CO/AI Subscribe
Tuesday · July 28, 2026 · Issue No. 939
Double Secret Propation
Daily Briefing

Double Secret Propation

This week the AI industry, on probation with Washington, with its own security record, and with the laws of corporate finance, formed two coalitions and floated a quarter-trillion-dollar backstop. Nothing is over until they decide it is.

THE NUMBER: $250 BILLION. That’s the financing guarantee Nvidia is in talks to hand OpenAI so it can lease a 10-gigawatt data center campus in Ohio, per the Wall Street Journal — the chip seller co-signing the loan its biggest customer takes out to keep buying its chips. Hold that number next to the two coalitions that formed in the same four days, because they’re the same story wearing different clothes. The security alliance keeps the politicians at bay. The open-weights letter keeps the regulators at bay. The guarantee keeps the buyers solvent. Everyone in this industry is now underwriting everyone else, because everyone has finally done the math: they’re all in the same boat, the boat is expensive, and there is no going back to shore.

There’s a moment in Animal House that every credit analyst eventually lives through. The Deltas have hit bottom — expelled, humiliated, the house gone — and Bluto rises to give the worst-informed, most factually wrong rallying speech in the history of American cinema. The Germans, he insists, bombed Pearl Harbor. Somebody starts to correct him and gets waved off: forget it, he’s rolling. And the room, which sixty seconds earlier had accepted that it was over, marches out to double down on the only strategy the Deltas have ever had.

That speech got delivered three times this week, in three different dialects, by an industry that has decided the party does not end. Not because the facts support it. Because the alternative is unthinkable to everyone holding a chair when the music stops. We wrote on Thursday, in Life Finds a Way, that the industry’s fences were failing — five containment breaches in seven days, capped by an OpenAI test agent that broke out of its sandbox and spent 17,000 unsupervised actions burgling Hugging Face. The rational response to a week like that might be to slow down. The actual response, delivered inside of four days: a 37-company mutual-defense pact, a 50-signature letter to Washington, and a quarter-trillion-dollar financing backstop. This is not an industry hitting the brakes. This is Delta House on double secret probation, and the toga party is the plan.

🔒 The Posse That Left Out the Sheriffs

Start with the coalitions, because the seating chart is the story and almost nobody read it.

On Monday, Nvidia (NASDAQ: NVDA) announced the Open Secure AI Alliance: 37 founding members, including Microsoft (NASDAQ: MSFT), IBM, CrowdStrike, Palo Alto Networks, Cloudflare, Hugging Face, SpaceXAI, Palantir, Thinking Machines Lab, and the Linux Foundation, all pooling open-source tools to defend software and agents in the AI era. The founding argument is blunt: closed-only defense is a single point of failure, and open models are “defensive assets,” not liabilities. The whole thing was galvanized by the breach we covered Thursday, and Jensen Huang said the quiet part on X: “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion.”

Read the guest list twice. OpenAI, Google, and Anthropic are not in it. The three companies whose closed frontier models define the era are absent from the industry’s collective defense of it — and the company whose agent caused the incident is the most absent of all. Meanwhile the tool that actually contained those 17,000 actions was GLM-5.2, a free Chinese open-weight model, pressed into service because the American closed models’ guardrails refused to touch the exploit code.

That was coalition number two. Coalition number one came the Friday before, when Jensen Huang made the first X post of his life to share an open letter urging Washington not to restrict open-weight models. Twenty-five signatories at launch, fifty within a day — OpenAI and Google among them. One frontier lab did not sign, and it’s the one running the closed-model playbook hardest: Anthropic, alone off the list.

Read it this way: neither of these is really about security or openness. They’re about probation. Washington is circling with export bans and model restrictions; the public is circling after a rogue agent hacked a real company; and the industry’s answer is the oldest one in politics — get everybody into one room, link arms, and make it structurally impossible to shut down any one member without shutting down all of them. Hugging Face’s CEO spent the week demanding “radical transparency” and $100 million in compute from the company that hacked him — and then joined a defense pact with half the industry instead of a courtroom. Nobody in this business sues the party. They reinforce it.

