s would have been repaid from a mark: a number set by the last buyer in a private round, untested by any open market. The week&#8217;s pricing followed that gradient without sentiment. <strong>Cheapest against yesterday&#8217;s cash. Conditional, and increasingly explained, against tomorrow&#8217;s contracts. Refused against a number on a page.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lAjh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lAjh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 424w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 848w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 1272w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lAjh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png" width="1456" height="1060" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1060,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:255463,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201708558?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lAjh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 424w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 848w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 1272w, https://substackcdn.com/image/fetch/$s_!lAjh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c8fe20b-9222-4c43-a8a6-bbf346a4bb8a_1872x1363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">None of this says the lending stops. Morgan Stanley expects issuance to accelerate in the second half [1]. It says the lending discriminates, and what it discriminates against is distance from cash. Each rung down the ladder, the borrower pays more, explains more, and pledges more. At the bottom rung, the market said no to collateral with a listing already in motion. A ticker will do what the mark could not; the prospect of one was not enough. This reading would be wrong if SoftBank closes its loan at or near $6 billion before the IPO prices, or if Oracle&#8217;s $40 billion raise comes as ordinary investment-grade debt without leaning on equity. Either outcome would mean the market lends against marks and backlog as readily as against cash flow after all.</p><p style="text-align: justify;">Until then, the hierarchy stands. <strong>Cash flow lends. Backlog negotiates. Valuation waits for its ticker.</strong></p><div><hr></div><h3>Notes</h3><p>[1] Morgan Stanley research note, June 10, 2026, as reported by <a href="https://techstartups.com/2026/06/10/ai-debt-boom-global-ai-debt-issuance-to-top-570-billion-as-big-tech-races-toward-1-trillion-in-ai-infrastructure-spending-morgan-stanley-says/">Reuters via Tech Startups</a>: ~$236 billion in AI-linked global debt issuance through May 31, 2026, roughly four times the prior-year pace; full-year 2026 forecast of nearly $570 billion. Analyst estimate, not a measured total.</p><p>[2] UBS estimate, as reported by <a href="https://www.techtimes.com/articles/318171/20260610/morgan-stanley-sees-ai-debt-nearly-doubling-570-billion-2026-bonds-now-fund-buildout.htm">TechTimes</a>: 2026 hyperscaler capital spending on pace to consume close to 100% of operating cash flows, versus a 10-year average of about 40%. Analyst estimate.</p><p>[3] <a href="https://www.sec.gov/Archives/edgar/data/0001018724/000110465926072140/tm2613616d4_8k.htm">Amazon Form 8-K</a>, filed June 10, 2026: term loan agreement dated June 8, 2026, Citibank N.A. as administrative agent; $17.5 billion senior unsecured delayed draw term loan facility; commitments expire September 30, 2026; three-year maturity per draw. SOFR margin of 0.625&#8211;0.875% depending on ratings and the absence of financial covenants per the filing as reported by <a href="https://finance.yahoo.com/sectors/technology/articles/amazon-secures-17-5-billion-133641308.html">Yahoo Finance</a>; the agreement retains customary covenants and events of default. Joint lead arrangers: Citibank, JPMorgan, BofA Securities, HSBC, Wells Fargo.</p><p>[4] <a href="https://www.bloomberg.com/news/articles/2026-06-08/amazon-kicks-off-canadian-dollar-investment-grade-bond-offering">Bloomberg</a>: C$14 billion (~$10 billion) priced June 8, 2026, the largest corporate debt offering on record in Canadian dollars, with more than C$28 billion in orders. <a href="https://www.investing.com/news/economy-news/amazon-issues-recordsetting-canadian-dollardenominated-corporate-bond-deal-4733619">Reuters</a> confirms from the final pricing term sheet filed with the SEC: five tranches, maturities 2029&#8211;2056, surpassing Alphabet&#8217;s C$8.5 billion record set a month earlier.</p><p>[5] <a href="https://finance.yahoo.com/sectors/technology/articles/amazon-secures-17-5-billion-133641308.html">Yahoo Finance</a>, per Amazon&#8217;s Q1 2026 results: trailing-twelve-month free cash flow of $1.2 billion versus $25.9 billion a year earlier; Q1 2026 capex of $44.2 billion; ~$200 billion full-year 2026 capex plan disclosed with Q4 2025 earnings.</p><p>[6] <a href="https://www.sec.gov/Archives/edgar/data/0001341439/000119312526265848/orcl-ex99_1.htm">Oracle Q4 FY2026 earnings press release</a> (Form 8-K exhibit, June 10, 2026): RPO of $638 billion, up 363% year-over-year and up $85 billion sequentially. Revenue and EPS beats per <a href="https://sherwood.news/tech/oracle-q4-earnings-and-revenue-top-estimates/">Sherwood News</a>: revenue $19.2 billion vs. $19.1 billion expected; adjusted EPS $2.11 vs. $1.96 expected ($2.03 excluding one-time net investment gains). One miss beneath the headlines, per <a href="https://finance.yahoo.com/sectors/technology/article/oracle-q4-earnings-beat-on-revenue-but-miss-on-cloud-sales-221337908.html">Yahoo Finance</a>: total cloud revenue of $9.91 billion came in below the $9.99 billion consensus, with cloud applications light and cloud infrastructure ahead.</p><p>[7] <a href="https://sherwood.news/tech/oracle-q4-earnings-and-revenue-top-estimates/">Sherwood News</a> and <a href="https://www.thestreet.com/latest-news/orcl-oracle-earnings-call-updates-q4-2026">TheStreet</a>. Shares fell in after-hours trading on June 10 despite the beats. Precedent: in Q2 FY2026, a 32.4% EPS beat was followed by a -10.8% day-of move (<a href="https://247wallst.com/investing/2026/06/10/live-will-oracle-crush-q4-earnings-after-the-market-closes-tonight/">24/7 Wall St.</a>). Note the broader tape: May CPI printed at a three-year high the same day, and all three major US indices fell, so the decline was not purely company-specific.</p><p>[8] <a href="https://www.sec.gov/Archives/edgar/data/0001341439/000119312526265848/orcl-ex99_1.htm">Oracle Q4 FY2026 earnings press release</a>: fiscal 2026 free cash flow of negative $23.7 billion; $43 billion raised in debt financing and $5 billion in equity financing in fiscal 2026; approximately $40 billion in combined debt and equity financing planned for fiscal 2027, including the previously announced $20 billion at-the-market equity issuance; fiscal 2027 total revenue guidance confirmed at $90 billion. The release adds that Oracle &#8220;does not expect to issue additional debt in calendar year 2026&#8221; &#8212; making the near-term portion of the raise equity-led by the company&#8217;s own statement. The $90&#8211;95 billion reported-capex figure for fiscal 2027 is from the earnings call (see [9]).</p><p>[9] Oracle Q4 FY2026 <a href="https://www.investing.com/news/transcripts/earnings-call-transcript-oracle-q4-2026-earnings-beat-expectations-despite-stock-dip-93CH-4736322">earnings call</a>, June 10, 2026: expected net cash outlay for capital expenditures of around $70 billion in fiscal 2027, with customer prepayments and timing impacts of $20&#8211;25 billion raising reported capex above that figure; the press release includes a reconciliation table for the new measure, and CFO Hilary Maxson detailed it on the call (<a href="https://www.cnbc.com/2026/06/10/oracle-orcl-q4-earnings-report-2026.html">CNBC</a>). Fiscal 2026 net cash outlay was $48 billion after ~$8 billion of prepayment and timing impacts, against $55.7 billion of reported capex &#8212; up 162% year-over-year, with depreciation nearly doubling to $7.62 billion.</p><p>[10] <a href="https://www.sec.gov/Archives/edgar/data/0001341439/000119312526265848/orcl-ex99_1.htm">Oracle Q4 FY2026 earnings press release</a>: prepaid and customer-supplied hardware portions of large AI contracts total $75 billion, which the company states &#8220;substantially reduces the amount of capital Oracle must raise&#8221; for its AI datacenter buildout.</p><p>[11] <a href="https://sherwood.news/tech/oracle-q4-earnings-and-revenue-top-estimates/">Sherwood News</a>: the RPO balance is largely anchored by Oracle&#8217;s OpenAI partnership under the $500 billion Stargate initiative. Bank of America analysts estimate that over 50% of the remaining performance obligation comes from OpenAI (<a href="https://www.cnbc.com/2026/06/10/oracle-orcl-q4-earnings-report-2026.html">CNBC</a>); analyst estimate, not a company disclosure.</p><p>[12] <a href="https://www.bloomberg.com/news/articles/2026-06-10/softbank-s-attempt-to-get-6-billion-openai-margin-loan-stalls">Bloomberg</a>, June 10, 2026: talks to raise at least $6 billion via a margin loan backed by SoftBank&#8217;s OpenAI stake have stalled; the initial $10 billion target was cut by 40% in May after lender hesitation. SoftBank may resume the margin loan later and is considering other fundraising options. A fair objection: SoftBank itself is rated BB+ with a negative outlook from <a href="https://www.bloomberg.com/news/articles/2026-03-03/softbank-s-30-billion-openai-bet-spurs-s-p-credit-outlook-cut">S&amp;P</a> (revised March 3, 2026, on the additional $30 billion OpenAI commitment), so borrower quality may have weighed on the talks. But margin lending looks to the collateral first, and the concern lenders voiced, per Bloomberg&#8217;s reporting, was the difficulty of valuing an unlisted company &#8212; not SoftBank&#8217;s own credit.</p><p>[13] <a href="https://finance.yahoo.com/markets/stocks/articles/softbank-attempt-6-billion-openai-042525869.html">Bloomberg via Yahoo Finance</a>: approximately $5 billion had been secured before talks stalled, though it was unclear whether commitments were verbal or written.</p><p>[14] <a href="https://openai.com/index/accelerating-the-next-phase-ai/">OpenAI announcement</a>, March 31, 2026: the round closed with $122 billion in committed capital at a post-money valuation of $852 billion; confirmed by <a href="https://www.bloomberg.com/news/articles/2026-03-31/openai-valued-at-852-billion-after-completing-122-billion-round">Bloomberg</a>. SoftBank contributed $30 billion of the round. The figure is a private-round valuation, not a market price &#8212; which is the point.</p><p>[15] <a href="https://www.theedgesingapore.com/amp/news/tech/softbanks-attempt-get-us6-bil-openai-margin-loan-stalls--bloomberg">Bloomberg via The Edge Singapore</a>: OpenAI said on Monday, June 8, that it filed confidentially for a US IPO and is working with Goldman Sachs and Morgan Stanley on a potential listing as soon as the fall. Some prospective lenders on the margin loan had said they viewed it more favorably after news of the IPO preparation; the talks stalled regardless.</p><p>[16] <a href="https://finance.yahoo.com/markets/stocks/articles/softbank-6-billion-openai-margin-130347475.html">Bloomberg via Yahoo Finance</a> and <a href="https://qz.com/softbank-openai-margin-loan-stalled-061026">Quartz</a>: a $40 billion bridge loan taken on to fund SoftBank&#8217;s OpenAI commitments comes due in March 2027; SoftBank has indicated it intends to cover it from existing assets plus additional financing. Counterpoint on severity from Hua Cheng, head of Asia credit research at AllianceBernstein, who called the stalled margin loan one piece of a larger puzzle and not a standalone red flag.</p><p>[17] <a href="https://finance.yahoo.com/markets/stocks/articles/softbank-attempt-6-billion-openai-042525869.html">Bloomberg via Yahoo Finance</a>: shares declined as much as 9.7% on June 10; SoftBank had overtaken Toyota as Japan&#8217;s most valuable company by market capitalization on June 1 (<a href="https://www.bloomberg.com/news/articles/2026-06-01/softbank-set-to-dethrone-toyota-as-japan-s-most-valuable-company">Bloomberg</a>, <a href="https://asia.nikkei.com/business/markets/equities/softbank-dethrones-toyota-as-japan-s-most-valuable-company">Nikkei Asia</a>) &#8212; the first time in more than two decades. SoftBank&#8217;s credit default swaps had narrowed to about 307 basis points from a May 20 peak above 367 &#8212; the credit market was already charging for the OpenAI concentration before the loan stalled.</p>]]></content:encoded></item><item><title><![CDATA[Nvidia Won the Cloud. Now It Wants the Laptop.]]></title><description><![CDATA[Nvidia&#8217;s new laptop chip trails Apple where it counts and it was built to win anyway.]]></description><link>https://www.airealist.ai/p/nvidia-won-the-cloud-now-it-wants</link><guid isPermaLink="false">https://www.airealist.ai/p/nvidia-won-the-cloud-now-it-wants</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Thu, 11 Jun 2026 11:26:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JgZx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JgZx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JgZx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JgZx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg" width="1168" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1168,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180094,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201453469?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JgZx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JgZx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff946b818-3692-4a87-9800-49537d03db2f_1168x784.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Jensen Huang stood at the Taipei Music Center on the last day of May and announced that Nvidia intended to &#8220;reinvent the single most important tool of humanity.&#8221;[1] The tool in question is the personal computer, and the product behind the sentence is a laptop chip: RTX Spark, a 20-core Arm processor fused to a Blackwell GPU around a 128-gigabyte pool of memory, co-announced with Microsoft.[2] It ships this fall in machines from Asus, Dell, HP, Lenovo, and MSI, with a Surface Laptop Ultra as the flagship. Shares of AMD, Intel, and Qualcomm fell on the news.[3] The market read the announcement as a land grab in the PC business.</p><p style="text-align: justify;">Eight weeks earlier, this publication described the single move that could pull local AI back into Nvidia&#8217;s orbit. In &#8220;<a href="https://www.airealist.ai/p/your-parents-paid">Your Parents Paid</a>,&#8221; we documented how Nvidia&#8217;s own product segmentation had handed the fastest-growing consumer AI workload to Apple and AMD, and we listed three conditions under which that would reverse. The third: &#8220;the CUDA moat extends into inference. If NVIDIA ships inference-specific optimizations &#8212; through TensorRT-LLM, NIM, or a CUDA-exclusive quantization format &#8212; that make the performance gap too large to ignore, practitioners return to NVIDIA hardware regardless of memory capacity.&#8221;[4]</p><p style="text-align: justify;">RTX Spark is condition three, shipped as a product line. But it arrived with a twist we didn&#8217;t predict: <strong>Nvidia isn&#8217;t closing the performance gap. It&#8217;s making the gap irrelevant.</strong></p><h2>The spec sheet and the missing number</h2><p style="text-align: justify;">Start with what Nvidia published. The RTX Spark product page lists up to 6,144 CUDA cores on the Blackwell GPU, up to 20 CPU cores, up to 1 petaflop of FP4 AI performance, and up to 128 gigabytes of unified memory.[2] On stage, Huang claimed the chip runs 120-billion-parameter models locally.[5] That claim deserves a moment of respect. In April, we showed that the 120B model class needed 60-70 gigabytes at usable quantization and therefore did not fit on any consumer Nvidia product. The 32-gigabyte ceiling on the RTX 5090 was the centerpiece of Nvidia&#8217;s segmentation, the design choice that pushed private-inference buyers toward a $3,699 Mac Studio.[4] RTX Spark removes that ceiling. The capacity objection is gone.</p><p style="text-align: justify;">Now look for the number that isn&#8217;t there. The product page lists cores, petaflops, and gigabytes. It does not list memory bandwidth.[6] For local language models, bandwidth is the most important metric: token generation reads the entire working set of model weights from memory for every token, making decode speed a near-linear function of memory throughput. Capacity decides whether a model loads. Bandwidth decides whether you can stand to use it. Nvidia headlined the first number and buried the second, the same disclosure pattern it used for the DGX Spark desktop, whose 273 GB/s figure appeared in technical documentation rather than marketing.[7]</p><p style="text-align: justify;">Launch coverage and pre-launch leaks fill the blank and explain the silence. The full-spec N1X silicon inside RTX Spark is, by all accounts, the same configuration as the DGX Spark&#8217;s GB10: a 256-bit interface of LPDDR5X (laptop-class memory) delivering roughly 273 GB/s, with launch-day spec coverage citing up to 300.[8] Apple&#8217;s M4 Max delivers 546 GB/s. The M5 Max delivers 614. The M3 Ultra delivers 819.[9] On the dimension that determines how fast a local model actually runs, the machine Nvidia just announced trails the machines it was announced to displace by a factor of 2 to 3.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lrbJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lrbJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 424w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 848w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 1272w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lrbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png" width="1456" height="782" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:782,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157308,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201453469?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lrbJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 424w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 848w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 1272w, https://substackcdn.com/image/fetch/$s_!lrbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7e459dd-a954-41b7-99d1-3c368a17f5a0_1779x956.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>RTX Spark&#8217;s memory bandwidth &#8212; absent from its product page &#8212; sits in Apple M5 Pro territory, well below the Apple machines that hold 128GB.</em></figcaption></figure></div><p style="text-align: justify;">So the puzzle is real. Nvidia came back for local AI without closing the gap that lost it the market in the first place. Why would a company that just reported $215.9 billion in annual revenue enter a fight it has already measured itself losing on the merits?</p><p style="text-align: justify;">Because the fight isn&#8217;t on the merits. RTX Spark is not a bid for the PC market. It is the recapture of the one AI workload that was escaping Nvidia&#8217;s orbit, and the recapture runs on defaults, not on benchmarks. The machinery has four layers, and only one of them is silicon.</p><h2>Four layers of default</h2><p style="text-align: justify;"><strong>The first layer is the hardware itself</strong>, and the most important word on the product page is &#8220;natively.&#8221; Nvidia&#8217;s copy reads: &#8220;CUDA, the software that accelerates the world&#8217;s AI, runs natively on RTX Spark.&#8221;[10] Every prior path to large-model local AI on a thin-and-light Windows machine ran through someone else&#8217;s silicon and someone else&#8217;s runtime: Qualcomm&#8217;s NPU through ONNX, AMD&#8217;s iGPU through Vulkan, Apple&#8217;s unified memory through Metal. Each of those paths was hardware-agnostic by necessity, which is precisely what made local inference the first workload to slip Nvidia&#8217;s gravity. RTX Spark ends the necessity. For the first time, the premium Windows laptop tier ships with the same CUDA stack that runs the datacenter, and 128 gigabytes to feed it. </p><div class="pullquote"><p style="text-align: center;">The escape route and the orbit now share a machine.