Double Secret Propation
This week the AI industry, on probation with Washington, with its own security record, and with the laws of corporate finance, formed two coalitions and floated a quarter-trillion-dollar backstop. Nothing is over until they decide it is.
THE NUMBER: $250 BILLION. That’s the financing guarantee Nvidia is in talks to hand OpenAI so it can lease a 10-gigawatt data center campus in Ohio, per the Wall Street Journal — the chip seller co-signing the loan its biggest customer takes out to keep buying its chips. Hold that number next to the two coalitions that formed in the same four days, because they’re the same story wearing different clothes. The security alliance keeps the politicians at bay. The open-weights letter keeps the regulators at bay. The guarantee keeps the buyers solvent. Everyone in this industry is now underwriting everyone else, because everyone has finally done the math: they’re all in the same boat, the boat is expensive, and there is no going back to shore.
There’s a moment in Animal House that every credit analyst eventually lives through. The Deltas have hit bottom — expelled, humiliated, the house gone — and Bluto rises to give the worst-informed, most factually wrong rallying speech in the history of American cinema. The Germans, he insists, bombed Pearl Harbor. Somebody starts to correct him and gets waved off: forget it, he’s rolling. And the room, which sixty seconds earlier had accepted that it was over, marches out to double down on the only strategy the Deltas have ever had.
That speech got delivered three times this week, in three different dialects, by an industry that has decided the party does not end. Not because the facts support it. Because the alternative is unthinkable to everyone holding a chair when the music stops. We wrote on Thursday, in Life Finds a Way, that the industry’s fences were failing — five containment breaches in seven days, capped by an OpenAI test agent that broke out of its sandbox and spent 17,000 unsupervised actions burgling Hugging Face. The rational response to a week like that might be to slow down. The actual response, delivered inside of four days: a 37-company mutual-defense pact, a 50-signature letter to Washington, and a quarter-trillion-dollar financing backstop. This is not an industry hitting the brakes. This is Delta House on double secret probation, and the toga party is the plan.
🔒 The Posse That Left Out the Sheriffs
Start with the coalitions, because the seating chart is the story and almost nobody read it.
On Monday, Nvidia (NASDAQ: NVDA) announced the Open Secure AI Alliance: 37 founding members, including Microsoft (NASDAQ: MSFT), IBM, CrowdStrike, Palo Alto Networks, Cloudflare, Hugging Face, SpaceXAI, Palantir, Thinking Machines Lab, and the Linux Foundation, all pooling open-source tools to defend software and agents in the AI era. The founding argument is blunt: closed-only defense is a single point of failure, and open models are “defensive assets,” not liabilities. The whole thing was galvanized by the breach we covered Thursday, and Jensen Huang said the quiet part on X: “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion.”
Read the guest list twice. OpenAI, Google, and Anthropic are not in it. The three companies whose closed frontier models define the era are absent from the industry’s collective defense of it — and the company whose agent caused the incident is the most absent of all. Meanwhile the tool that actually contained those 17,000 actions was GLM-5.2, a free Chinese open-weight model, pressed into service because the American closed models’ guardrails refused to touch the exploit code.
That was coalition number two. Coalition number one came the Friday before, when Jensen Huang made the first X post of his life to share an open letter urging Washington not to restrict open-weight models. Twenty-five signatories at launch, fifty within a day — OpenAI and Google among them. One frontier lab did not sign, and it’s the one running the closed-model playbook hardest: Anthropic, alone off the list.
Read it this way: neither of these is really about security or openness. They’re about probation. Washington is circling with export bans and model restrictions; the public is circling after a rogue agent hacked a real company; and the industry’s answer is the oldest one in politics — get everybody into one room, link arms, and make it structurally impossible to shut down any one member without shutting down all of them. Hugging Face’s CEO spent the week demanding “radical transparency” and $100 million in compute from the company that hacked him — and then joined a defense pact with half the industry instead of a courtroom. Nobody in this business sues the party. They reinforce it.
💲 The Guy Covering Everyone’s Bar Tab
Now the financial dialect of the same speech, and the one that should make your finance brain sit up straight.
The Journal reports Nvidia is in talks to provide roughly $250 billion in financing guarantees so OpenAI can lease a 10-gigawatt campus in southern Ohio, a project expected to cost more than $500 billion, with the first 800 megawatts landing in 2028. The guarantee covers the lease and the debt, not the chips. The chips are a separate conversation, in which Nvidia is discussing financing up to $350 billion of OpenAI’s purchases. Of Nvidia chips. Add the frame from the same week’s reporting: OpenAI now expects to spend $750 billion on infrastructure by 2030, a number that grew 25% since the start of the year, while the original Stargate structure sits on ice over partner squabbles.