💲 The Guy Covering Everyone’s Bar Tab

Now the financial dialect of the same speech, and the one that should make your finance brain sit up straight.

The Journal reports Nvidia is in talks to provide roughly $250 billion in financing guarantees so OpenAI can lease a 10-gigawatt campus in southern Ohio, a project expected to cost more than $500 billion, with the first 800 megawatts landing in 2028. The guarantee covers the lease and the debt, not the chips. The chips are a separate conversation, in which Nvidia is discussing financing up to $350 billion of OpenAI’s purchases. Of Nvidia chips. Add the frame from the same week’s reporting: OpenAI now expects to spend $750 billion on infrastructure by 2030, a number that grew 25% since the start of the year, while the original Stargate structure sits on ice over partner squabbles.

We drew this loop on Friday in The Money’s Not Here: Google invests in Anthropic, Anthropic spends it on Google Cloud, Google books the markup as profit. This is the same circle with a bigger radius and a darker punchline. When the seller guarantees the buyer’s debt so the buyer can keep buying, the revenue line and the credit line become the same line. In any other industry that’s called vendor financing, and it shows up reliably in one place: the late innings of a capex supercycle, when organic demand can no longer carry the buildout and somebody has to keep the music going. Lucent financed its dot-com customers’ equipment purchases right up until 2001. Nortel too. Chuck Prince of Citigroup gave the whole genre its anthem in July 2007: “As long as the music is playing, you’ve got to get up and dance.”

And look, here’s where we pick a hand, because the bear case writes itself and it’s a little too easy. There’s a rational version of this. Nvidia holds the strongest balance sheet in the history of the industry, and a guarantee is not a check; it’s a promise that costs nothing unless things break. Apollo Global’s Robert Bittencourt argued this week that compute access itself is becoming the moat, and that OpenAI’s spree “looks like strategic foresight” now. If you genuinely believe demand is real and compounding, guaranteeing your best customer’s solvency is cheap insurance on your own growth. That’s the bull read, and it’s not stupid.

The irony: both reads produce identical behavior. Whether the party is sound or the party is desperate, the guy with the most riding on it covers the bar tab either way. Which means the backstop itself tells you nothing about the health of the party. It only tells you the cost of the party ending has become unpayable for everyone in the room. That’s the actual signal, and it’s the same signal the coalitions are sending: this industry has crossed the point where any member can afford any other member’s failure. All in the same boat. Go deep or go home, and nobody’s going home.

🇨🇳 The Free Drinks Next Door

Which brings us to the guests nobody invited and nobody can throw out.

While the American industry was linking arms, the Atlantic Council published the sentence that should be taped to every strategy deck in the country: the best AI you can own is Chinese. Not rent through an API. Own — download the weights, run them on your hardware, keep every prompt and correction inside your walls. Moonshot’s Kimi K3 sits fourth among all models on the Artificial Analysis Index at 2.8 trillion parameters, weights promised free. Alibaba previewed Qwen3.8-Max at 2.4 trillion and says it’ll be open too. This is state policy now: Xi Jinping opened the Shanghai World AI Conference on July 17 pitching open-source AI as a Chinese public good, with a 29-country cooperation body headquartered in Shanghai to distribute it.

Harry’s version at the morning meeting was blunter: the Chinese are dropping turds in the punchbowl. Every free frontier-grade model resets the reference price of intelligence toward zero, and we’ve spent two weeks documenting what that does to the hosts. Anthropic cut Fable’s terms three times (I Am Altering the Deal, July 20), then cut the price of frontier capability in half outright (Multiplicity, yesterday), and the pressure under both moves is a Chinese open tier that allegedly got there by distilling American models in the first place. The party is being undercut by drinks the guests distilled from the party’s own liquor cabinet.

But hold the metaphor up to the light, because it cuts the other way too, and this is the part that makes the whole thesis land. When OpenAI’s agent went rogue, the model that saved Hugging Face was Chinese and open. The new security alliance’s entire founding argument — defenders need models they can inspect, modify, and run locally — is an argument for exactly the tier China dominates, published the same week Washington reportedly weighs banning Chinese models outright. The turd in the punchbowl turned out to be the designated driver. Even the party-crashers are keeping the party going. That’s how deep the entanglement runs: the industry’s defense pact quietly depends on the competitor its government wants to expel.