</p></div><p style="text-align: justify;"><strong>The second layer is the runtime</strong>, where the recapture stops being a hardware story. On RTX AI PCs, Nvidia&#8217;s NIM microservices run as containers in Windows Subsystem for Linux, with CUDA acceleration, and package models with everything needed to run them.[11] The quieter announcement is the one that matters: Microsoft&#8217;s Windows ML inference stack now automatically routes to Nvidia&#8217;s TensorRT for RTX whenever it detects RTX hardware.[12] Read that sentence again at the level of incentives. A Windows application developer who calls the operating system&#8217;s standard AI interface does not have to select an inference backend. The operating system selects it, and on this machine, the selection is CUDA. The developer didn&#8217;t choose Nvidia. Windows chose it for them. Jensen&#8217;s defense writes itself: developers begged for this. Local CUDA parity with the datacenter was among the loudest requests in Nvidia&#8217;s developer ecosystem, and the convenience is not an illusion. But convenience is how every default gets built. </p><div class="pullquote"><p style="text-align: center;">The trap and the gift are one and the same.</p></div><p style="text-align: justify;">That shift, from chosen dependency to ambient dependency, is the difference between the lock-in we described in &#8220;Open Source, Closed Orbit&#8221; and the lock-in being assembled now.[13] The original Black Hole worked on practitioners: researchers and engineers who chose CUDA because the tools were better, then found the exit priced in switching costs. The new layer works on people who never make a choice at all. The mainstream Windows developer building an AI feature in 2027 will write to Windows ML, ship to machines that route to TensorRT, and acquire a CUDA dependency the way one acquires an accent. Nobody decides to have one.</p><p style="text-align: justify;"><strong>The third layer is the agent platform</strong>, and it explains the timing. RTX Spark&#8217;s marketing mentions chatbots only briefly. The page promises a PC where &#8220;agents work alongside you &#8212; running tasks, generating assets, writing code, on demand,&#8221; and pitches the desktop variants as machines &#8220;built to run personal AI agents 24/7 right at your desk.&#8221;[14] The plumbing has a name: NVIDIA OpenShell, an agent framework coming to Windows on top of Microsoft&#8217;s new security primitives, packaging local autonomous agents with guardrails gating what they can touch &#8212; alongside NIM containers as local agent endpoints and native NIM support arriving in Azure AI Foundry in July.[15] The agent era re-platforms the PC around continuous local inference, the bandwidth-hungry, always-on workload pattern that decides hardware defaults for a decade. Whoever owns the default runtime when that re-platforming happens owns the next ten years of Windows AI development. </p><div class="pullquote"><p style="text-align: center;">The Windows re-platforming is being co-authored by Nvidia.</p></div><p style="text-align: justify;"><strong>The fourth layer is the funnel</strong>, and it is the oldest trick in the catalog. NIM&#8217;s developer tier is free and genuinely useful: unlimited endpoints for prototyping, hosted on DGX Cloud. Production is a different conversation. Nvidia&#8217;s own product page walks the path in two sentences: prototype freely, then &#8220;talk to an NVIDIA product specialist about moving from pilot to production with the security, API stability, and support that comes with NVIDIA AI Enterprise.&#8221;[16] The same NIM container that runs on the laptop runs in the datacenter and the cloud, which Nvidia presents as portability and which functions as a ratchet. A team prototypes an agent on a Spark laptop, the prototype works, and scaling it means an enterprise agreement that cross-sells the rest of the stack. </p><div class="pullquote"><p style="text-align: center;">It is the catalog-and-contract structure we have documented across eight Nvidia infrastructure domains.[13] The laptop makes it nine, and it sits at the top of the funnel, where developers form habits.</p></div><p style="text-align: justify;">Put the four layers together, and the design is legible. Nvidia fixed the capacity problem, kept the bandwidth problem, and wrapped both in the Windows default. It can concede the benchmark because it is buying the path. A 2x decode deficit against a Mac Studio matters to the practitioner who measures tokens per second. <strong>It matters not at all to the Windows developer whose operating system, container catalog, agent framework, and cloud funnel have already agreed on the answer before the question was asked.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GFP3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GFP3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 424w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 848w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 1272w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GFP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png" width="1456" height="1067" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1067,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:189490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201453469?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GFP3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 424w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 848w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 1272w, https://substackcdn.com/image/fetch/$s_!GFP3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5090c88-7b53-4fa3-be53-ba0ee04912ee_1733x1270.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>The four-layer recapture &#8212; hardware, runtime, agents, funnel &#8212; each level routing to the same stack. None of them is a benchmark.</em></figcaption></figure></div><p style="text-align: justify;">There is a precedent for this, and Jensen named it himself two months before the announcement. &#8220;GeForce is NVIDIA&#8217;s greatest marketing campaign,&#8221; he told the GTC crowd in March. &#8220;Your parents paid for you to be an NVIDIA customer... until someday you became an amazing computer scientist and became a proper customer.&#8221;[17] GeForce recruited the CUDA generation: gamers who became graduate students, who became the engineers who made CUDA the default in the datacenter. The pipeline aged. Gaming now accounts for 7% of Nvidia&#8217;s revenue, and the recruits were buying Macs.[18] Spark is that pipeline rebuilt for the agent era. The laptop is the new GeForce, except this time the product being marketed isn&#8217;t a graphics card a teenager will outgrow. It&#8217;s a default that a developer will never notice.</p><h2>What the machine actually does</h2><p style="text-align: justify;">Honesty about the product, because it&#8217;s good. RTX Spark&#8217;s compute is real: the full configuration matches the 6,144 CUDA cores of a desktop RTX 5070, and on the GB10 silicon it shares with the DGX Spark, prefill &#8212; the compute-bound phase where a long prompt is ingested &#8212; runs at roughly 2,000 tokens per second on a 20B model.[19] For workloads that are mostly ingestion (summarizing long documents, retrieval over a document base, batch classification), that is a serious machine in a laptop chassis. The 45-to-80-watt envelope, the all-day-battery claim, and the full RTX gaming stack make it the most credible Windows-on-Arm product ever shipped, where Qualcomm&#8217;s Snapdragon X struggled to give mainstream buyers a reason to switch.[20] And 128 gigabytes of addressable memory on a Windows laptop is a first. None of this is vaporware.</p><p style="text-align: justify;">The decode numbers are equally real, and they cut the other way. On the same GB10 silicon, LMSYS measured the DGX Spark generating just under 50 tokens per second on a 20B model at 4-bit precision &#8212; against 215 for an RTX Pro 6000 and 205 for an RTX 5090, a gap of roughly 4x that the reviewers attributed directly to the LPDDR5X memory interface.[19] Decode speed doesn't improve with the laptop&#8217;s power envelope because memory bandwidth doesn&#8217;t scale with wattage; the laptop will generate tokens at desktop-GB10 speed, which is to say at half to a third the speed of the Apple Silicon machines it shares a price bracket with.[21] </p><div class="pullquote"><p style="text-align: justify;">A reasoning model that thinks for ten thousand tokens before answering will make a Spark user wait three to four minutes per answer. The &#8220;agents running 24/7 at your desk&#8221; pitch quietly depends on the user not watching them work.</p></div><p style="text-align: justify;">A note on a number you will see misquoted. Nvidia&#8217;s specifications include a 600 GB/s figure, and parts of the trade press have already printed it as the memory bandwidth.[22] It isn&#8217;t. The 600 GB/s is NVLink-C2C, the interconnect between the CPU and GPU complexes on the package. The memory interface feeding both remains LPDDR5X at roughly 273 to 300 GB/s. Bandwidth between two processors and bandwidth to the memory that holds the model are different numbers, and conflating them doubles the product&#8217;s apparent throughput. The confusion is not an accident of complicated engineering. Retail listings may yet publish the figure; the DGX Spark precedent, where the number surfaced in technical documentation after launch, suggests the pattern is policy. A company that headlines its interconnect bandwidth and buries its memory bandwidth knows which comparison it would lose.</p><p style="text-align: justify;">So the honest scorecard reads: best-in-class prefill for the form factor, true 120B capacity, decode bandwidth in M5 Pro territory at M5 Max prices, and a marketing sheet built to keep you from computing that last number. Our April verdict &#8212; no amount of software makes 273 GB/s faster than hardware with three times the bandwidth &#8212; survives contact with the new product. <strong>What changed is that Nvidia stopped trying to win the comparison and started making sure the buyer never runs it.</strong></p><h2>The practitioners who walk away</h2><p style="text-align: justify;">The recapture has a boundary, and the boundary is choice. Everything in the four-layer machinery operates on defaults: the default premium laptop, the default OS inference path, the default agent runtime, the default scaling story. Nothing in it binds the practitioner who actively chooses a stack. llama.cpp still runs everywhere. Vulkan still outruns vendor stacks on AMD silicon.[4] Apple&#8217;s MLX is becoming the default backend of Ollama, the most popular local-model tool, with measured decode gains of 93% on supported models.[23] The buyer who reads benchmarks before purchasing will keep buying the machine with 614 GB/s, and <strong>nothing Nvidia shipped last week changes that calculus.</strong></p><p style="text-align: justify;">But count the populations. The benchmark-reading tier is a niche. The Windows installed base is more than a billion machines, refreshed through OEM defaults and corporate procurement cycles that have shipped &#8220;the premium Intel laptop&#8221; for thirty years and will ship &#8220;the premium RTX Spark laptop&#8221; with equal indifference to memory-bus arithmetic. <strong>Distribution decides defaults, and defaults decide ecosystems</strong>. Qualcomm proved that distribution alone doesn&#8217;t move an ecosystem: two years of Snapdragon X laptops put Arm Windows machines in every retail channel without giving developers a reason to target them. Nvidia inherits the compatibility groundwork Qualcomm paid for and arrives with the developer reason pre-installed: a machine carrying the stack the world&#8217;s AI is already written on, an OS that routes to it silently, and an agent platform whose launch partner is the OS vendor itself.</p><p style="text-align: justify;">The exception that proves the design: the people most likely to escape recapture are the people Nvidia&#8217;s original segmentation already pushed out. The medical practice that bought a Mac Studio in 2025 for private 70B inference has no reason to return; its stack is Metal, its tooling is MLX, and its data never left the building. Nvidia has written them off; the project is making sure the next ten million developers never become them.</p><h2>The ninth domain</h2><p style="text-align: justify;">Readers of this publication have seen this architecture before. &#8220;<a href="https://www.airealist.ai/p/open-source-closed-orbit">Open Source, Closed Orbit</a>&#8221; mapped how Nvidia replicated the open-source ecosystem&#8217;s eight critical infrastructure functions &#8212; model hosting, developer tooling, inference serving, fine-tuning, evaluation, and the rest &#8212; each replica routing back to Nvidia hardware.[13] The framework&#8217;s gap was geographic: the eight domains lived in the cloud, and the datacenter, and the device on the desk remained contested ground. That contest is what &#8220;<a href="https://www.airealist.ai/p/your-parents-paid">Your Parents Paid</a>&#8221; documented from the other side: at the device tier, where workloads run through llama.cpp and MLX rather than NIM and Triton, the pull was visibly loosening. Local inference wasn't escaping because someone built a better CUDA; it was because the workload didn&#8217;t need CUDA at all.[4]</p><p style="text-align: justify;">RTX Spark closes the map. The device is the ninth domain, and the replication strategy is identical to the first eight: take a function the open ecosystem performs in a hardware-agnostic way, ship a vertically integrated version that is easier than the agnostic one, and let convenience do what compulsion couldn&#8217;t. The two pieces are mirror images. April&#8217;s story was segmentation pushing the workload out: a 32-gigabyte ceiling, a missing NVLink, a bandwidth-starved Spark desktop, each a deliberate gap that protected datacenter margins. June&#8217;s story is integration pulling the workload back: full capacity, native CUDA, OS-level routing, and an agent platform. Opposite moves. Same gravity. In both directions, the constant is that Nvidia designs the consumer product around what it does to the datacenter business, because <strong>the datacenter is 90% of revenue, and the consumer device is, in Jensen&#8217;s own framing, a marketing campaign with a motherboard.</strong>[17][18]</p><h2>What would have to break</h2><p>The recapture thesis is falsifiable, and we&#8217;ll state the conditions plainly.</p><p style="text-align: justify;">First, it breaks if the default path opens up. If Windows ML&#8217;s hardware routing stays neutral in practice &#8212; if a developer writing to the standard Windows AI interface gets equivalent first-class treatment on Qualcomm NPUs and AMD silicon, and the TensorRT route confers no meaningful advantage &#8212; then the second layer of the machinery never engages, and RTX Spark is just a fast laptop. The incentive structure argues against this. Microsoft has reasons to keep Windows ML formally vendor-neutral; Nvidia has reasons to make the neutral interface perform best on its hardware; and &#8220;formally neutral, practically optimized&#8221; is how platform defaults in computing have historically worked. Watch the benchmark deltas between Windows ML on Spark and Windows ML on Snapdragon through 2027. If your AI feature had to run on a non-RTX machine tomorrow, would anything break? If you don&#8217;t know, the default has already been decided.</p><p style="text-align: justify;">Second, it breaks if the agnostic stack holds the mainstream, not just the practitioners. Ollama&#8217;s MLX migration, llama.cpp&#8217;s ubiquity, and an M5 Ultra refresh give Apple every chance to keep the enthusiast tier and grow it; the M5 Ultra skipped this week&#8217;s WWDC and is now expected around October on reported memory-supply constraints, which puts Nvidia&#8217;s fall launch and Apple&#8217;s 128GB-class answer in the same quarter.[24] If local AI on Windows stalls &#8212; if the agent-PC pitch lands as this decade&#8217;s 3D TV &#8212; then Nvidia will have built a beautiful funnel over a dry riverbed. The third condition is the prosaic one: adoption. Windows-on-Arm carries a decade of compatibility scar tissue, fall launches slip, Morgan Stanley&#8217;s channel checks put N1X machines at $2,899 and up, and premium-priced first-generation platforms have a long history of underselling their keynotes.[25] If OEM sell-through disappoints by the end of 2027, the ninth domain stays open.</p><p style="text-align: justify;">Here is why we doubt Nvidia loses even then. In September 2025, Nvidia agreed to buy $ 5 billion of Intel common stock, roughly 4% of the company whose RTX Spark franchise it is ostensibly built to attack; the purchase closed in December after antitrust clearance.[26] The equity is the smaller half of the deal. The same agreement commits Intel to build x86 system-on-chips for the PC market &#8220;that integrate NVIDIA RTX GPU chiplets&#8221; &#8212; Intel&#8217;s own filing language.[26] Read the two moves together. If Arm-based AI PCs win, Nvidia owns the chip. If x86 holds, the incumbent&#8217;s next-generation PC silicon will carry Nvidia&#8217;s GPU by contract. The instruction set is a coin flip Nvidia has hedged; the layer it refuses to share in either branch is the one this piece is about: the GPU, the runtime, and the default path between a Windows developer and a model. That hedge is the clearest evidence of the bet. Companies hedge the parts they consider interchangeable. They never hedge the moat.</p><p style="text-align: justify;">In April, we ended by noting that the local inference market was growing despite Nvidia&#8217;s product line, not because of it, and that the gravity of the Black Hole was measurably weakening at the device tier. Eight weeks later, Nvidia shipped the correction, which tells you how seriously it took the leak. <strong>It did not ship more bandwidth. It shipped a default.</strong></p><p>Local inference still doesn&#8217;t need CUDA. Nvidia just rebuilt the machine it runs on so that the path of least resistance does.</p><div><hr></div><h3>Notes</h3><p>[1] Jensen Huang, GTC Taipei keynote at Computex 2026, Taipei Music Center, May 31&#8211;June 1, 2026 (June 1 local time). &#8220;Reinvent the single most important tool of humanity&#8221; quoted by <a href="https://www.tomshardware.com/laptops/nvidia-unveils-rtx-spark-superchip-at-computex-2026-new-platform-promises-to-turn-windows-into-an-agentic-ai-os-with-arm-cpu-blackwell-gpu-and-128gb-unified-memory">Tom&#8217;s Hardware</a>.</p><p>[2] NVIDIA RTX Spark product page (<a href="https://www.nvidia.com/en-us/products/rtx-spark/">nvidia.com/en-us/products/rtx-spark</a>, accessed June 10, 2026): up to 6,144-core Blackwell RTX GPU, up to 20-core CPU, up to 1 petaflop FP4, up to 128GB unified memory. Laptop partners: Asus ProArt P16, Dell XPS 16, HP OmniBook X 14, Lenovo Yoga Pro 9n, Microsoft Surface Laptop Ultra, MSI Prestige N16 Flip AI+; desktop partners include Acer and Gigabyte. Announced May 31, 2026 with Microsoft (<a href="https://nvidianews.nvidia.com/news/nvidia-microsoft-windows-pcs-agents-rtx-spark">NVIDIA Newsroom</a>); availability fall 2026. CPU complex: 20 Arm cores (10x Cortex-X925 + 10x Cortex-A725), co-designed with MediaTek, per <a href="https://hothardware.com/news/nvidia-announces-rtx-spark-at-computex-2026">HotHardware</a>. Nvidia also showed a two-year cadence roadmap with successor chips in 2028 and 2030.</p><p>[3] AMD, Intel, and Qualcomm share declines on the announcement: <a href="https://www.cnbc.com/2026/06/02/nvidias-new-pc-chips-are-ceos-bid-to-own-every-part-of-ai-stack.html">CNBC</a>, June 2, 2026.</p><p>[4] &#8220;<a href="https://www.airealist.ai/p/your-parents-paid">Your Parents Paid</a>,&#8221; The AI Realist, April 3, 2026. The three reversal conditions appear in the closing section, &#8220;What would have to break.&#8221; Companion hardware guide: &#8220;<a href="https://www.airealist.ai/p/what-to-buy-for-local-llms-april">What to Buy for Local LLMs (April 2026)</a>.&#8221;</p><p>[5] 120-billion-parameter local model claim: Nvidia keynote and product materials, reported by <a href="https://www.notebookcheck.net/Nvidia-N1X-officially-confirmed-to-arrive-as-the-RTX-Spark.1312010.0.html">Notebookcheck</a>. At Q4-class quantization a 120B dense model requires roughly 60&#8211;70GB of memory; 120B-class MoE models fit comfortably in 128GB. Vendor claim; independent throughput benchmarks on shipping hardware not yet available.</p><p>[6] NVIDIA RTX Spark product page, accessed June 10, 2026. The specifications section lists GPU cores, CPU cores, FP4 throughput, and memory capacity. No memory bandwidth figure appears anywhere on the page.</p><p>[7] NVIDIA DGX Spark: 128GB LPDDR5x, 273 GB/s, documented in the <a href="https://docs.nvidia.com/dgx-spark/">DGX Spark User Guide</a> rather than launch marketing. See &#8220;Your Parents Paid,&#8221; note 18.</p><p>[8] N1X full-spec configuration matching DGX Spark&#8217;s GB10 (256-bit LPDDR5X-8533, ~273 GB/s): <a href="https://www.tomshardware.com/pc-components/cpus/nvidias-long-awaited-n1-n1x-soc-specs-leak-ahead-of-computex-launch-n1-to-feature-up-to-20-arm-based-cores-standard-n1-equipped-with-12-and-10-core-configs">Tom&#8217;s Hardware</a> pre-launch specification reporting. Tom&#8217;s Hardware&#8217;s <a href="https://www.tomshardware.com/laptops/nvidia-unveils-rtx-spark-superchip-at-computex-2026-new-platform-promises-to-turn-windows-into-an-agentic-ai-os-with-arm-cpu-blackwell-gpu-and-128gb-unified-memory">launch article</a> states &#8220;up to 300 GB/s of memory bandwidth&#8221; in its spec rundown, suggesting the ceiling figure was briefed to press; it appears nowhere on the product page (note 6). One analysis cites LPDDR5X-9400 (~301 GB/s). The GB10-lineage claim is consistent across sources but not officially confirmed.</p><p>[9] Apple memory bandwidth, manufacturer specifications: M4 Max 546 GB/s; M5 Max with 40-core GPU &#8212; the only configuration offering 128GB &#8212; 614 GB/s (the 32-core variant is 460 GB/s); M5 Pro 307 GB/s; M3 Ultra 819 GB/s (<a href="https://support.apple.com/en-us/126318">Apple tech specs</a>; <a href="https://www.apple.com/newsroom/2026/03/apple-debuts-m5-pro-and-m5-max-to-supercharge-the-most-demanding-pro-workflows/">Apple Newsroom, M5 Pro and M5 Max</a>). See &#8220;Your Parents Paid,&#8221; notes 32&#8211;34, for pricing at the 128GB tier.</p><p>[10] NVIDIA RTX Spark product page: &#8220;CUDA, the software that accelerates the world&#8217;s AI, runs natively on RTX Spark.&#8221; Developer section: &#8220;The same NVIDIA CUDA stack the world&#8217;s AI is built on, so you can develop and prototype on the same machine... prototype, fine-tune, and inference on the latest models locally.&#8221;</p><p>[11] NVIDIA NIM microservices on RTX AI PCs run through WSL2 with CUDA acceleration: <a href="https://developer.nvidia.com/blog/kickstart-your-ai-journey-on-rtx-ai-pcs-and-workstations-with-nvidia-nim-microservices/">NVIDIA Developer Blog</a>. That deployment path was established on x86 RTX PCs; Arm-native NIM containers are already in production on the DGX Spark, which runs the same GB10-lineage silicon as RTX Spark.</p><p>[12] Windows ML, powered by ONNX Runtime, automatically uses the TensorRT for RTX inference library on GeForce RTX GPUs: <a href="https://blogs.nvidia.com/blog/rtx-ai-garage-computex-microsoft-build/">NVIDIA blog, Microsoft Build coverage</a>. TensorRT for RTX is natively supported by Windows ML.</p><p>[13] &#8220;<a href="https://www.airealist.ai/">Open Source, Closed Orbit: The Hardware Monopolist&#8217;s Guide to Owning Open Source</a>,&#8221; The AI Realist. The eight-domain replication framework and the catalog-and-contract lock-in structure.</p><p>[14] NVIDIA RTX Spark product page: &#8220;Welcome to the PC where agents work alongside you &#8212; running tasks, generating assets, writing code, on demand... There&#8217;s intelligence on both sides of the keyboard now.&#8221; Desktop section: &#8220;Built to run personal AI agents 24/7 right at your desk.&#8221;</p><p>[15] &#8220;NVIDIA OpenShell is coming to Windows on top of Microsoft&#8217;s new security primitives, giving developers a single, easy-to-deploy package for running autonomous agents safely&#8221;: <a href="https://www.nvidia.com/en-us/geforce/news/computex-2026-nvidia-geforce-rtx-announcements/">NVIDIA, Computex 2026 announcements</a>, May 31, 2026; OpenShell appears in NVIDIA&#8217;s trademark list (<a href="https://nvidianews.nvidia.com/news/nvidia-microsoft-windows-pcs-agents-rtx-spark">NVIDIA Newsroom</a>). NIM containers as local agent endpoints and native NIM support in Azure AI Foundry from July 2026: Microsoft Build 2026 coverage (<a href="https://windowsnews.ai/article/nvidia-and-microsoft-turn-windows-into-an-ai-agent-powerhouse-with-rtx-spark-and-dgx-station-at-buil.422401">Windows News</a>); the Foundry date is per Build coverage, not yet confirmed in Microsoft primary documentation.</p><p>[16] NVIDIA NIM product page (<a href="https://www.nvidia.com/en-us/ai-data-science/products/nim-microservices/">nvidia.com</a>, accessed June 10, 2026): &#8220;Get unlimited access to NIM API endpoints for prototyping, accelerated by DGX Cloud. When ready for production, download and self-host NIM on your preferred infrastructure... Talk to an NVIDIA product specialist about moving from pilot to production with the security, API stability, and support that comes with NVIDIA AI Enterprise.&#8221;</p><p>[17] Jensen Huang, GTC 2026 keynote, March 16, 2026: &#8220;GeForce is NVIDIA&#8217;s greatest marketing campaign... Your parents paid for you to be NVIDIA customers.&#8221; Full quote and sourcing in &#8220;Your Parents Paid,&#8221; note 1.</p><p>[18] NVIDIA Q4 FY2026 earnings (Form 8-K, filed February 25, 2026, <a href="https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&amp;CIK=1045810&amp;type=8-K">SEC EDGAR</a>): fiscal 2026 revenue $215.9B, of which Data Center $197.3B (91%) and Gaming $16.0B (7%).</p><p>[19] LMSYS, &#8220;NVIDIA DGX Spark In-Depth Review,&#8221; October 2025: GPT-OSS 20B (MXFP4) in Ollama at 2,053 tok/s prefill and 49.7 tok/s decode on DGX Spark, versus 10,108/215 on RTX Pro 6000 and 8,519/205 on RTX 5090. The reviewers attribute the decode gap to the unified LPDDR5x memory interface. Figures are for the GB10 desktop; RTX Spark shares the silicon per note 8 but laptop-specific benchmarks are not yet published.</p><p>[20] Power envelope 45&#8211;80W and integrated-GPU-only positioning (no discrete pairing planned): Engadget and Tom&#8217;s Hardware launch coverage. Qualcomm Windows-on-Arm context: Microsoft&#8217;s Windows-on-Arm exclusivity with Qualcomm expired in 2024, as Qualcomm executives publicly confirmed, opening the door to this product.</p><p>[21] Decode speed invariance with TDP: token generation is memory-bandwidth-bound, and LPDDR5X bandwidth does not change with the power envelope. Prefill, which is compute-bound, takes a 15&#8211;25% reduction at laptop wattage per independent analysis. Community analysis; consistent with the bandwidth-bound decode model established in &#8220;Your Parents Paid,&#8221; notes 18 and 36.</p><p>[22] 600 GB/s NVLink-C2C (CPU-to-GPU interconnect) listed by Nvidia and reported by <a href="https://videocardz.com/newz/nvidia-rtx-spark-laptops-may-start-above-1799-n1x-systems-reportedly-above-2899">VideoCardz</a>; misreported as peak memory bandwidth by at least one major outlet (<a href="https://www.notebookcheck.net/Nvidia-N1X-officially-confirmed-to-arrive-as-the-RTX-Spark.1312010.0.html">Notebookcheck</a>: &#8220;With NVLink, its memory bandwidth peaks at 600 GB/s&#8221;).</p><p>[23] Ollama&#8217;s transition of its Apple Silicon backend from llama.cpp to MLX, with preview decode improvements of 93% on supported models: <a href="https://ollama.com/blog/mlx">ollama.com/blog/mlx</a>, March 2026. Methodological caveats in &#8220;Your Parents Paid,&#8221; note 38.</p><p>[24] Apple&#8217;s M5 Ultra Mac Studio, widely anticipated at WWDC (keynote June 8, 2026), did not appear; reporting attributes the slip to RAM supply constraints, with October 2026 viewed as the likely window (<a href="https://www.macworld.com/article/2973459/2026-mac-studio-m5-release-date-specs-price-rumors.html">Macworld</a>, June 8, 2026). Nvidia, for its part, says it does not expect RTX Spark laptop supply to be limited despite the same global memory shortage (<a href="https://finance.yahoo.com/news/nvidia-debuts-rtx-spark-processor-for-windows-laptops-taking-aim-at-intel-amd-053000567.html">Yahoo Finance</a>; vendor claim). The rumored M5 Ultra retains the UltraFusion dual-die design, two M5 Max dies with interconnect bandwidth above 1,000 GB/s (<a href="https://www.trendforce.com/news/2026/06/08/news-apple-may-debut-m5-ultra-powered-mac-studio-at-wwdc-boosting-demand-for-tsmc-n3p-and-soic-mh/">TrendForce</a>, citing Commercial Times) &#8212; rumored, not announced.</p><p>[25] Pricing per a Morgan Stanley report based on channel checks with PC brands at Computex: &#8220;AI PCs with N1X will need to price at US$2,899, while N1 models will be priced at US$1,799&#8221; (<a href="https://wccftech.com/laptops-and-pcs-powered-by-nvidia-rtx-spark-n1x-variant-cant-be-priced-below-2900/">Wccftech</a>; <a href="https://videocardz.com/newz/nvidia-rtx-spark-laptops-may-start-above-1799-n1x-systems-reportedly-above-2899">VideoCardz</a>, June 2&#8211;3, 2026). Nvidia has not published pricing. Microsoft confirmed a fall release for the Surface Laptop Ultra while declining to discuss pricing (<a href="https://www.pcworld.com/article/3156219/the-price-of-nvidia-rtx-spark-pcs-is-going-to-hurt.html">PCWorld</a>, Build 2026).</p><p>[26] Securities Purchase Agreement dated September 15, 2025; announced September 18: NVIDIA purchased 214,776,632 Intel shares at $23.28, a $5.0 billion aggregate price (<a href="https://www.sec.gov/Archives/edgar/data/0000050863/000005086325000155/intc-20250915.htm">Intel Form 8-K, September 2025</a>). The FTC, which had examined whether the roughly 4% stake raised antitrust concerns, cleared the deal December 18, 2025; the purchase closed December 26 (<a href="https://www.theregister.com/2025/12/29/nvidia_intel_5_billion/">The Register</a>; <a href="https://www.cnbc.com/2025/12/29/nvidia-takes-5-billion-stake-in-intel-under-september-agreement.html">CNBC</a>). The product commitment is in the same announcement: &#8220;For personal computing, Intel will build and offer to the market x86 system-on-chips (SOCs) that integrate NVIDIA RTX GPU chiplets&#8221; (<a href="https://www.sec.gov/Archives/edgar/data/0000050863/000005086325000155/a09152025form8-kex991.htm">Intel 8-K Exhibit 99.1</a>). No ship dates for products under the agreement have been announced.</p>]]></content:encoded></item><item><title><![CDATA[Macron Said Confirmed. SoftBank Said Up To.]]></title><description><![CDATA[The &#8364;93 billion headline is mostly one company's pledge. The pledge is mostly a ceiling. The balance sheet beneath it is the most concentrated in AI.]]></description><link>https://www.airealist.ai/p/macron-said-confirmed-softbank-said</link><guid isPermaLink="false">https://www.airealist.ai/p/macron-said-confirmed-softbank-said</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Tue, 09 Jun 2026 13:49:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hmyt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hmyt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hmyt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hmyt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2446532,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201298263?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hmyt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!hmyt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdc34a9a-592a-43f2-a834-8857ce76a487_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p style="text-align: justify;"><em><strong>Update: 10 June 2026.</strong> Nine days after the summit, the strain is already visible. The margin loan SoftBank wanted against its OpenAI stake has stalled: cut from $10 billion to $6 billion on lender hesitation, then stuck at roughly $5 billion. A loan against the marquee asset is supposed to be the easy money. All of it confirms what the headline number was hiding. Read on.</em></p></blockquote><p style="text-align: justify;">On the morning of June 1, 2026, in the gilded halls of Versailles, Emmanuel Macron told the assembled chief executives that this year&#8217;s Choose France summit would &#8220;crystallize a record amount of 93 billion euros of confirmed investments.&#8221;[1] The word that mattered was <em>confirmed</em> &#8212; <em>confirm&#233;s</em>. It is the word that turns a press release into a balance sheet, an intention into a number a finance minister can book.</p><p style="text-align: justify;">Strip the SoftBank pledge out of the total, and the record disappears. The Japanese conglomerate&#8217;s commitment &#8212; up to &#8364;75 billion to build five gigawatts of AI data-center capacity across France &#8212; would be four-fifths of the headline on its own; even the firm tranche France&#8217;s own press counted into the total, &#8364;45 billion, is roughly half of it.[2] It is also the reason the number is a record at all: this single edition of Choose France exceeded the <em>announced</em> investment promises of the eight previous summits combined, which together totaled around &#8364;87 billion.[3] One pledge, from one company, made one summit larger than eight.</p><p style="text-align: justify;">And that pledge is not &#8364;75 billion of confirmed money. By SoftBank&#8217;s own announcement, issued the day before the summit, only the first phase &#8212; &#8364;45 billion to deliver 3.1 gigawatts &#8212; is a commitment. The remaining &#8364;30 billion describes &#8220;additional sites&#8221; the company plans to develop.[4] The language shift inside a single press release, from &#8220;commitment&#8221; and &#8220;investment&#8221; to &#8220;plans,&#8221; is the whole story compressed into one document.</p><p style="text-align: justify;">The last time Masayoshi Son stood beside a head of state and named a number this large, it was $500 billion. Sixteen months later, a fraction of one of its seven sites was running.</p><h2>The anatomy of a record</h2><p style="text-align: justify;">A Choose France headline is not a measurement. It is a sum of commitment tiers, each with a different probability of becoming a building, presented to the cameras as a single figure. Disaggregate the &#8364;93 billion and five tiers separate cleanly: one firm, one a ceiling, one smaller but real, one barely more than a letter of intent, and one recycled from a previous summit.</p><p style="text-align: justify;">At the firm end sits SoftBank&#8217;s &#8364;45 billion first phase &#8212; named sites, a named industrial partner in Schneider Electric, a developer in SB Energy, and a 2031 horizon.[5] This is the most concrete pledge at the summit, and it deserves to be treated as a real intent. Below it sits the &#8364;30 billion remainder of the SoftBank ceiling, which exists only as &#8220;plans for additional sites.&#8221; Below that sits a layer of genuine but smaller data-center commitments: Brookfield&#8217;s pledge, Nebius&#8217;s &#8364;8 billion site on a former Bridgestone plant at B&#233;thune, an Ardian-Verne campus in the Paris region.[6] And below <em>that</em> sits the softest tier &#8212; capacity that is announced but not yet sited or committed: the MGX&#8211;Bpifrance &#8220;imminent selection of a second site,&#8221; worth around &#8364;7.5 billion, and a Revolut commitment contingent on the fintech obtaining a French banking license.[7][8]</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QvC0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QvC0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 424w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 848w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 1272w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QvC0!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png" width="1200" height="491.2087912087912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:596,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:163209,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/201298263?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QvC0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 424w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 848w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 1272w, https://substackcdn.com/image/fetch/$s_!QvC0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f3a33c-ebd3-4bda-8ff3-59b61cd0936c_1947x797.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">The recycling is not a footnote to this structure; it is part of how the record was assembled. Brookfield&#8217;s France AI total is now quoted at &#8364;30 billion &#8212; but &#8364;20 billion of that was announced at the February 2025 AI Action Summit, the same event that produced the &#8364;109 billion headline; only &#8364;10 billion is new to this summit.[6] The MGX&#8211;Bpifrance money is the expansion of Campus AI, the Bpifrance&#8211;Mistral&#8211;MGX&#8211;Nvidia joint venture first unveiled at Choose France 2025, whose flagship campus at Fouju is still in early construction.[7] The &#8364;7.5 billion &#8220;doubles&#8221; a commitment that was itself last year&#8217;s announcement. Macron&#8217;s own framing conceded the pattern: the summit, he said, represented &#8220;20 billion invested, and 20 billion of AI investments as a follow-up to the summit in February.&#8221;[9] That February summit &#8212; the &#8364;109 billion AI Action Summit whose figure France never reconciled to disbursement &#8212; is being folded back into June&#8217;s total as &#8220;follow-up.&#8221;[10] A material share of this year&#8217;s record is last year&#8217;s record, counted again.</p><p style="text-align: justify;">This is the Commitment-versus-Spend Gap, the analytical move that separates an announced figure from the capital that actually moves. Summit pledges do convert &#8212; France has led European foreign direct investment for years running, and Choose France is not a fiction. But they convert at a rate and with a lag that the headline never discloses, and the disaggregation above is why the headline and the eventual deployment are different numbers. At hyperscaler and sovereign-summit scale, the gap is not an anomaly to be explained away; it is the default structure of the announcement. The headline is the ceiling of what could happen. The filing, eventually, shows the floor of what did. The distance between them is where the analysis lives &#8212; and at Versailles, the distance is most of the number.</p><div class="callout-block" data-callout="true"><p>This raises the real question. Why would the most active investor in artificial intelligence structure its largest-ever European commitment as an option it might never fully exercise? The answer is on its balance sheet.</p></div><h2>What the same pledge looks like sixteen months later</h2><p style="text-align: justify;">To price a SoftBank infrastructure pledge at the moment of announcement, you do not need a forecast. You need the last one.</p><p style="text-align: justify;">On January 21, 2025, Son stood in the White House alongside Donald Trump, Sam Altman, and Larry Ellison to announce Stargate: $500 billion over four years to build AI data centers across the United States, with $100 billion to be deployed &#8220;immediately.&#8221;[11] SoftBank took financial responsibility, and Son took the chairmanship. The structure was familiar to anyone who had watched Son work: of the $500 billion, only around $52 billion was committed equity &#8212; roughly $19 billion each from SoftBank and OpenAI, around $7 billion each from Oracle and MGX. The other ninety percent was to come from debt and vendor financing, not yet arranged.[12] A mega-pledge, in the Son method, does not deploy existing capital. It opens a financing campaign.</p><p style="text-align: justify;">Sixteen months on, the campaign&#8217;s results are measurable. Independent satellite analysis put the flagship Abilene, Texas campus at roughly 0.3 to 0.6 gigawatts operational by April 2026 &#8212; four of its eight buildings live &#8212; against a site target of 1.2 gigawatts and an announced program of ten.[13] The other six US sites were foundations and steel on 2028 timelines. One site of seven was partially energized; the rest were under construction.