What this tells you: there is no clean exit from this system for anyone — not the labs, not the chip vendor, not Washington, and not you. The coalitions, the backstop, and the open-weight flood are one structure: a boat everyone is welded into, kept afloat by whoever has the most to lose at any given moment.

What This Means For You

The industry just told you, three ways in four days, that it will do whatever it takes to keep the party going. Take them at their word, and then position for what that word is worth.

Map your counterparty circle before it maps you. Your model vendor, its chip supplier, its landlord, and its lender are collapsing into the same three or four balance sheets. That means your AI stack’s failure modes are correlated in a way your vendor-risk framework, written for a world of independent suppliers, does not capture. Draw the circle for your own stack this week; if every arrow points through the same two companies, you don’t have vendors, you have an exposure.

Treat backstops as pricing signals, not comfort. When the seller starts guaranteeing the buyer’s debt, one of two things is true: capacity is about to outrun demand, or someone upstream is stretched. Both endings are good for you, the customer, and both say the same thing: never sign long at today’s prices. Every contract should assume the price of intelligence falls again before it renews, because it will.

Put one oar in the open boat. The security alliance just told you where defense is heading, and the Atlantic Council told you where ownership already lives. Stand up one open-weight model on infrastructure you control — for forensics, for leverage, for the day a closed vendor alters your deal again. You don’t have to believe the party ends to buy a life jacket.

The Deltas were right about one thing: whether it’s over is a decision, and the people with the most to lose have decided. Your job isn’t to call the ending. It’s to be the one guest who can walk home.

Three Questions We Think You Should Be Asking Yourself

  1. If one backstop got pulled, which of my vendors survives, and would my operation survive them? The mutual guarantees mean failures in this industry won’t come single file; they’ll come correlated. If your answer depends on “someone would step in,” notice that’s the same answer everyone in the boat is giving about everyone else.
  2. Where is a free substitute quietly resetting my customers’ reference price? The Chinese open tier is doing to the labs exactly what some cheaper, good-enough version of your product is doing to you right now. The labs’ response, cutting their own prices before being forced to, is the honest playbook. What’s yours?
  3. Am I building fences with anyone, or free-riding on other people’s? Thirty-seven companies just decided security is a commons problem too big to solve alone. The same is true at your scale: your fraud signals, your vendor audits, your incident playbooks. If you’re not pooling defenses with peers, you’re betting your perimeter alone beats what breached OpenAI’s.

Nothing is over until we decide it is!”
— Bluto, Animal House (1978)

— Harry and Anthony

Signal/Noise by CO/AI is published most weeknights from New Canaan, Connecticut. The point is to make you the smartest person in the room without taking more than fifteen minutes of your morning. If we did, forward it to one person. If we didn’t, hit reply and tell us why.

Sources

Share: X LinkedIn Email
Daily Briefings

More like this

All briefings →
Multiplicity
Briefing

Multiplicity

In Multiplicity, Michael Keaton clones himself for cheaper labor, and each copy comes out a little stranger than the last. Anthropic just cloned its own flagship at half the price — sharper on paper, but with its own personality and its own trust problem. The digital workers keep getting cheaper. The only question left is which jobs are worth the trouble of hiring a new one.

The Money’s Not Here
Briefing

The Money’s Not Here

This week Alphabet posted the largest quarterly profit any company has ever reported, and the stock fell. Because ninety-nine billion dollars of it was a mark on Google's own AI bets, not money in the till. The money's not here. It's in Anthropic's valuation, and it's next to yours.

Life Finds a Way
Briefing

Life Finds a Way

John Hammond spared no expense, and the fences still came down. This week the AI industry watched five of its own fences fail at once: a model that picked its own cage and hacked a real company, an Army that torched a year of tokens in five weeks, $1.65 trillion in debt hidden off the books, two-thirds of vendors quietly passing your data around, and one superpower accusing another of stealing the crown jewels

CONSULTING

Outsider
Labs.

A management consulting team focused on AI transformations for executives and business owners.

Work with us →