</p><p style="text-align: justify;">Some of that gap is just physics: gigawatt data centers take three to five years to build, and measuring a ten-year program at month sixteen will always show a low number. Abilene, taken alone, is arguably ahead of a normal curve. So the conversion rate, in itself, is not the indictment. The indictment is what happened around it.</p><p style="text-align: justify;">The vehicle itself barely functioned. By early 2026, Stargate LLC &#8212; the entity unveiled with such ceremony &#8212; had reportedly hired no staff and was developing no data centers; OpenAI had bypassed it for bilateral deals with Oracle, Amazon, and Google, and had come to treat the word &#8220;Stargate&#8221; as, in one executive&#8217;s framing, an umbrella term for its compute strategy rather than a company.[14] The Abilene flagship&#8217;s planned expansion was canceled in March 2026; the UK Stargate site was paused in April due to energy costs.[15]</p><p style="text-align: justify;">None of this means that nothing was built. This is the point at which the skeptical version of the story has to be disciplined, because the booster version is partly true. Abilene is a genuine, operational AI campus running Nvidia hardware; thousands of tradespeople built it; major lenders &#8212; JPMorgan, a Newmark-led syndicate &#8212; genuinely closed billions in project finance against it.[16] The accurate claim is not that the money was fake. It is that conversion was slow, partial, debt-heavy, and routed around the very vehicle that gave the announcement its name. </p><div class="callout-block" data-callout="true"><p style="text-align: justify;">The $500 billion functioned as a frame. The deployed reality was a fraction of it, arriving years behind the rhetoric. That is the precedent now anchoring a French summit&#8217;s record.</p></div><h2>The balance sheet behind the pledge</h2><p style="text-align: justify;">The deeper reason to discount the &#8364;75 billion is not SoftBank&#8217;s track record. It is SoftBank&#8217;s balance sheet, and specifically the distinction between the money SoftBank actually moves and the money it lends its name to.</p><p style="text-align: justify;">SoftBank&#8217;s funded AI capital has gone almost entirely into one place: its equity position in OpenAI. It completed a $41 billion round in December 2025 for roughly an 11 percent stake, then in February 2026 agreed a further $30 billion that would bring the cumulative total to $64.6 billion and the stake to about 13 percent &#8212; a figure that is reached only when the follow-on completes, in tranches running to October 2026.[17] To fund it, SoftBank sold its entire Nvidia stake, shed T-Mobile shares, and drew on a $40 billion bridge facility, the first $10 billion of it borrowed in April 2026, with the facility&#8217;s fee structure deliberately escalating to punish slow repayment.[18]</p><p style="text-align: justify;">By early 2026, the position had consequences a rating agency could not ignore. S&amp;P revised SoftBank&#8217;s outlook to negative in March, affirming a BB+ rating already below investment grade and describing OpenAI as one of the group&#8217;s investments &#8220;with the weakest credit quality&#8221; &#8212; even as Moody&#8217;s held a stable view a notch lower, the disagreement itself is a measure of how contested the bet is.[19] Reported leverage was still inside SoftBank&#8217;s own 25 percent loan-to-value ceiling at the end of 2025, but the chief financial officer had publicly opened the door to exceeding it &#8220;temporarily,&#8221; and S&amp;P warned the OpenAI follow-on could push leverage toward the 35 percent line that would trigger a downgrade. The shares fell roughly 45 percent from their October 2025 high; one bank labeled the company a &#8220;valuation trap&#8221;; and SoftBank paused a separate $50 billion acquisition to preserve capacity.[20]</p><p style="text-align: justify;">The bull would correctly object that this is only the liability side. SoftBank also holds one of the most valuable single assets in technology &#8212; roughly 90 percent of Arm, a stake worth more than $150 billion at mid-2026 prices &#8212; plus some $45 billion in unrealized gains on the OpenAI position itself, and it has shown it can monetize on demand, having sold Nvidia and T-Mobile to raise cash. That is real, and it is the strongest case for SoftBank&#8217;s resilience. But it cuts toward the concentration problem, not away from it: by mid-2026, the Arm and OpenAI stakes together made up nearly two-thirds of SoftBank&#8217;s assets, and the Arm holding is already pledged &#8212; an $8.5 billion margin loan drawn against it, with room for more. The crown jewel is collateral. And the credit market noticed: SoftBank&#8217;s five-year credit-default swaps widened to an eleven-month high after the S&amp;P action, the widest among major Japanese corporates &#8212; the cost of insuring its debt rising in step with the bet.[20]</p><p style="text-align: justify;">There is a circularity worth naming. SoftBank is OpenAI&#8217;s largest outside backer and, through SB Energy, a builder of the data centers OpenAI will rent. In France, it would play both roles again: financing the anchor tenant and constructing the capacity that the tenant is expected to fill. </p><div class="callout-block" data-callout="true"><p style="text-align: justify;">This is the round-trip structure that has become the default at the top of the AI market &#8212; the same shape as Oracle and OpenAI, as Nvidia and CoreWeave &#8212; where the investor, the builder, and the customer are versions of the same few balance sheets passing capacity back and forth among themselves. It works while the music plays. It concentrates the risk when it stops.</p></div><p style="text-align: justify;">Here is what that balance sheet did <em>not</em> do: fund Stargate LLC. The roughly $19 billion equity tranche SoftBank pledged to the vehicle has no confirmation of ever having been wired, because the vehicle was bypassed.[21] The chief financial officer&#8217;s own description of the model is the tell: SoftBank makes an equity investment, but the project itself is &#8220;financed as project finance,&#8221; so its own commitment is &#8220;limited&#8221; and &#8220;should not be too huge.&#8221;[22] Stripped of the jargon: SoftBank lends its name and a sliver of equity, and someone else&#8217;s debt builds the thing. The capital that flowed to an actual Stargate site was a $500 million check into SB Energy for the Milam County build. The headline was $500 billion; SoftBank&#8217;s verified site-level equity was three orders of magnitude smaller.</p><p style="text-align: justify;">This reframes what the French &#8364;45 billion actually is. It is not a promise that SoftBank will place &#8364;45 billion on its own books. It is a promise that SoftBank will supply catalytic equity and arrange project financing that does not yet exist &#8212; Son said as much at the podium, describing the venture as one SoftBank is &#8220;aggregating project financing&#8221; to fund, against demand from an anchor tenant not yet named, on a balance sheet already carrying the most concentrated single-name bet in the AI buildout.[22] The pledge&#8217;s deliverability is downstream of a financing structure that has to be assembled and of an OpenAI liquidity event &#8212; an IPO &#8212; that has to occur before the bridge facility is repaid. France controls none of those variables.</p><p style="text-align: justify;">And here, the two halves of the story close together. Staged commitments and project finance are, on their own, unremarkable &#8212; every large data-center developer rings capex into phases and funds it with non-recourse debt, because that is cheaper than equity and isolates the risk. The question is never whether a pledge is staged; it is what the staging rests on. SoftBank will not put &#8364;75 billion of its own balance sheet behind this &#8212; the balance sheet just described could not absorb it on top of the OpenAI commitment &#8212; so it writes a &#8364;75 billion <em>option</em> instead: a headline ceiling, a smaller firm tranche, and project finance to be arranged later. What changes with leverage is not the structure but the margin for error within it. A cash-rich sponsor that stages a pledge can absorb a slipped tranche or a delayed financing; a sponsor whose crown jewel is already collateral, whose follow-on runs to October, and whose bridge presumes an IPO cannot. </p><div class="callout-block" data-callout="true"><p style="text-align: justify;">The option produces the headline; the headline produces the political record; the record is what the summit needed. </p></div><p style="text-align: justify;">The more strained the balance sheet, the larger and softer the number it can afford to announce, because softness is free and the announcement is the deliverable. To be precise about where the softness enters: not, mostly, with SoftBank. Its press release was scrupulous &#8212; &#8220;up to&#8221; &#8364;75 billion, a firm &#8220;&#8364;45 billion,&#8221; the rest explicitly &#8220;plans.&#8221; The recharacterization happened at the podium, when a phased pledge with one firm tranche became, in Macron&#8217;s telling, &#8364;93 billion &#8220;confirmed.&#8221; SoftBank disclosed an option. The summit booked it as cash.</p><h2>What France actually brings, and what it doesn&#8217;t</h2><p style="text-align: justify;">The honest counterargument is that France is not Texas, and the difference favors the pledge. This deserves a fair hearing, because it is the strongest case for taking the &#8364;45 billion at close to face value.</p><p style="text-align: justify;">France&#8217;s advantages are real and, unlike capital, not exportable. The grid is roughly 70 percent nuclear, France is, in most years, the world&#8217;s largest net electricity exporter, and industrial power prices sit well below those in much of Europe, with EDF long-term pricing around &#8364;70 per megawatt-hour from 2026.[23] For a buildout whose binding constraint is increasingly power rather than capital, that is a genuine structural edge, and it is why the first-phase sites cluster in Hauts-de-France near existing grid and nuclear infrastructure, including a former coal site at Bouchain where EDF is the named development partner.[24] It also matters that the prior SoftBank pledges failed precisely on the variable that France has solved: the Saudi solar plan had no offtaker, and the UK Stargate site was paused due to energy costs. France removes the constraint that killed those. If any SoftBank data-center pledge converts close to schedule, the case for this one is better than most &#8212; and that concession should be granted in full.</p><p style="text-align: justify;">But cheap power is necessary, not sufficient, and it is not the variable that has stalled the buildout this year. What stalled Stargate was not the price of electricity; it was demand discipline and financing &#8212; a canceled expansion, a paused site, a vehicle that never funded. France solves the kilowatt-hour. It does not supply the anchor tenant, the assembled debt, or the balance-sheet capacity, and those are the three things the precedent says actually bind. Power is the one layer of the stack that France owns, and it is the bottom layer. Above the kilowatt-hour, the French buildout is foreign at every tier. The capital is Japanese. The chips are American &#8212; Nvidia silicon, subject to American export jurisdiction. The most likely offtaker of five gigawatts of French inference and training capacity is American, because the anchor tenant SoftBank builds for is OpenAI, and no European anchor of remotely comparable demand has been named.[25] </p><div class="callout-block" data-callout="true"><p style="text-align: justify;">France is not building sovereign AI capacity. It is providing the land and the electricity for someone else&#8217;s intelligence layer, and calling the result French because the substations are.</p></div><p>Macron said the summit would make France &#8220;the leading country hosting data centers and computing capacity in Europe,&#8221; and that the country was &#8220;closing the gap we had in computing capacity.&#8221;[26] Both claims may even come true. But hosting capacity and owning intelligence are different sovereignties, and the gap that closes is the one measured in megawatts, not models. This is the substrate-state position, normally diagnosed in Southeast Asian economies that host hyperscaler data centers without owning any layer of the intelligence that runs on them. It is striking to find a G7 economy with a world-class research base occupying the same structural slot &#8212; providing the physical inputs and importing everything above it. The fair counter is that substrate can be a first rung rather than a ceiling: Taiwan and South Korea became chip powers partly by first hosting foreign firms&#8217; manufacturing, and a country cannot build the intelligence layer on capacity it never built. Hosting compute you don&#8217;t yet own can be a deliberate developmental bet. But the bet only pays off if value accrues locally over time &#8212; if the substrate becomes a ladder. </p><p>The SoftBank pledge is built the other way: a foreign sponsor, foreign chips, and a most-likely-foreign tenant, with no disclosed mechanism for the intelligence layer to be handed over to French hands. It is a substrate as a destination, not a substrate as a rung.</p><p>There are two genuine exceptions inside the broader French buildout, and honesty requires naming both &#8212; because they sharpen the point rather than soften it. The first is Campus AI, the joint venture whose expansion supplied the &#8364;7.5 billion tier; its French AI champion, Mistral, secured up to 200 megawatts of capacity there, announced the same day as the summit.[7] But Mistral&#8217;s role in Campus AI is principally that of shareholder and board member; the project&#8217;s own coordinator described the startup as a &#8220;preferred&#8221; future client while conceding that, for now, &#8220;nothing has yet been done&#8221; on a binding tenancy.[7] Campus AI&#8217;s own president framed the stakes in terms that could serve as this article&#8217;s thesis: the test, he said, is that &#8220;every gigawatt must grow value in France, and not simply pass through it.&#8221;[7] The second exception, and the more real one, is Mistral&#8217;s own data center at Bruy&#232;res-le-Ch&#226;tel &#8212; its first debt-financed build, totaling $830 million for roughly 13,800 Nvidia chips and about 44 megawatts of capacity.[27] That is the genuine article: a French company owning its own compute.</p><p>And its scale is the whole argument in one number. Forty-four megawatts of sovereign French compute, against SoftBank&#8217;s 3,100-megawatt first phase. The champion&#8217;s owned infrastructure is roughly 1% of the substrate that the country provides for someone else&#8217;s use. For the marquee number &#8212; five gigawatts &#8212; there is no French anchor. The grid is the moat, and nearly everything it powers belongs to someone else. And even the grid advantage is contingent on RTE, the French grid operator, actually delivering 3.1 gigawatts of new connection capacity to three specific sites by 2031 &#8212; an unprecedented load addition on a timeline that grid-connection history does not obviously support, and that no signed connection agreement has yet confirmed.[28]</p><h2>What would have to be true</h2><p>The thesis is falsifiable, and it is worth stating the conditions plainly, because they are also the things a serious investor should watch. And there is someone who should watch. An option-shaped pledge harms no one if everyone prices it as an option &#8212; but it is not being priced that way. It is being booked as a record by a government building industrial-policy narrative on it, cited by analysts pricing &#8220;France is Europe&#8217;s AI hub&#8221; into datacenter REITs and French-exposure allocations, and folded into the case for a SoftBank credit that already trades below investment grade. The reader who needs the disaggregation is the one about to treat &#8364;93 billion of intention as &#8364;93 billion of capital.</p><p>The skeptical reading is wrong if, within roughly twelve months, SoftBank secures binding project financing &#8212; not a memorandum &#8212; for at least the Dunkirk site; if a named anchor tenant or binding offtake agreement appears; if an executed lease replaces &#8220;preferred bidder&#8221; status at Bouchain; and if the OpenAI IPO closes cleanly enough to let SoftBank refinance the March 2027 bridge without forced asset sales. If those happen, the &#8364;45 billion converts, and the substrate-state critique becomes a quibble about who owns the value rather than whether the buildings exist.</p><p>The thesis is confirmed if the tells repeat: financing perpetually &#8220;being assembled,&#8221; capacity that &#8220;can scale to&#8221; rather than &#8220;will reach,&#8221; a first-operations date that slips past 2028, no anchor tenant disclosed by 2027, a further S&amp;P action, or the same &#8220;pause&#8221; language that appeared over the UK site in April. </p><div class="callout-block" data-callout="true"><p>On sixteen years of SoftBank precedent &#8212; from the 2016 Trump Tower pledge that resolved substantially into the WeWork loss, to the 2018 Saudi solar plan shelved within six months of its announcement, to Stargate at one energized site of seven &#8212; the base case is not fabrication. It is conversion that runs well below the headline and well behind the clock.[29]</p></div><p>Which is the precise thing the word <em>confirm&#233;s</em> was chosen to obscure. Macron did not announce &#8364;93 billion of investment. He announced &#8364;93 billion of intention, of which the largest single component is a ceiling, two-fifths of that ceiling is merely a plan, and the firm remainder rests on a balance sheet betting its credit rating on a single American startup&#8217;s path to an IPO. The number is not false. It is an option &#8212; priced, and presented, as a certainty.</p><div><hr></div><h3>Notes</h3><p>[1]: Emmanuel Macron, remarks at the Choose France summit, Versailles, June 1, 2026: &#8220;Cette &#233;dition de Choose France &#224; elle seule va permettre de cristalliser un montant record de 93 milliards d&#8217;euros d&#8217;investissements confirm&#233;s.&#8221; Reported by <a href="https://www.franceinfo.fr/economie/en-ouverture-du-sommet-choose-france-emmanuel-macron-annonce-93-milliards-d-euros-d-investissements-et-la-creation-de-plus-15-000-emplois_8039180.html">franceinfo, June 1, 2026</a>; quote also carried verbatim by <a href="https://fr.euronews.com/next/2026/06/01/9-sommet-choose-france-emmanuel-macron-annonce-93-milliards-deuros-dinvestissements">Euronews FR</a>. The &#8364;93 billion figure spans 71 projects and a French-government-stated ~15,600 jobs; it is an announcer-claimed forward figure, not an audited outcome.</p><p>[2]: SoftBank Group Corp., <a href="https://group.softbank/en/news/press/20260531_0">&#8220;SoftBank Group to Build 5 GW of AI Data Center Capacity in France,&#8221; press release, May 30, 2026</a>. The &#8364;75 billion figure is stated as &#8220;up to.&#8221;</p><p>[3]: franceinfo, June 1, 2026, reporting that the single 2026 edition exceeded the cumulative announced totals of the prior eight Choose France editions (~&#8364;87 billion combined). Prior editions per &#201;lys&#233;e/Business France press dossiers (<a href="https://www.diplomatie.gouv.fr/IMG/pdf/dp_choose_france_2023_vf_006__cle812e96.pdf">2023 dossier, diplomatie.gouv.fr</a>): 2023 ~&#8364;13B; 2024 ~&#8364;15B; 2025 stated variously as ~&#8364;20B (Macron, 2026 framing) and &#8364;40.8B (2025 press dossier) &#8212; the moving baseline is noted as itself indicative of headline elasticity.</p><p>[4]: <a href="https://group.softbank/en/news/press/20260531_0">SoftBank press release, May 30, 2026</a>: the first phase is described as &#8220;an initial &#8364;45 billion investment to deliver 3.1 GW&#8221;; subsequent capacity is described as the company &#8220;also plans to develop additional sites across France.&#8221; The shift in verb from &#8220;investment/commitment&#8221; to &#8220;plans&#8221; is within the same document.</p><p>[5]: <a href="https://group.softbank/en/news/press/20260531_0">SoftBank press release, May 30, 2026</a>. Named first-phase sites: Dunkirk (Loon-Plage), Bosquel, and Bouchain, all in Hauts-de-France; Schneider Electric named as strategic partner (robotized manufacturing at Dunkirk); SB Energy as developer; first operations targeted 2028, full phase by 2031. Per a separate SoftBank announcement (reported by TechRepublic, June 2026), the Bosquel ~1 GW site is structured as a majority-SoftBank joint venture with Sesterce &#8212; i.e. even within the &#8220;firm&#8221; first phase, the capital structure is partly third-party, not pure SoftBank balance sheet.</p><p>[6]: Smaller data-center tier, per Choose France 2026 reporting (<a href="https://www.lemondeinformatique.fr/actualites/lire-choose-france-plusieurs-milliards-d-euros-pour-les-infrastructures-ia-100317.html">Le Monde Informatique</a>, Le Journal des Entreprises, Silicon.fr, June 1, 2026): Brookfield &#8364;10B at Escaudain (Nord), with Data4, for a ~1 GW datacenter, bringing its stated France AI total to &#8364;30B &#8212; of which &#8364;20B was announced at the February 2025 AI Action Summit (<a href="https://bam.brookfield.com/press-releases/brookfield-invest-eu20-billion-frances-ai-infrastructure">Brookfield press release, Feb 10, 2025</a>: &#8364;15B via Data4 + &#8364;5B associated infrastructure, delivery by 2030), so only &#8364;10B is new to the 2026 summit. Nebius ~&#8364;8B / 240 MW on the former Bridgestone site at B&#233;thune. Ardian/Verne ~&#8364;5B for a 500 MW &#206;le-de-France campus, full 500 MW capacity targeted only 2035&#8211;2037, itself the first tranche of a broader ~&#8364;10B / 1 GW French consortium (Ardian, Iliad, EDF, Orange, Scaleway). Figures are announcer-claimed; several were pre-trailed by Les Echos and final terms may differ.</p><p>[7]: MGX&#8211;Bpifrance ~&#8364;7.5B is the national expansion of Campus AI, the joint venture of Bpifrance, Mistral AI, MGX (UAE), and Nvidia, first announced at Choose France 2025 (May 19, 2025) to build &#8220;Europe&#8217;s largest AI Campus&#8221; (flagship ~1.4 GW, Paris region). Per the <a href="https://presse.bpifrance.fr/bpifrance-mistral-et-mgx-etendent-campus-ai-a-lechelle-nationale-pour-batir-un-reseau-de-3-gw-dusines-dia/">Bpifrance press release (June 1, 2026)</a>, the expansion targets up to 3 GW nationally and the ~&#8364;7.5B second-site selection &#8220;doubles the consortium&#8217;s initial investment&#8221;; the second site selection is described as &#8220;imminent,&#8221; not yet committed. The flagship campus at Fouju (Seine-et-Marne) was reported still in early construction (&#8221;foundations laid, main site not yet begun&#8221;) as of April 2026; the flagship&#8217;s secured first tranche is reported at ~&#8364;8.5B (Le Figaro), a separate figure from the &#8364;7.5B second-site expansion. Campus AI is the one summit pledge with a French intelligence-layer anchor (Mistral); the substrate-state exception is noted in the body. The Campus AI president quoted in the body is Thibaud Desfoss&#233;s (&#8221;chaque gigawatt doit faire fructifier la valeur en France, et non simplement la traverser&#8221;), per the Bpifrance press release.</p><p>[8]: Revolut&#8217;s ~&#8364;1B France commitment was reported as contingent on the firm obtaining a French/EU banking licence.</p><p>[9]: Emmanuel Macron, remarks reported by Reuters, June 1, 2026: characterizing the AI-related portion as &#8220;20 billion invested, and 20 billion of AI investments as a follow-up to the summit in February.&#8221; Verify verbatim French against the &#201;lys&#233;e transcript before publication.</p><p>[10]: The February 2025 AI Action Summit in Paris produced a ~&#8364;109 billion headline; France published no public reconciliation of that figure to authorized, appropriated, or disbursed capital. See <a href="https://www.airealist.ai/p/the-kings-new-datacenters">&#8220;The King&#8217;s New Datacenters&#8221;</a> (The AI Realist, March 25, 2026), which audited the &#8364;109B pledge to an honest near-term figure of roughly &#8364;25B.</p><p>[11]: OpenAI, <a href="https://openai.com/index/announcing-the-stargate-project/">&#8220;Announcing The Stargate Project,&#8221; January 21, 2025</a>; announced at the White House with President Trump, Sam Altman, Larry Ellison, and Masayoshi Son. Headline: &#8220;$500 billion over the next four years &#8230; We will begin deploying $100 billion immediately.&#8221; Son named chairman.</p><p>[12]: Reported equity structure (The Information; corroborated by Bloomberg, WSJ): ~$52B committed equity against the $500B headline &#8212; roughly $19B each SoftBank and OpenAI, ~$7B each Oracle and MGX &#8212; implying ~90% of the program was to be debt- and vendor-financed and not yet arranged at announcement. WSJ reported SoftBank&#8217;s equity share could be as low as ~10%.</p><p>[13]: Epoch AI, <a href="https://epoch.ai/blog/openai-stargate-where-the-us-sites-stand">&#8220;OpenAI Stargate: where the US sites stand&#8221;</a>, satellite-imagery analysis, April 17, 2026: Abilene operational at ~0.3 GW (April 17 reading; a later cached version of the same page shows ~0.6 GW), ~4 of 8 buildings live, against a 1.2 GW site target; Epoch projects the program to &#8220;exceed 9 gigawatts by 2029&#8221; versus the $500B/10 GW headline announced January 2025; six other US sites in early construction on ~Q4 2028 timelines. &#8220;Operational&#8221; capacity is satellite-verified (Airbus DS imagery); OpenAI&#8217;s &#8220;nearly 7 GW planned / $400B+ over three years&#8221; figures (five-new-sites announcement, Sept/Oct 2025: https://openai.com/index/five-new-stargate-sites/) are announcer-claimed. The Abilene ~600 MW expansion was redirected, with Microsoft taking the adjacent 900 MW Crusoe site.</p><p>[14]: Reporting by The Information, corroborated by Bloomberg and the Financial Times (early&#8211;April 2026): Stargate LLC had hired no staff and was developing no data centers; OpenAI pursued bilateral capacity deals (Oracle ~$300B/4.5 GW, plus AWS, Google Cloud) and treated &#8220;Stargate&#8221; as an umbrella term for its compute strategy. Bloomberg (Aug 7, 2025) earlier reported CFO Yoshimitsu Goto conceding the effort was &#8220;taking longer than anticipated.&#8221;</p><p>[15]: Abilene expansion (~600 MW) cancelled: Bloomberg, March 6, 2026 (Microsoft took the adjacent Crusoe capacity). Stargate UK paused: Bloomberg, April 9, 2026, citing energy costs.</p><p>[16]: Abilene construction: Crusoe/Oracle; JPMorgan project-finance facility (~$2.3B, May 2025) and a Newmark-led syndicate (~$7.1B); Nvidia GB200 racks installed from mid-2025; Ellison stated an ultimate target above 450,000 GB200 GPUs under a 15-year Oracle lease. These are real, closed commitments and are cited to discipline the &#8220;headline is empty&#8221; overclaim.</p><p>[17]: SoftBank <a href="https://group.softbank/en/news/press/20251231">completed a $41B OpenAI round in December 2025</a> for ~11% (comprising ~$30B from SoftBank Vision Fund 2 plus ~$11B syndicated co-investment); on February 27, 2026 it agreed a further $30B follow-on (<a href="https://group.softbank/en/news/press/20260227">SoftBank Group Corp. press release</a>), funded through Vision Fund 2 as part of OpenAI&#8217;s ~$110B round (the largest private funding round on record, valuing OpenAI at ~$852B), bringing cumulative investment to an expected $64.6B and ~13% stake &#8220;upon completion,&#8221; subject to closing conditions. The follow-on is staged: first $10B tranche executed April 1, 2026; further $10B tranches scheduled July 1 and October 1, 2026 (SoftBank Group Corp. press release, April 1, 2026). As of the June 1 summit, the $64.6B figure is therefore expected-on-completion, not a settled position.</p><p>[18]: Funding via disposal of SoftBank&#8217;s entire Nvidia stake (~$5.83B, October 2025) and T-Mobile shares; $40B bridge facility signed March 27, 2026, with the first $10B drawn April 1, 2026 (SoftBank Group Corp. press release). The facility is unsecured and full recourse to SoftBank, with no OpenAI shares or Arm stake pledged as collateral; per <a href="https://thenextweb.com/news/softbank-10b-margin-loan-openai-stake-collateral">IFR / loan syndication reporting</a>, the margin starts at 250bp over SOFR and steps up by 17.5bp from July through end-September 2026, a structure designed to incentivise an early takeout via bonds or term loans ahead of an expected OpenAI IPO (widely reported as targeted for late 2026 / as early as Q4 2026; the 12-month tenor, maturing ~March 25&#8211;26, 2027, is read by lenders as a bet on that listing). A separate ~$10B margin loan (arranged by Goldman Sachs, JP Morgan, Mizuho; two-year facility with one-year extension, limited recourse) is distinct from the bridge; SoftBank subsequently scaled this facility back toward as little as ~$6B after creditor hesitation (<a href="https://fortune.com/2026/05/30/softbank-75-billion-investment-french-ai-data-centers-masayoshi-son-emmanuel-macron/">Bloomberg, via Fortune</a>) &#8212; a direct signal of the financing strain the body describes. MST Financial&#8217;s David Gibson, via the Financial Times, estimated SoftBank faces &#8220;[an estimated] $50bn ... of funding, between OpenAI, investments and refinancing&#8221; to arrange over the course of 2026; OpenAI is not expected to reach profitability until 2030.</p><p>[19]: S&amp;P Global Ratings, action reported March 2026 (<a href="https://finance.yahoo.com/news/softbank-30-billion-openai-bet-091742980.html">S&amp;P statement via Bloomberg</a>; B-tier link to wire coverage of the agency statement): outlook revised to negative, BB+ affirmed (below investment grade), OpenAI described as &#8220;one of its investments with the weakest credit quality&#8221;; S&amp;P also flagged the unlisted-asset proportion rising above 50% (from 42%) and warned the $30B follow-on could push leverage toward the 35% level that would trigger a downgrade. Moody&#8217;s held SoftBank at Ba2/stable (2025 upgrade). The agency divergence is presented to avoid cherry-picking the bearish view; both keep SoftBank below investment grade.</p><p>[20]: SoftBank&#8217;s reported loan-to-value ratio was 20.6% at end-December 2025, within its stated financial policy (LTV managed below 25% in normal conditions, 35% emergency ceiling; SoftBank Group Corp. disclosure). CFO Yoshimitsu Goto told the Financial Times (March 2026) the group &#8220;does not rule out&#8221; temporarily exceeding 25%. ADR down ~45% from its October 2025 high by late March 2026; Jefferies downgraded to &#8220;Underperform,&#8221; calling the company a &#8220;valuation trap&#8221;; SoftBank paused a separate ~$50B acquisition (Switch). The piece does not claim the 25% ceiling was breached as of publication &#8212; only that the CFO opened the door and S&amp;P flagged the trajectory.</p><p>[21]: No A-tier source confirms SoftBank&#8217;s ~$19B Stargate LLC equity tranche was wired; reporting (The Information, Bloomberg, FT) indicates the JV was bypassed in favor of bilateral deals. Bloomberg Intelligence estimated SoftBank&#8217;s actual Stargate cash requirement nearer ~$40B &#8220;given its less-active-than-expected participation&#8221; &#8212; an estimate, not a disclosure.</p><p>[22]: Yoshimitsu Goto, SoftBank Q3 FY2025 earnings call, February 12, 2026 (translated remarks): SoftBank makes an equity investment while the project itself is financed as project finance, so SoftBank&#8217;s own size is &#8220;limited&#8221; and the amount &#8220;should not be too huge.&#8221; Verify exact translated wording against the SoftBank transcript before publication. Son corroborated the same structure at the Choose France podium, stating SoftBank is &#8220;aggregating project financing&#8221; for the French venture and that the figure &#8220;balloons to roughly $750 billion once the broader system is factored in&#8221; (<a href="https://www.cnbc.com/2026/05/31/softbank-to-build-up-ai-data-centers-in-france-with-major-investment.html">CNBC, June 1, 2026</a>) &#8212; the announcer himself confirming both that the financing is not yet assembled and that the headline expands on a &#8220;broader-system&#8221; basis.</p><p>[23]: French grid: ~70% nuclear share of generation; France the largest net electricity exporter in Europe/globally in most years (RTE/IEA data &#8212; cite data year at fact-check). Note the 2022 exception: amid widespread reactor-corrosion outages France was briefly a net importer, which is why the body says &#8220;in most years.&#8221; EDF long-term industrial pricing ~&#8364;70/MWh from 2026 per the post-ARENH framework. Replace paraphrase with primary RTE/CRE figures and the specific data year before publication.</p><p>[24]: SoftBank press release, May 30, 2026; Bouchain former coal-plant site with EDF as named development partner (described at &#8220;preferred bidder/due diligence&#8221; stage). Grid-proximity rationale for the Hauts-de-France cluster per company and regional (CC2SO/RTE) materials; Bosquel reported ramping 240 MW &#8594; ~1 GW &#8594; 1.4 GW per regional authority citing RTE.</p><p>[25]: No anchor tenant was named in the SoftBank announcement. The substrate-state characterization (Japanese capital, US chips, likely-US offtake) is an analytical inference from SoftBank&#8217;s OpenAI relationship, not a stated offtake agreement; flagged as inference.</p><p>[26]: Emmanuel Macron, remarks from the &#201;lys&#233;e, June 1, 2026, reported by regional French press (mesinfos/La Semaine de l&#8217;&#206;le-de-France): aim to make France &#8220;le premier pays accueillant des centres de donn&#233;es et des capacit&#233;s de calcul en Europe&#8221; and &#8220;Nous sommes clairement en train de combler le retard que nous avions en mati&#232;re de capacit&#233;s de calcul en Europe.&#8221; Verify against the &#201;lys&#233;e transcript before publication.</p><p>[27]: Mistral AI raised $830M in debt financing (its first debt raise since founding) from a seven-bank consortium (incl. BNP Paribas, Cr&#233;dit Agricole CIB, HSBC, MUFG) to acquire ~13,800 Nvidia GB300 chips for a data center at Bruy&#232;res-le-Ch&#226;tel (Essonne), ~44 MW, operational expected Q2 2026 (<a href="https://techcrunch.com/2026/03/30/mistral-ai-raises-830m-in-debt-to-set-up-a-data-center-near-paris/">TechCrunch, March 30, 2026</a>; also Reuters, CNBC). Separately, on June 1, 2026, Bpifrance announced Mistral secured up to 200 MW of capacity with Campus AI (<a href="https://presse.bpifrance.fr/mistral-securise-jusqua-200-mw-de-capacite-de-calcul-avec-campus-ai-en-france/">Bpifrance press release</a>); the Campus AI project coordinator (L&#8217;Usine Nouvelle) described Mistral as a &#8220;preferred&#8221; future client and board member/shareholder while stating no binding tenancy was yet concluded &#8212; the distinction between equity partner and committed offtaker is preserved in the body. Scale contrast: ~44 MW of Mistral-owned compute vs. SoftBank&#8217;s 3,100 MW first phase.</p><p>[28]: RTE 3.1 GW connection feasibility to Dunkirk/Bosquel/Bouchain by 2031: no published binding confirmation as of publication. CRE fast-track connection regime (deliberation 2025-120) implies multi-year (&#8776;3&#8211;4 year) connection timelines even when expedited. Press-release language on &#8220;abundant, decarbonised electricity&#8221; is political framing, not a signed connection agreement.</p><p>[29]: SoftBank pledge precedents: (a) December 2016 Trump Tower &#8220;$50B / 50,000 jobs,&#8221; drawn from the forming Vision Fund, with ~half of deployed capital flowing into WeWork (peak ~$47B valuation; 2023 bankruptcy) &#8212; <a href="https://www.axios.com/2024/12/16/softbank-donald-trump-masayoshi-son">Axios retrospective</a>; (b) March 2018 Saudi PIF &#8220;$200B / 200 GW&#8221; solar MOU, shelved by ~September 2018 (WSJ); (c) Vision Fund 2 ($108B target, ultimately run largely on ~$38B of SoftBank&#8217;s own capital). Each: a head-of-state-adjacent headline converting to a fraction of announced, slower, and structurally different capital. France-specific conversion claims are forecasts based on this precedent, not observed outcomes.</p>]]></content:encoded></item><item><title><![CDATA[The Amendments Were Whispered]]></title><description><![CDATA[A deputy in the president's own party admitted who wrote his amendments. The moat just confessed.]]></description><link>https://www.airealist.ai/p/the-amendments-were-whispered</link><guid isPermaLink="false">https://www.airealist.ai/p/the-amendments-were-whispered</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Wed, 03 Jun 2026 06:38:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-bvw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-bvw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-bvw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-bvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2070115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/200410578?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-bvw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!-bvw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c7ae6a-9bb8-4d49-aebc-649c5dd31ce3_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On May 29, a deputy from the president&#8217;s party named &#201;ric Bothorel filed twelve amendments to a copyright bill. Three more came from his Renaissance colleague Prisca Th&#233;venot. All fifteen landed the same Friday, three days before the Assembly&#8217;s culture commission was due to examine the text, and all fifteen failed the following Tuesday.[1] Asked where the measures came from, Bothorel told Le Point that some had been <em>souffl&#233;s par Mistral</em> &#8212; whispered by Mistral.[2]</p><p>That sentence is the one this newsletter spent four thousand words predicting last week.</p><p>&#8220;<a href="https://www.airealist.ai/p/lobby-levy-legislate">Lobby, Levy, Legislate</a>&#8221; argued that Mistral&#8217;s moat is not sovereignty or model quality but access: the French president&#8217;s contact list, which Arthur Mensch is working to convert into formal law before the 2027 election changes who answers the phone.[3] That was an inference from the customer roster and the lobbying pattern. It did not name this bill; it named the move. A week later, a legislator in the governing party put the move on the public record.</p><p>The bill itself is narrow. Proposition de loi n&#176; 2634, adopted by the Senate, would install a <em>pr&#233;somption d&#8217;utilisation</em>: a presumption that an AI provider trained on protected cultural works, unless the provider can document otherwise.[4] It reverses the burden of proof. Today, an author has to prove their work was scraped; under the text, the company has to show what went into the model. The French government&#8217;s own civic portal describes it in one line: the bill reverses the burden of proof. [5]</p><p>The amendments tell you whom that threatens. One of Bothorel&#8217;s amendments inserts two words, <em>de mod&#232;les</em>, after &#8220;fournisseurs,&#8221; narrowing the bill so it binds only model-builders and exempts the French firms that merely deploy AI downstream &#8212; the corporates that fill Mistral&#8217;s customer list. Its justification is not commercial. It is sovereign: a broad scope, the amendment argues, would halt the sector&#8217;s growth and our digital sovereignty. [6] Another strikes the retroactivity clause, reciting the industry&#8217;s standard line that documenting training data demands complex technical adaptations. [7] A third went after the bill&#8217;s title.[8] Filing amendments against a bill is ordinary politics; a legislator admitting the affected company drafted them is not. The sovereignty argument, deployed to reshape a copyright statute, in the pen of the president&#8217;s party. This is not yet the procurement law the long-form predicted &#8212; it is the same access doing the simpler job first: shielding the customer list from a bill before writing the law that entrenches it.</p><p>Emmanuel Maurel, the deputy carrying the text, attributed the pressure to &#8220;certains anciens ministres du bloc central&#8221; &#8212; former central-bloc ministers now working the building.[9] Readers of the long-form will recognize the address. The piece built its second act on one such figure: C&#233;dric O, the former secretary of state for digital affairs who became a Mistral shareholder and adviser.[3] Maurel, with no framework to grind, arrived at the same door.</p><p>The calendar rhymes, too. Ya&#235;l Braun-Pivet, the Assembly&#8217;s president, received Mensch on May 7. Five days later, the panel that sets the Assembly&#8217;s agenda drew up the lineup for a cross-party session and left the copyright bill off it.[10] The Assembly says the meeting was routine. The sequence stands regardless.</p><p>Last week&#8217;s piece closed on &#8220;a calendar that runs out in eighteen months.&#8221; This week sharpens why the calendar matters. The lobbying is not the behavior of a company that thinks it has time; it is the behavior of one racing against a deadline. Fifteen amendments filed in a single afternoon are the president&#8217;s party spending its access while the access still exists.</p><p>There is one scenario where the clock resets: Gabriel Attal. The former prime minister has made AI a central plank of his campaign, vowing to turn France into &#8220;la patrie de l&#8217;IA,&#8221; and a macroniste successor in the &#201;lys&#233;e would keep the contact list warm.[11] But Attal is not the favorite, by far. A moat that depends on a trailing candidate is a moat with an expiry date. The base case is the one the long-form named: the access leaves with the administration that built it. That is why Mistral is not waiting. You do not whisper fifteen amendments into a friendly deputy&#8217;s hand if you expect the friendly deputies to still be there in three years.</p><p>The commission turned back all fifteen, and the bill survived the room. But the surviving committee is not a passage. The text now sits last in the running order of a reserved day claimed by a small opposition group, a slot it may never reach; if it advances with amendments attached, it returns to the Senate to die of scheduling.[12] Mistral does not need to defeat this bill. It needs the bill to never finish, and it has a governing party willing to file amendments to buy time.</p><p>Still, time is the one thing Mistral cannot lobby for. The president, whose contact list is the moat, is term-limited and polling in the low twenties; in 2027, he leaves, and the phone Mensch has been calling stops being his to answer.[13] The amendments filed in a single afternoon are not the work of a winning company. They are the work of one racing to pour its access into law before the access walks out of the &#201;lys&#233;e. Strip the sovereignty language, and the structure is plain crony capitalism: a national champion whose valuation, customer base, and inner circle of former ministers are all underwritten by one man&#8217;s term in office.[3] </p><p>The lobbying was the visible part. The confession was the story. The clock is the verdict. Macron&#8217;s days are numbered, and everyone on his contact list is counting down with him.</p><h3>Notes</h3><p>[1]: Amendments to Proposition de loi n&#176; 2634, Commission des affaires culturelles et de l&#8217;&#233;ducation, Assembl&#233;e nationale. Of sixteen amendments examined June 2, 2026, twelve were filed by M. &#201;ric Bothorel and three by Mme Prisca Th&#233;venot (both groupe Ensemble pour la R&#233;publique); one, by Mme V&#233;ronique Ludmann (Horizons), was withdrawn. All were deposited May 29, 2026 and rejected or withdrawn June 2. <a href="https://www.assemblee-nationale.fr/dyn/17/amendements/2634/CION-CEDU/AC2">Amendment list and authors, Assembl&#233;e nationale</a>.</p><p>[2]: Thomas Graindorge, &#8220;<a href="https://www.lepoint.fr/politique/je-nai-jamais-vu-un-lobbying-de-cette-puissance-a-lassemblee-la-bataille-de-mistral-contre-le-droit-7IAUAG552JBWNIQBLCZ76QNCU4">&#171; Je n&#8217;ai jamais vu un lobbying de cette puissance &#187; : &#224; l&#8217;Assembl&#233;e, la bataille de Mistral contre le droit d&#8217;auteur</a>,&#8221; Le Point, June 1, 2026. &#201;ric Bothorel quoted acknowledging certain measures were &#8220;souffl&#233;s par Mistral.&#8221; Erwan Balanant (Les D&#233;mocrates) is quoted in the same piece: &#8220;Je n&#8217;ai jamais vu un lobbying de cette puissance-l&#224; sur les domaines culturels.&#8221;</p><p>[3]: <a href="https://www.airealist.ai/p/lobby-levy-legislate">&#8220;The President&#8217;s Customer List,&#8221;</a> The AI Realist, May 2026. The C&#233;dric O biographical detail &#8212; his role as Mistral shareholder and adviser following his tenure as secretary of state for digital affairs &#8212; is sourced there.</p><p>[4]: Proposition de loi relative &#224; l&#8217;instauration d&#8217;une pr&#233;somption d&#8217;utilisation des contenus culturels par les fournisseurs d&#8217;intelligence artificielle, n&#176; 2634, <a href="https://www.senat.fr/dossier-legislatif/ppl25-220">adopted by the S&#233;nat (unanimously) April 8, 2026</a>. Commission text n&#176; 2864-A0 deposited at the Assembl&#233;e June 2, 2026. Note: the S&#233;nat title used &#8220;pr&#233;somption d&#8217;exploitation&#8221;; the version examined at the Assembl&#233;e reads &#8220;pr&#233;somption d&#8217;utilisation.&#8221;</p><p>[5]: <a href="https://www.vie-publique.fr/loi/302764">Vie publique</a> (Direction de l&#8217;information l&#233;gale et administrative), notice of April 10, 2026: the bill &#8220;renverse la charge de la preuve de l&#8217;utilisation de contenus culturels par les fournisseurs d&#8217;IA.&#8221;</p><p>[6]: <a href="https://www.assemblee-nationale.fr/dyn/17/amendements/2634/CION-CEDU/AC2">Amendement n&#176; AC2</a>, M. &#201;ric Bothorel, Commission des affaires culturelles, rejected June 2, 2026: &#8220;&#192; l&#8217;alin&#233;a 4, apr&#232;s le mot &#171; fournisseurs &#187; ins&#233;rer les mots &#171; de mod&#232;les &#187;.&#8221; Expos&#233; sommaire: &#8220;Un champ d&#8217;application trop large et non justifi&#233; du texte [&#8230;] mettrait un coup d&#8217;arr&#234;t &#224; l&#8217;essor du secteur et &#224; notre souverainet&#233; num&#233;rique.&#8221; The amendment also cites the Munich Regional Court ruling GEMA v. OpenAI (November 11, 2025) &#8212; the same enforcement action analyzed in <a href="https://www.airealist.ai/p/register-disclose-pay">&#8220;Register, Disclose, Pay.&#8221;</a></p><p>[7]: <a href="https://www.assemblee-nationale.fr/dyn/17/amendements/2634/CION-CEDU/AC10">Amendement n&#176; AC10</a>, M. &#201;ric Bothorel: &#8220;Supprimer l&#8217;alin&#233;a 5,&#8221; removing retroactive application to pending litigation, on the grounds that transparency and traceability compliance requires &#8220;des adaptations techniques complexes&#8221; that cannot be applied retroactively.</p><p>[8]: <a href="https://www.assemblee-nationale.fr/dyn/17/amendements/2634/CION-CEDU/AC3">Amendement n&#176; AC3</a>, M. &#201;ric Bothorel, targeting the bill&#8217;s title (TITRE).</p><p>[9]: Maurel quote per Le Point (note 2). Maurel, the GDR rapporteur, has publicly championed the text alongside the collecting societies Adami, SACD, and ADAGP.</p><p>[10]: Braun-Pivet&#8211;Mensch meeting (May 7) per Le Point (note 2). The bill&#8217;s absence from the agenda set by the May 12 Conf&#233;rence des pr&#233;sidents is corroborated by &#8220;IA : pas de proposition de loi sur le droit d&#8217;auteur &#224; l&#8217;ordre du jour de l&#8217;Assembl&#233;e nationale,&#8221; Le Monde, May 12, 2026, and by D&#233;cideurs Juridiques, May 12, 2026.</p><p>[11]: Gabriel Attal, first major campaign rally, May 29, 2026, per Le Point (note 2), which reports his ambition to make France &#8220;la patrie de l&#8217;IA&#8221; and attributes to him an effort to slow the text. Direct-quote wording to be confirmed against the rally transcript before syndication.</p><p>[12]: Procedural posture per Le Point (note 2): the text is placed last in the GDR niche order of June 11; amendments lengthen h&#233;micycle debate and, if adopted, force a return to the S&#233;nat for a conforming vote.</p><p>[13]: Emmanuel Macron, in his second consecutive term, is barred by Article 6 of the French Constitution from seeking a third; his mandate ends in 2027. His approval stood in the low twenties as of May 2026 (Ipsos, Elabe, and Morning Consult tracking polls), as detailed in &#8220;The President&#8217;s Customer List&#8221; (note 3).</p>]]></content:encoded></item><item><title><![CDATA[The Overbuild Put]]></title><description><![CDATA[Meta is the only hyperscaler without a cloud business. It just told shareholders it might need one &#8212; and that is the most revealing thing it has said about a buildout it can no longer obviously fill.]]></description><link>https://www.airealist.ai/p/the-overbuild-put</link><guid isPermaLink="false">https://www.airealist.ai/p/the-overbuild-put</guid><dc:creator><![CDATA[Julien Simon]]></dc:creator><pubDate>Mon, 01 Jun 2026 11:51:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nV9P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nV9P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nV9P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nV9P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc032c12-b94f-46a4-9681-7f306e828109_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2377335,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/200094655?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nV9P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!nV9P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc032c12-b94f-46a4-9681-7f306e828109_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On May 27, asked at Meta&#8217;s annual shareholder meeting whether the company would ever take on Amazon, Microsoft, and Google in cloud computing, Mark Zuckerberg said the idea was &#8220;definitely on the table.&#8221; [1] Then he added the qualifier that matters more than the headline: Meta hasn&#8217;t rented out compute &#8220;because we think that we have a use for the compute,&#8221; and a cloud business becomes an option only &#8220;if we get to a point where we feel that we have overbuilt.&#8221; [2]</p><p>Read that again with the calendar open. Five weeks earlier, on April 24, Meta had signed a deal making it one of the largest customers in the world for Amazon&#8217;s Graviton processors &#8212; renting compute capacity from a direct competitor&#8217;s cloud, explicitly to get access to the silicon it needs now without waiting on its own data centers. [3] So in the same quarter, the only one of the four U.S. hyperscalers that does not sell cloud services [4] was simultaneously a major <em>buyer</em> of someone else&#8217;s compute and a prospective <em>seller</em> of its own. Short and long, on the same balance sheet, at the same time.</p><p>That is the contradiction worth chasing. Everyone in AI is supposedly starved for compute &#8212; GPUs backordered for months, Amazon&#8217;s own training chips shipping slower than it can build them, North American data-center vacancy at 1.4% at the end of 2025. [5] And here is the company building more of it than anyone, raising the possibility that it might have too much. Where does &#8220;excess capacity&#8221; come from in a world that can&#8217;t get enough?</p><h2>The claim: a put, not a pivot</h2><p>The answer is that &#8220;excess&#8221; and &#8220;scarcity&#8221; are not opposites here. They are the same condition seen from two ends of a balance sheet &#8212; and which end you look from determines how you should price Meta.</p><p>Meta&#8217;s cloud remark is not a product strategy. It is a put option on its own buildout. And the interesting question is whether to read that option as <em>fragility</em> or as <em>optionality</em>. Both readings are live. Both are defensible from the same numbers. The piece that follows is about which one the evidence favors, and why the remark itself is the tell.</p><p>The numbers frame the tension. Meta raised its 2026 capital-expenditure guidance to $125-$145 billion, up from a prior range of $115&#8211;$ 135 billion, citing higher component prices and &#8220;additional data center costs to support future year capacity.&#8221; [6] As much as double what it spent in 2025, and even at the floor, more than 2024 and 2025 combined. [7] Yet first-quarter capex came in at just $19.84 billion &#8212; <em>below</em> the $27.57 billion analysts expected. [8] The company spent modestly and guided enormously in the same breath, and the market punished the guidance, not the spend: the stock fell roughly 7%. [9]</p><p>The exposure is not in what Meta has spent but in what it has promised to spend. The first-quarter filing carries $237.67 billion in non-cancelable contractual commitments &#8212; mostly third-party cloud capacity, servers, network infrastructure, and data centers &#8212; against $81.18 billion of cash and marketable securities. [10] Separately, it disclosed $182.88 billion of leases not yet commenced, consisting of data centers, colocations, and network infrastructure that begin between now and 2036. [11] The commitment line jumped by $107 billion in the quarter alone, which chief financial officer Susan Li attributed to multiyear cloud deals and infrastructure purchase agreements. [12] The overbuild, if there is one, does not live in trailing capex. It lives in the contracts &#8212; and contracts do not flex when demand disappoints.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!psA4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!psA4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 424w, https://substackcdn.com/image/fetch/$s_!psA4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 848w, https://substackcdn.com/image/fetch/$s_!psA4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 1272w, https://substackcdn.com/image/fetch/$s_!psA4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!psA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png" width="1456" height="824" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:824,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:200594,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/200094655?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!psA4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 424w, https://substackcdn.com/image/fetch/$s_!psA4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 848w, https://substackcdn.com/image/fetch/$s_!psA4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 1272w, https://substackcdn.com/image/fetch/$s_!psA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48e9f326-b53f-41ef-bf92-d535a267ab03_2332x1320.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first reading &#8212; call it the <strong>Overbuild Put</strong> &#8212; holds that Meta is stacking every available lever to make a buildout look affordable whose paying customer it has not yet secured, and that the cloud remark is the final lever: a backstop buyer of last resort for capacity its own products may not fill. The second reading &#8212; call it <strong>Scarcity Builds the Glut</strong> &#8212; holds that the overbuild is rational, that an advertising machine of staggering profitability is funding it from cash, that scarcity is real and the surplus will be absorbed, and that the cloud option is genuine upside rather than a distress signal. The rest of this piece develops both, then resolves them.</p><h2>The mechanism: four levers and a backstop</h2><p>Start with the paradox, because resolving it is the whole argument.</p><p>The compute Meta is renting from Amazon, and the compute it is building is not the same as the compute it is renting. The Graviton deal brings tens of millions of Arm-based CPU cores into Meta&#8217;s portfolio &#8212; general-purpose silicon suited to agentic inference, the workload that runs <em>after</em> a model is trained, and available immediately. [3] Hyperion, Meta&#8217;s flagship campus in Richland Parish, Louisiana, is a five-gigawatt site built for the next generation of frontier <em>training</em>, and it does not come online until 2029. [13] Different silicon, different workload, different clock. Meta is short on the inference capacity it needs this year and long on the training capacity it has committed to for the end of the decade.</p><p>That gap &#8212; between capacity contracted years ahead and demand demonstrated today &#8212; is where &#8220;excess&#8221; is manufactured. And it is manufactured by the very scarcity panic that justifies the spending. Racing a feared shortage, you commit to gigawatts that arrive in giant, indivisible blocks long before the workloads exist to fill them. The scarcity is what produces the glut. They are the same phenomenon.</p><p>Meta&#8217;s own answer is that the gap is illusory &#8212; that the committed capacity is precisely the inference base it needs to put personal and business agents in front of billions of users, as Li told the call. [14] That may prove right. It is also exactly the demand that has to materialize on schedule for the contracts to pay, and a backstop is what a management team names when it wants insurance against its own forecast.</p><p>Now the affordability levers &#8212; each of them legal, disclosed, and used across the industry. The question is never whether any one of them is permissible; it is what they add up to. The buildout only proceeds if it can be made to look cheaper than it is.</p><p>The first lever is the off-balance-sheet vehicle. Meta financed Hyperion through a joint venture with Blue Owl Capital &#8212; Blue Owl owns 80%, Meta 20% &#8212; funding construction through a special-purpose vehicle (SPV), Beignet Investor, that raised roughly $27 billion of debt against about $2.5 billion of equity: close to $30 billion in total, the largest private-credit data-center deal on record. [15] The structure keeps the debt off Meta&#8217;s books, and the price of that engineering shows in the terms. The bonds, rated A+ by a single agency on the strength of Meta&#8217;s backing, priced at a 6.58% yield &#8212; roughly 225 basis points over Treasuries, wider than Meta&#8217;s own senior notes pay despite the identical credit standing behind them, the premium a charge for the off-balance-sheet structure, and the 24-year tenor &#8212; and mature in 2049. [16] This is not a one-off but a template. A second vehicle follows the same logic: a roughly $13 billion structure for a gigawatt campus in El Paso, leaning on the same thin-equity, debt-heavy capitalization that is wildly insufficient if the workloads stall. [17][18] One detail in that deal is its own signal &#8212; it has no anchor lender, leaving the banks to syndicate the debt into capital markets rather than place it with a single committed buyer. [17] And these vehicles sit on top of, not instead of, the $58.75 billion of senior notes already on Meta&#8217;s own balance sheet. [19]</p><p>The second lever is the lease itself. To keep the rating agencies from treating the arrangement as debt, Meta structured the Hyperion lease on a four-year renewable term &#8212; short enough that the obligation need not be consolidated onto the balance sheet as a single long-term liability. [20] The debt is real; it simply does not appear where a casual reader of the 10-K would expect to find it.</p><p>The third lever is depreciation. Effective January 1, 2025, Meta extended the estimated useful life of a subset of its servers and network equipment to 5.5 years, a change it disclosed would reduce full-year 2025 depreciation expense by approximately $2.9 billion. [21] Lower depreciation flows straight to reported operating income without changing a dollar of cash. The timing is the point: Meta stretched the assumed life of its hardware precisely as it ramped the buildout, flattering the income statement at the moment the spending most needed flattering. The contrast with Amazon is exact. In the same window, Amazon <em>shortened</em> the useful life of a subset of its servers to five years, explicitly citing the rapid pace of AI innovation. [22] Two companies, one hardware reality, opposite accounting choices &#8212; and Meta picked the one that defers the reckoning. Michael Burry&#8217;s public broadside in late 2025, estimating roughly $176 billion of industry-wide understated depreciation between 2026 and 2028, is the bear case for that choice arriving on schedule. [23]</p><p>The defense is real: a GPU&#8217;s economic life does cascade &#8212; from frontier training down to cheaper inference and eventual resale &#8212; so a longer book life can be honest rather than cosmetic. But the cascade has to land somewhere. It presumes a profitable second use for silicon Meta has finished training on, and that second use is either internal inference demand or an outside renter. The depreciation assumption and the cloud option are the same bet wearing different clothes.</p><p>The fourth lever is the one Zuckerberg named out loud. Each of the first three makes the buildout <em>look</em> affordable; none makes it <em>pay</em>. The vehicles, the lease slicing, the stretched depreciation all assume the same thing &#8212; that the compute, once built, generates revenue. The financing analyst on the Hyperion deal said it plainly: Meta has to build the thing, &#8220;put workloads in it,&#8221; and operate on the presumption that it will monetize those loads later. [24] The cloud option is the answer to the question every other lever begs. If Meta&#8217;s own products do not fill the capacity, Meta rents it to someone whose products will &#8212; and the debt gets serviced either way. That is what a put is: the right to sell the underlying when you no longer want to hold it.</p><p>This is why the Commitment-versus-Spend gap matters so much. A company that has spent $19.84 billion against $237.67 billion in commitments is not yet overbuilt. [8][10] It is <em>contracted to</em> overbuild, with the spending back-loaded and the demand unproven. The cloud remark is what a management team says when it can see the gap between the contracts it has signed and the demand it can document, and wants the market &#8212; and the credit market in particular &#8212; to know there is an exit.</p><p>The strongest objection is that this is simply how the cloud business was born. AWS grew out of Amazon&#8217;s own internal slack in 2006: build for yourself, find you have spare capacity, rent it out. Selling the excess is not a red flag &#8212; it is the canonical path to the most lucrative franchise in enterprise computing. The distinction is sequence and leverage. Amazon converted capacity it already owned into a product before anyone had committed a quarter-trillion dollars of debt-financed, off-balance-sheet capacity to the bet. Meta is committing the capacity first, financing it through vehicles built to keep the debt invisible, and presuming the product will follow. AWS monetized a surplus it stumbled into; Meta is pre-committing to a surplus and naming, in advance, its buyer of last resort. One is discovery. The other is a hedge.</p><h2>What actually exists</h2><p>Here, the second reading is at its strongest, and honesty requires giving it full weight.</p><p>Meta can build models. For a year, that was an open question. Llama 4 launched in April 2025 to a poor reception; Yann LeCun later told the <em>Financial Times</em> that the benchmark results had been &#8220;fudged a little bit,&#8221; that the team used different models for different benchmarks, and that Zuckerberg lost confidence in the group and sidelined it. [25] Eleven of the fourteen researchers behind the original Llama left the company; LeCun himself departed in November 2025. [26] The flagship &#8220;Behemoth&#8221; model was delayed due to performance issues and never shipped as promised. [27] If the thesis were &#8220;Meta cannot compete at the frontier,&#8221; that history would carry it.</p><p>But it isn&#8217;t, and the history was reversed. On April 8, 2026, Meta Superintelligence Labs &#8212; the division built around the $14.3 billion Scale AI investment and chief AI officer Alexandr Wang &#8212; released Muse Spark, which scored 52 on the independent Artificial Analysis Intelligence Index &#8212; fourth in the world at launch, behind only Gemini 3.1 Pro, GPT-5.4, and Claude Opus 4.6, and far ahead of Llama 4 Maverick&#8217;s 18. [28] Meta is, demonstrably, back in the race. But the profile is spiky in a telling way: Muse Spark&#8217;s weakest results fall on exactly the agentic, real-world-work benchmarks that enterprise compute is sold against &#8212; it trails GPT-5.4 and Anthropic&#8217;s Claude models on Artificial Analysis&#8217;s GDPval economic-task evaluation and on Terminal-Bench, gaps Meta itself flagged as priorities for further work &#8212; while its standout scores cluster in consumer health and multimodal fluency. [29]</p><p>What it did with that model is the crux. Muse Spark is closed. Its weights are not published, and at launch, Meta offered no public API, only a private preview to select users &#8212; the model was available free through the Meta AI app and website, and rolling out as the default assistant across Facebook, Instagram, WhatsApp, and Ray-Ban glasses, but not sold to developers as a service. [30] Meta deliberately declined to monetize the intelligence layer externally. The model exists to make Meta&#8217;s own products better and to be consumed by Meta&#8217;s own three-billion-user base, monetized the way Meta monetizes everything &#8212; through advertising, supplemented by new $7.99 and $19.99 Meta AI subscriptions. [31]</p><p>And the advertising machine is extraordinary. First-quarter revenue rose 33% to $56.31 billion, the fastest growth since 2021; ad impressions were up 19% and price per ad up 12%; operating income reached $22.87 billion; and the company generated $12.4 billion of free cash flow in the quarter even after capex. [32] This is the heart of the optimistic reading. Meta is funding a generational infrastructure bet out of one of the most profitable businesses in the world, not borrowing against hope. It underperformed expectations in the quarter and retains the discipline to throttle. If the buildout is rational, this is why.</p><p>That cushion is thinning fast, though. The $43.6 billion of free cash flow Meta generated across 2025 is set to fall steeply in 2026 as capex roughly doubles &#8212; far enough that several analysts now model it turning negative within a year or two. [33] The ads engine funds the buildout today; whether it still does in 2027 is the seam the bear case pulls at.</p><p>It also sharpens the problem. A closed model that, at launch, sold nothing to outside developers does not generate external compute revenue. Muse Spark fills Meta&#8217;s <em>consumer</em> demand, not the <em>commercial</em> demand that would absorb a five-gigawatt training campus and service a thirty-billion-dollar SPV. The model&#8217;s success and the buildout&#8217;s empty revenue case trace to one decision: Meta chose to keep its best work inside the walls. The capacity outside the walls still needs a tenant.</p><h2>Whose money builds it</h2><p>If the advertising machine genuinely pays for all of this, one hire is hard to explain. In January 2026, Meta named Dina Powell McCormick, with sixteen years at Goldman Sachs, where she ran the global sovereign investment banking business, later a deputy national security adviser, with the Gulf relationships to match, president and vice chairman. [34] Zuckerberg&#8217;s brief for her was specific: partner &#8220;with governments and sovereigns to build, deploy, invest in, and finance Meta&#8217;s AI and infrastructure,&#8221; and build &#8220;new strategic capital partnerships&#8221; that &#8220;expand our long-term investment capacity.&#8221; [35] A company that can comfortably fund its buildout from operating cash flow does not recruit a sovereign-wealth dealmaker to expand its investment capacity.</p><p>The move follows a path Microsoft, OpenAI, and Amazon have already worn &#8212; courting Gulf sovereign-wealth funds to help underwrite AI infrastructure. [36] It is the logic of the SPVs taken one tier further. Private credit moved the debt off Meta&#8217;s balance sheet; sovereign capital would move part of the funding burden off the private-credit market, which &#8212; as the El Paso deal&#8217;s missing anchor lender hints &#8212; is showing early signs of indigestion. Each tier widens the circle of people other than Meta who carry the bet.</p><p>And it changes what the capacity costs in something other than dollars. Sovereign money is not neutral money. A loan financed by a foreign government carries strings; private credit does not: preferences about where the capacity sits, who gets access, and what the financier expects in return. Meta has not closed such a deal &#8212; it has hired the person whose job is to find one. But the direction is the tell. When the cheapest available capital for a buildout is a sovereign-wealth fund, the buildout has outgrown every conventional source, and the question of who holds leverage over Meta&#8217;s compute stops being rhetorical.</p><h2>The mirror: Amazon built the same trap in reverse</h2><p>The cleanest way to see what Meta is doing is to set it beside the company it is renting chips from.</p><p>Amazon is the canonical case of infrastructure reversion: a company that stumbled repeatedly at the intelligence layer &#8212; Titan, Nova, the slow developer uptake of its own silicon &#8212; and resolved each stumble by retreating to infrastructure it could sell. The difference is that Amazon <em>has</em> the infrastructure business. When its models underperformed, it had AWS to monetize the compute regardless, and Bedrock to resell everyone else&#8217;s models through its own billing relationship. The reversion worked because the floor was already a product.</p><p>Meta has arrived at the same place from the opposite direction. It has the intelligence-layer stumbles. It has the infrastructure. What it lacks is a cloud business that would let the infrastructure pay for itself if the models don&#8217;t. The two companies even diverge on the accounting of identical hardware, each in the direction its strategy implies: Amazon, which sells compute and lives with hardware honesty, shortened its server life; Meta, which needs the buildout to look affordable, lengthened it. [21][22]</p><p>So the Infrastructure Reversion Test produces a Meta-specific verdict. Reversion is a fallback to a business you already run. Meta is contemplating reversion to a business it has never run, against incumbents who own two-thirds of the market between them, [4] as the backstop for a model strategy that, at launch, sold nothing to outsiders. It closed its models and is now weighing whether to sell the floor beneath them. When the intelligence layer is walled off from outside revenue, the only thing left to sell to outsiders is the raw compute &#8212; and that is the layer with the lowest margins and the most entrenched competition.</p><p>The bear&#8217;s favorite analogy belongs here, and it cuts more sharply than the bulls admit. The dark-fiber buildout of the late 1990s did, eventually, become the backbone of the modern internet &#8212; vindication, the optimists say, for building ahead of demand. But the surplus enriched whoever bought it cheaply out of bankruptcy, not the companies that financed and laid it. [37] If Hyperion and its siblings are dark fiber 2.0, the relevant question is not whether the capacity is used. It is who is holding the paper when it does. And the paper here sits with private-credit funds, insurers, and &#8212; through target-date and core bond funds &#8212; ordinary retirement accounts, layered over a thin equity cushion. [18][38]</p><p>This also answers the objection that the SPV debt is the lenders&#8217; problem, not Meta&#8217;s. It is both, and the split is the point. Meta&#8217;s own direct exposure is comparatively contained &#8212; the lease payments it owes the vehicles, plus its minority equity. The structure&#8217;s fragility &#8212; the thin cushion, the long-dated near-junk debt &#8212; sits with Blue Owl, the bondholders, and the insurers behind them. The risk sits there by design. Meta engineered it onto someone else&#8217;s balance sheet, which is precisely why it can afford to be sanguine about overbuilding, and why &#8220;cloud is on the table&#8221; costs it so little to say.</p><h2>What would have to break</h2><p>The cloud remark serves as the hinge between the two readings, making this a thesis with a falsification date built in.</p><p>If Meta never exercises the option &#8212; if Muse-series models scaling across three billion users, plus recommendation and ads inference, plus whatever agentic workloads arrive, actually fill Hyperion and El Paso, and the SPV debt is serviced out of the advertising machine&#8217;s cash flow &#8212; then the optimists were right. The buildout was a rational forward purchase, the cloud line was idle optionality, the levers were prudent capital management. The end-state even has a name: Meta becomes a second Google &#8212; billions of users, a wall of apps, a competitive frontier model, and the custom silicon and data centers to run it all in-house. Google built precisely that stack, and it pays.</p><p>But the comparison is where the bull case turns on itself. Google&#8217;s vertical integration includes the one layer Meta has conspicuously skipped: it monetizes the same silicon and models externally, renting its TPUs and selling Gemini through Google Cloud &#8212; the chips that train Gemini and serve a billion users also collect rent from outside customers. [39] Google fills its own fleet and sells the overflow. Meta closed its model, withheld the API, and runs no cloud; and its silicon program, MTIA, is the least-proven leg of the stack, which is why it still leans on Nvidia, AMD, and rented AWS capacity to do the work TPUs do for Google. [3] Follow the optimistic case all the way to its end, and Meta lands as Google minus the cloud &#8212; the exact configuration that makes &#8220;cloud is on the table&#8221; necessary in the first place. The bull and bear cases converge on the same missing layer.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6scE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6scE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 424w, https://substackcdn.com/image/fetch/$s_!6scE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 848w, https://substackcdn.com/image/fetch/$s_!6scE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!6scE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6scE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png" width="1456" height="920" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:920,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186442,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.airealist.ai/i/200094655?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6scE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 424w, https://substackcdn.com/image/fetch/$s_!6scE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 848w, https://substackcdn.com/image/fetch/$s_!6scE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!6scE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe47478cd-0af5-4b01-ad4b-7aa04e524b76_2332x1474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The market has already begun pricing that gap. On near-identical first-quarter beats, Alphabet&#8217;s stock rose about 7% the same day Meta&#8217;s fell &#8212; the difference resting on the cloud layer that turns AI capex into outside revenue. [40] And independent modeling cited by the Financial Times puts most of the hyperscalers, Meta included, at negative implied returns on AI investment through 2030, even on the generous assumption that the systems cost nothing to run; Amazon, the most mature cloud monetizer, is the lone positive, at roughly 7%. [41]</p><p>If Meta does exercise it &#8212; if it stands up external compute sales because internal demand fell short of the contracted capacity &#8212; then the put was the plan all along, and the levers were what they looked like: a structure for sustaining a buildout whose customer Meta had not secured.</p><p>The clock that decides it is already running, and three hands move at once. The physical capacity arrives on a schedule &#8212; Prometheus at a gigawatt in 2026, El Paso in 2028, Hyperion&#8217;s five gigawatts in 2029. [13][17][42] The SPV debt amortizes on another, with refinancing risk concentrating as the late-2020s maturities meet the capacity coming online. And the depreciation assumption reconciles on a third: if the stretched five-and-a-half-year life proves optimistic, the write-downs land in precisely the 2026&#8211;2028 window Burry flagged. [23] Demand, power delivery, and refinancing have to line up on the same timeline for the optimistic case to hold. [38] Each runs on its own logic, and none waits for the others.</p><p>There is a reason the credit market is already watching rather than the equity market. Meta&#8217;s five-year credit-default swaps had no liquid market until November 2025 &#8212; there was little to insure, because until then Meta funded itself largely from its own cash rather than from debt. [43] The CDS exists today because Meta became a borrower, and it has widened alongside Oracle&#8217;s, the cohort&#8217;s weakest credit, whose five-year spread has sat near 200 basis points since the spring &#8212; its highest since the 2008&#8211;09 financial crisis, and roughly quadruple its mid-2025 level. [44] JPMorgan now sells a hyperscaler CDS basket &#8212; Alphabet, Amazon, Meta, Microsoft, Oracle &#8212; so institutions can hedge a category of risk that barely existed eighteen months ago, against five names carrying $969 billion in commitments with $662 billion of data-center leases not yet commenced. [45] The instrument to bet against Meta&#8217;s buildout was built before Meta finished building it.</p><p>Weigh it, and the tension does not fully resolve &#8212; but it tips. The advertising business is strong enough that the optimistic case cannot be dismissed, and the first-quarter underspend shows real discipline. Yet a management team that genuinely expected internal demand to fill its capacity would not need to remind shareholders, with the CDS trading and the commitments at a quarter-trillion dollars, that it could always rent out the capacity. You name the exit when you can see the scenario that requires it. The most revealing thing Zuckerberg said in May was not that the cloud is on the table. It was the condition attached: <em>if we feel that we have overbuilt.</em> He is pricing the probability himself.</p><p>Meta is the one hyperscaler that built the cathedral before it had a congregation. &#8220;Cloud is on the table&#8221; is the sound of a company that has noticed, and is letting its lenders know there is a door.</p><h3>Notes</h3><p>[1] Mark Zuckerberg, remarks at Meta&#8217;s annual shareholder meeting, May 27, 2026, as reported in Jonathan Vanian, <a href="https://www.cnbc.com/2026/05/27/mark-zuckerberg-says-meta-starting-cloud-business-on-the-table.html">&#8220;Mark Zuckerberg says a Meta cloud computing business &#8216;definitely on the table,&#8217;&#8221; CNBC, May 27, 2026</a>.</p><p>[2] Ibid. Zuckerberg: &#8220;We haven&#8217;t done that yet because we think that we have a use for the compute,&#8221; and the option arises &#8220;if we get to a point where we feel that we have overbuilt.&#8221; The conditional framing is load-bearing for this piece: Meta did not announce a cloud business; it named an option contingent on overbuild.</p><p>[3] Meta and AWS press releases, April 24, 2026; see <a href="https://www.pymnts.com/artificial-intelligence-2/2026/meta-becomes-one-of-worlds-largest-customers-of-amazon-ai-chips/">&#8220;Meta Becomes One of World&#8217;s Largest Customers of Amazon AI Chips,&#8221; PYMNTS, April 24, 2026</a> (Graviton Arm cores, &#8220;tens of millions&#8221; of cores, positioned for agentic inference). Graviton is an Arm-based CPU, not a GPU; reporting that the deal also covers Trainium/Inferentia is less firmly sourced and is not relied on here.</p><p>[4] &#8220;Of the four U.S. hyperscalers, Meta is the only one that doesn&#8217;t sell cloud infrastructure and services&#8221;; AWS holds roughly a third of the market, with Microsoft and Google together holding another third. CNBC, May 27, 2026 (n.1); <a href="https://www.techradar.com/pro/meta-cloud-computing-business-definitely-on-the-table-mark-zuckerberg-says-excess-data-center-capacity-could-be-used-to-enter-the-market">TechRadar, &#8220;Meta cloud computing business &#8216;definitely on the table,&#8217;&#8221; May 2026</a>.</p><p>[5] North American data-center vacancy fell to 1.4% at year-end 2025, per <a href="https://www.cbre.com/insights/books/north-america-data-center-trends-h2-2025">CBRE&#8217;s North America Data Center Trends, H2 2025</a>; JLL&#8217;s year-end 2025 read put the primary-market vacancy rate near 1%. On Trainium supply, AWS has stated demand exceeds production: <a href="https://techcrunch.com/2026/03/22/an-exclusive-tour-of-amazons-trainium-lab-the-chip-thats-won-over-anthropic-openai-even-apple/">TechCrunch, &#8220;An exclusive tour of Amazon&#8217;s Trainium lab,&#8221; March 22, 2026</a>.</p><p>[6] Meta Platforms, <a href="https://www.sec.gov/Archives/edgar/data/1326801/000162828026028364/meta-03312026xexhibit991.htm">&#8220;Meta Reports First Quarter 2026 Results,&#8221; April 29, 2026</a> (guidance raised to $125&#8211;145B from $115&#8211;135B; rationale: &#8220;higher component pricing... and, to a lesser extent, additional data center costs to support future year capacity&#8221;). SEC / Meta IR.</p><p>[7] 2025 full-year capex was $72.2 billion; 2026 guidance is nearly double that figure. <a href="https://fortune.com/2026/04/29/meta-zuckerberg-145-billion-ai-spending-roi/">Fortune, &#8220;Meta just bumped its 2026 capex forecast up to as much as $145 billion,&#8221; April 29, 2026</a>.</p><p>[8] Q1 2026 capital expenditures (including principal payments on finance leases) were $19.84 billion, below the $27.57 billion StreetAccount consensus. Meta 10-Q / <a href="https://www.cnbc.com/2026/04/29/meta-q1-earnings-report-2026.html">&#8220;Meta Q1 earnings report,&#8221; CNBC, April 29, 2026</a>.</p><p>[9] Shares fell roughly 7% (intraday as much as ~10%) following the capex guidance raise. CNBC (n.8); <a href="https://finance.yahoo.com/sectors/technology/article/meta-stock-sinks-after-q1-earnings-as-company-raises-2026-ai-spending-forecast-to-125-billion-145-billion-160136308.html">Yahoo Finance, April 30, 2026</a>.</p><p>[10] Non-cancelable contractual commitments of $237.67 billion as of March 31, 2026, described in the 10-Q (Note 8, Commitments and Contingencies) as &#8220;mostly related to third-party cloud capacity arrangements and continued investments in servers and network infrastructure, data centers, and consumer hardware products in Reality Labs,&#8221; with ~$42.25B due in 2026 and ~$47.65B in 2027; cash, cash equivalents and marketable securities of $81.18 billion. <a href="https://www.sec.gov/Archives/edgar/data/0001326801/000162828026028526/meta-20260331.htm">Meta Q1 2026 10-Q, SEC</a>.</p><p>[11] Operating and finance leases not yet commenced of approximately $182.88 billion as of March 31, 2026, &#8220;consisting of data centers, colocations, and certain network infrastructure,&#8221; commencing between the remainder of 2026 and 2036, with terms from greater than one year to 30 years. <a href="https://www.sec.gov/Archives/edgar/data/0001326801/000162828026028526/meta-20260331.htm">Meta Q1 2026 10-Q, Note 8, SEC</a>.</p><p>[12] Susan Li, Meta Q1 2026 earnings call, April 29, 2026: &#8220;These multiyear cloud deals and our infrastructure purchase agreements drove a $107 billion step up in our contractual commitments this quarter.&#8221; <a href="https://www.theglobeandmail.com/investing/markets/stocks/META/pressreleases/1604248/meta-meta-q1-2026-earnings-call-transcript/">Meta Q1 2026 earnings call transcript</a>.</p><p>[13] Hyperion: Richland Parish, Louisiana; ~5 gigawatts; completion expected 2029. Blue Owl / Meta joint-venture announcement and coverage. <a href="https://pe-insights.com/blue-owl-and-meta-close-record-30bn-financing-for-ai-data-centre-expansion-in-louisiana/">PE Insights, &#8220;Blue Owl and Meta close record $30bn financing,&#8221; 2025</a>.</p><p>[14] Susan Li, Meta Q1 2026 earnings call, April 29, 2026: the infrastructure investments &#8220;will support our training needs for future models and, most importantly, provide us the inference capacity necessary to deliver personal and business agents to billions of people.&#8221; <a href="https://www.theglobeandmail.com/investing/markets/stocks/META/pressreleases/1604248/meta-meta-q1-2026-earnings-call-transcript/">Transcript</a> (n.12).</p><p>[15] Meta Platforms, <a href="https://investor.atmeta.com/investor-news/press-release-details/2025/Meta-Announces-Joint-Venture-with-Funds-Managed-by-Blue-Owl-Capital-to-Develop-Hyperion-Data-Center/default.aspx">&#8220;Meta Announces Joint Venture with Funds Managed by Blue Owl Capital to Develop Hyperion Data Center,&#8221; October 2025</a> (Blue Owl 80% / Meta 20%; ~$27B debt to PIMCO and other investors plus ~$2.5B equity; largest private-credit data-center deal on record).</p><p>[16] Bonds issued by the Beignet vehicle were rated A+ by S&amp;P (single agency, reflecting Meta&#8217;s backing), priced at a 6.58% yield (~225 bps over Treasuries), fully amortizing, maturing 2049. <a href="https://finance.yahoo.com/sectors/technology/articles/meta-27-billion-bet-turns-114548473.html">Yahoo Finance / WSJ, &#8220;Meta&#8217;s $27 billion bet,&#8221; October 31, 2025</a>; PE Insights (n.13).</p><p>[17] &#8220;Sopaipilla&#8221;: ~$13 billion SPV for a gigawatt-scale data center in El Paso, Texas, expected online 2028; Morgan Stanley and JPMorgan leading and, unlike the PIMCO-anchored Hyperion deal, may offer the debt to capital-markets investors rather than place it with an anchor. Bloomberg, via <a href="https://www.advisorperspectives.com/articles/2026/05/05/meta-taps-morgan-stanley-jpmorgan-new-deal">&#8220;Meta Taps Morgan Stanley, JPMorgan for New Data Center Deal,&#8221; Advisor Perspectives, May 5, 2026</a>.</p><p>[18] On the inadequacy of the thin equity cushion in these data-center SPVs &#8212; typically on the order of 10% equity against a debt-heavy structure &#8212; see <a href="https://paulkedrosky.com/weekend-reading-plus-spvs-meta-and-fiber-buildout-2-0/">Paul Kedrosky, &#8220;SPVs, Credit, and AI Datacenters,&#8221; June 2025</a>. Reported Meta vehicles, including a triple-net leaseback arrangement involving Apollo, have been described at roughly 90% debt / 10% equity (<a href="https://covenantlite.substack.com/p/covenant-lite-29-metas-29-billion">Covenant Lite, &#8220;Meta&#8217;s $29 Billion Bet with Apollo,&#8221; July 2025</a>); whether that arrangement is distinct from the Blue Owl&#8211;led Hyperion financing or an earlier account of the same raise is not independently confirmed, and the body does not treat it as a separate vehicle.</p><p>[19] Carrying amount of long-term debt (fixed-rate senior unsecured notes) of $58.75 billion as of March 31, 2026. <a href="https://www.sec.gov/Archives/edgar/data/0001326801/000162828026028526/meta-20260331.htm">Meta Q1 2026 10-Q, Note 7, SEC</a>.</p><p>[20] Meta structured the Hyperion leases in four-year increments so rating agencies would not treat them as debt. <a href="https://medium.com/@mparekh/ai-metas-mega-ai-financing-deals-show-roadmap-for-peers-rtz-891-0e33c8f6660b">The Information, &#8220;The Creative Dealmaking Behind Meta&#8217;s $30 Billion Data Center Financing,&#8221; reported via Michael Parekh, November 2025</a>.</p><p>[21] Meta Platforms Form 8-K, FY2024 results: &#8220;In January 2025, we completed an assessment of the useful lives of certain servers and network assets, which resulted in an increase in their estimated useful life to 5.5 years, effective beginning fiscal year 2025... we expect this change in accounting estimate will reduce our full year 2025 depreciation expense by approximately $2.9 billion.&#8221; <a href="https://www.sec.gov/Archives/edgar/data/0001326801/000132680125000014/meta-12312024xexhibit991.htm">SEC</a>.</p><p>[22] Amazon shortened the useful life of a subset of its servers and networking equipment to five years in early 2025, citing the rapid pace of AI and machine-learning innovation &#8212; the opposite direction to Meta. <a href="https://deepquarry.substack.com/p/depreciation-of-gpus-between-useful">DeepQuarry, &#8220;Depreciation of GPUs: between useful lives and useful myths,&#8221; December 2025</a>.</p><p>[23] Michael Burry&#8217;s late-2025 argument that hyperscalers understate depreciation by using five-to-six-year lives for hardware with a real economic life closer to two-to-three years, estimated at ~$176 billion of understated depreciation industry-wide across 2026&#8211;2028; Nvidia publicly rebutted. WSJ, &#8220;The Accounting Uproar Over How Fast an AI Chip Depreciates,&#8221; December 8, 2025; CNBC, November 25, 2025. (Burry comparison to Cisco circa 2000, not Enron.)</p><p>[24] Paraphrased from the financing analyst quoted on the Hyperion structure: Meta must build the facility, place workloads in it, and presume future monetization of those workloads. WSJ via Yahoo Finance, October 31, 2025 (n.16).</p><p>[25] Yann LeCun, interview with Melissa Heikkil&#228;, Financial Times, published January 2, 2026: Llama 4 benchmark &#8220;results were fudged a little bit,&#8221; the team &#8220;used different models for different benchmarks to give better results,&#8221; and Zuckerberg &#8220;lost confidence in everyone who was involved&#8221; and &#8220;sidelined the entire GenAI organisation.&#8221; FT (subscription); reproduction: <a href="https://www.fastcompany.com/91469583/yann-lecun-meta-llama-4-model-zuckerberg">Fast Company, &#8220;Yann LeCun: Meta &#8216;fudged&#8217; on Llama 4 testing,&#8221; January 2026</a>.</p><p>[26] Eleven of the fourteen researchers who created the original Llama left Meta; LeCun departed in November 2025. Maginative, &#8220;Meta Goes All-In on &#8216;Superintelligence,&#8217;&#8221; June 2025; <a href="https://thenextweb.com/news/meta-thinking-machines-lab-talent-raid">The Next Web, &#8220;Meta hires five Thinking Machines Lab founders,&#8221; April 2026</a>.</p><p>[27] &#8220;Behemoth&#8221; (the planned ~2-trillion-parameter flagship) was repeatedly delayed on performance and not released in promised form; the GenAI organization was sidelined ahead of the Superintelligence Labs reorganization. Maginative (n.26); Wikipedia, &#8220;Meta Superintelligence Labs&#8221; (secondary, for chronology only).</p><p>[28] Muse Spark scored 52 on the Artificial Analysis Intelligence Index v4.0, fourth globally behind Gemini 3.1 Pro (57), GPT-5.4 (57), and Claude Opus 4.6 (53); Llama 4 Maverick scored 18. Artificial Analysis was given early access to benchmark independently. <a href="https://artificialanalysis.ai/articles/muse-spark-everything-you-need-to-know">Artificial Analysis, &#8220;Muse Spark: everything you need to know,&#8221; April 8, 2026</a>. Note: Meta&#8217;s own claim of 50.2% on Humanity&#8217;s Last Exam used a multi-agent &#8220;Contemplating&#8221; mode with tools; the independent single-agent figure was 39.9%. Treat vendor mode-specific claims separately. The #4 ranking reflects the index at launch (April 8, 2026); the leaderboard has since shifted as newer models posted higher scores.</p><p>[29] Artificial Analysis (given early access by Meta) scored Muse Spark 52 on its Intelligence Index v4.0, 4th at launch. On GDPval-AA &#8212; Artificial Analysis&#8217;s evaluation of economically valuable, real-world office tasks &#8212; Muse Spark scored roughly 1,427 Elo (Meta&#8217;s own reported figure was 1,444), behind GPT-5.4 (~1,672) and Anthropic&#8217;s Claude Opus 4.6 (~1,606) and Sonnet 4.6 (~1,648), though ahead of Gemini 3.1 Pro Preview (1,320); it likewise trailed the leaders on Terminal-Bench Hard. Meta flagged long-horizon agentic systems and coding workflows as areas of continued investment. Most non-composite Muse Spark figures are Meta-reported: because the model is closed (no open weights; Meta AI app and a private API preview only), independent evaluators such as Vals.ai and BenchLM had not posted independent scores as of late May 2026. <a href="https://artificialanalysis.ai/articles/muse-spark-everything-you-need-to-know">Artificial Analysis, &#8220;Muse Spark: everything you need to know,&#8221; April 8, 2026</a>; <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">VentureBeat, April 8, 2026</a>.</p><p>[30] Muse Spark launched closed-weight, distributed free through the Meta AI app/website and rolling out as the default assistant across Meta&#8217;s platforms and Ray-Ban glasses, with no first-party public API at launch (Artificial Analysis benchmarked it via early access; Bloomberg reported the design and code would not be made public). Artificial Analysis (n.28); <a href="https://aitoolbriefing.com/blog/meta-muse-spark-closed-source-2026/">aitoolbriefing, &#8220;Meta&#8217;s Muse Spark Drops &#8212; And It&#8217;s Closed Source,&#8221; April 9, 2026</a>. API availability may change; the claim is specific to launch.</p><p>[31] Meta is testing Meta AI subscriptions at $7.99 and $19.99 per month. <a href="https://intellectia.ai/news/stock/zuckerberg-meta-may-enter-cloud-computing-market">Intellectia, &#8220;Zuckerberg: Meta May Enter Cloud Computing Market,&#8221; May 2026</a>.</p><p>[32] Meta Q1 2026: revenue $56.31B (+33% YoY, fastest since 2021); ad impressions +19%, price per ad +12%; income from operations $22.87B; free cash flow $12.4B. Net income $26.77B included an $8.03B tax benefit (underlying EPS $7.31). Meta Q1 2026 release / 10-Q (n.6, n.8, n.10); <a href="https://coindcx.com/blog/us-stock/meta-q1-2026-earnings-results/">CoinDCX earnings recap, April 2026</a>.</p><p>[33] Meta&#8217;s full-year free cash flow was $43.59 billion in 2025 (Meta Q4/FY2025 release, SEC 8-K). Sell-side projections for 2026 fall sharply as capex roughly doubles &#8212; one widely cited Street estimate has full-year free cash flow dropping toward the high single-digit billions (<a href="https://www.indmoney.com/blog/us-stocks/meta-layoffs-what-8000-job-cuts-reveal-about-tech-layoffs-ai-capex-problem">IND Money, citing Street estimates</a>) &#8212; and several analysts now model free cash flow turning negative across the AI-infrastructure cohort in 2026&#8211;2028; Barclays specifically projected a roughly 90% decline in Meta&#8217;s 2026 free cash flow after the raised guidance. <a href="https://www.cnbc.com/2026/02/06/google-microsoft-meta-amazon-ai-cash.html">CNBC, &#8220;Tech AI spending approaches $700 billion in 2026, cash taking big hit,&#8221; February 6, 2026</a>.</p><p>[34] Meta named Dina Powell McCormick president and vice chairman, announced January 12, 2026; she spent 16 years at Goldman Sachs, where she led its Global Sovereign Investment Banking business, served as deputy national security adviser in the first Trump administration, and most recently was president at BDT &amp; MSD Partners. She had been a Meta board member from April to December 2025. <a href="https://www.axios.com/2026/01/12/meta-dina-powell-mccormick-president-vice-chairman">Axios, &#8220;Meta taps Dina Powell McCormick as president and vice chairman,&#8221; January 12, 2026</a>; <a href="https://www.advisorperspectives.com/articles/2026/01/12/meta-taps-dina-powell-mccormick-driving-ai-buildout">Advisor Perspectives, January 12, 2026</a>.</p><p>[35] Zuckerberg said Powell McCormick would focus &#8220;on partnering with governments and sovereigns to build, deploy, invest in, and finance Meta&#8217;s AI and infrastructure&#8221;; Meta added that she would &#8220;drive an effort to build new strategic capital partnerships and find innovative ways to expand our long-term investment capacity.&#8221; Axios (n.34); <a href="https://www.agbi.com/tech/2026/01/meta-hires-former-trump-adviser-to-focus-on-middle-east-deals/">AGBI, &#8220;Meta hires former Trump adviser to focus on Middle East deals,&#8221; January 16, 2026</a>.</p><p>[36] Microsoft, OpenAI, and Amazon have made AI-infrastructure investment deals with Gulf-based sovereign-wealth funds, many focused on building data centers in the US and the Gulf. AGBI (n.35).</p><p>[37] In the late-1990s telecom buildout, the large majority of fiber laid sat dark for years and bandwidth prices collapsed; the surplus later became the backbone of Web 2.0, benefiting those who acquired it cheaply rather than those who financed it. <a href="https://developmentcorporate.com/saas/the-ai-infrastructure-bubble-4-surprising-reasons-the-90-billion-data-center-boom-could-end-in-a-bust/">&#8220;The AI Infrastructure Bubble,&#8221; Development Corporate, November 2025</a>.</p><p>[38] AI-infrastructure debt is reaching retail retirement accounts through target-date and core bond funds; the bull case &#8220;requires demand, power delivery, and refinancing to line up on the same timeline.&#8221; <a href="https://seekingalpha.com/article/4904529-your-401k-is-funding-ais-data-center-buildout">Seeking Alpha, &#8220;Your 401(k) Is Funding AI&#8217;s Data Center Buildout,&#8221; May 14, 2026</a>.</p><p>[39] Google Cloud sells external access to its Tensor Processing Units (TPUs) &#8212; the custom silicon that also trains Gemini and serves Google&#8217;s own products to over a billion users &#8212; through Compute Engine, Google Kubernetes Engine, and the Vertex AI / Gemini Enterprise Agent Platform, and offers Gemini models commercially on the same platform. <a href="https://cloud.google.com/tpu">&#8220;Tensor Processing Units (TPUs),&#8221; Google Cloud product page, accessed May 2026</a>.</p><p>[40] On April 29&#8211;30, 2026, Alphabet and Meta both beat first-quarter estimates and both raised capital-expenditure guidance, yet Alphabet&#8217;s stock rose roughly 7% while Meta&#8217;s fell roughly 7% &#8212; a divergence widely attributed to Alphabet (like Amazon and Microsoft) operating a cloud business that converts AI investment into external revenue, which Meta lacks. <a href="https://www.cnbc.com/2026/04/29/investors-trust-google-more-than-meta-when-comes-to-spending-on-ai.html">CNBC, &#8220;Investors still trust Google more than Meta when it comes to spending their money on AI,&#8221; April 30, 2026</a>.</p><p>[41] Modeling by Panmure Liberum, cited by the Financial Times, finds that most major US hyperscalers &#8212; Microsoft, Alphabet, Meta, and Oracle &#8212; show negative implied returns on AI investment over 2025&#8211;2030, even under the generous assumption that building and running the AI systems costs effectively nothing; only Amazon is positive, at roughly 7.2%, reflecting its more mature external cloud monetization. One published account put Meta&#8217;s implied figure near &#8722;29%. This is forward-looking modeling, not realized return. <a href="https://www.ibtimes.co.uk/big-tech-ai-investments-financial-challenges-1799764">IBTimes UK, &#8220;Big Tech&#8217;s AI Gamble Shows Negative Returns Despite Surge in Spending,&#8221; May 30, 2026</a>; figure for Meta via Sherwood/Yahoo Finance coverage of the same FT analysis.</p><p>[42] Prometheus, a ~1-gigawatt data center, is scheduled to come online in 2026. <a href="https://www.trendingtopics.eu/metas-comeback-muse-spark-puts-zuckerberg-back-in-the-ai-race-breaks-with-open-source/">Trending Topics, &#8220;Meta&#8217;s Comeback: Muse Spark,&#8221; April 12, 2026</a>.</p><p>[43] Meta&#8217;s (and Alphabet&#8217;s) five-year CDS did not begin trading until November 2025; before that these companies funded AI expansion from their balance sheets rather than debt markets, so there was little single-name CDS interest. <a href="https://www.mellon.com/insights/insights-articles/record-breaking-ai-related-debt-issuance-in-2025.html">Mellon Investments, &#8220;Record-Breaking AI-Related Debt Issuance in 2025,&#8221; December 15, 2025</a> (Bloomberg data).</p><p>[44] Oracle&#8217;s five-year CDS has sat near 200 basis points since spring 2026 &#8212; its highest since the 2008&#8211;09 financial crisis and roughly quadrupled from its mid-2025 level (&#8776;198 bps reported late March&#8211;April 2026). <a href="https://bondblox.com/news/oracles-5y-cds-spread-hits-all-time-highs">BondbloX, &#8220;Oracle&#8217;s 5Y CDS Spread Hits All-Time Highs,&#8221; March 31, 2026</a>; <a href="https://www.fool.com/investing/2026/04/10/oracles-credit-risk-is-at-an-all-time-high/">The Motley Fool / Yahoo Finance, April 10&#8211;11, 2026</a>. A specific basis-point level for Meta&#8217;s own CDS is not independently confirmed here and is deliberately not stated.</p><p>[45] JPMorgan launched a hyperscaler CDS basket (Alphabet, Amazon, Meta, Microsoft, Oracle) in March 2026, in $25M blocks with $5M per name; the five issued $121B in bonds in 2025 (vs. a $28B annual average 2020&#8211;2024), with total commitments of $969B and $662B in data-center leases yet to commence. <a href="https://winbuzzer.com/2026/03/24/jpmorgan-launches-cds-basket-hedge-ai-debt-risk-xcxwbn/">Winbuzzer, &#8220;JPMorgan Launches CDS Basket to Hedge AI Debt Risk,&#8221; March 24, 2026</a> (citing Fortune).</p>]]></content:encoded></item></channel></rss>