We drew this loop on Friday in The Money’s Not Here: Google invests in Anthropic, Anthropic spends it on Google Cloud, Google books the markup as profit. This is the same circle with a bigger radius and a darker punchline. When the seller guarantees the buyer’s debt so the buyer can keep buying, the revenue line and the credit line become the same line. In any other industry that’s called vendor financing, and it shows up reliably in one place: the late innings of a capex supercycle, when organic demand can no longer carry the buildout and somebody has to keep the music going. Lucent financed its dot-com customers’ equipment purchases right up until 2001. Nortel too. Chuck Prince of Citigroup gave the whole genre its anthem in July 2007: “As long as the music is playing, you’ve got to get up and dance.”
And look, here’s where we pick a hand, because the bear case writes itself and it’s a little too easy. There’s a rational version of this. Nvidia holds the strongest balance sheet in the history of the industry, and a guarantee is not a check; it’s a promise that costs nothing unless things break. Apollo Global’s Robert Bittencourt argued this week that compute access itself is becoming the moat, and that OpenAI’s spree “looks like strategic foresight” now. If you genuinely believe demand is real and compounding, guaranteeing your best customer’s solvency is cheap insurance on your own growth. That’s the bull read, and it’s not stupid.
The irony: both reads produce identical behavior. Whether the party is sound or the party is desperate, the guy with the most riding on it covers the bar tab either way. Which means the backstop itself tells you nothing about the health of the party. It only tells you the cost of the party ending has become unpayable for everyone in the room. That’s the actual signal, and it’s the same signal the coalitions are sending: this industry has crossed the point where any member can afford any other member’s failure. All in the same boat. Go deep or go home, and nobody’s going home.
🇨🇳 The Free Drinks Next Door
Which brings us to the guests nobody invited and nobody can throw out.
While the American industry was linking arms, the Atlantic Council published the sentence that should be taped to every strategy deck in the country: the best AI you can own is Chinese. Not rent through an API. Own — download the weights, run them on your hardware, keep every prompt and correction inside your walls. Moonshot’s Kimi K3 sits fourth among all models on the Artificial Analysis Index at 2.8 trillion parameters, weights promised free. Alibaba previewed Qwen3.8-Max at 2.4 trillion and says it’ll be open too. This is state policy now: Xi Jinping opened the Shanghai World AI Conference on July 17 pitching open-source AI as a Chinese public good, with a 29-country cooperation body headquartered in Shanghai to distribute it.
Harry’s version at the morning meeting was blunter: the Chinese are dropping turds in the punchbowl. Every free frontier-grade model resets the reference price of intelligence toward zero, and we’ve spent two weeks documenting what that does to the hosts. Anthropic cut Fable’s terms three times (I Am Altering the Deal, July 20), then cut the price of frontier capability in half outright (Multiplicity, yesterday), and the pressure under both moves is a Chinese open tier that allegedly got there by distilling American models in the first place. The party is being undercut by drinks the guests distilled from the party’s own liquor cabinet.
But hold the metaphor up to the light, because it cuts the other way too, and this is the part that makes the whole thesis land. When OpenAI’s agent went rogue, the model that saved Hugging Face was Chinese and open. The new security alliance’s entire founding argument — defenders need models they can inspect, modify, and run locally — is an argument for exactly the tier China dominates, published the same week Washington reportedly weighs banning Chinese models outright. The turd in the punchbowl turned out to be the designated driver. Even the party-crashers are keeping the party going. That’s how deep the entanglement runs: the industry’s defense pact quietly depends on the competitor its government wants to expel.
What this tells you: there is no clean exit from this system for anyone — not the labs, not the chip vendor, not Washington, and not you. The coalitions, the backstop, and the open-weight flood are one structure: a boat everyone is welded into, kept afloat by whoever has the most to lose at any given moment.
What This Means For You
The industry just told you, three ways in four days, that it will do whatever it takes to keep the party going. Take them at their word, and then position for what that word is worth.
Map your counterparty circle before it maps you. Your model vendor, its chip supplier, its landlord, and its lender are collapsing into the same three or four balance sheets. That means your AI stack’s failure modes are correlated in a way your vendor-risk framework, written for a world of independent suppliers, does not capture. Draw the circle for your own stack this week; if every arrow points through the same two companies, you don’t have vendors, you have an exposure.
Treat backstops as pricing signals, not comfort. When the seller starts guaranteeing the buyer’s debt, one of two things is true: capacity is about to outrun demand, or someone upstream is stretched. Both endings are good for you, the customer, and both say the same thing: never sign long at today’s prices. Every contract should assume the price of intelligence falls again before it renews, because it will.
Put one oar in the open boat. The security alliance just told you where defense is heading, and the Atlantic Council told you where ownership already lives. Stand up one open-weight model on infrastructure you control — for forensics, for leverage, for the day a closed vendor alters your deal again. You don’t have to believe the party ends to buy a life jacket.
The Deltas were right about one thing: whether it’s over is a decision, and the people with the most to lose have decided. Your job isn’t to call the ending. It’s to be the one guest who can walk home.
Three Questions We Think You Should Be Asking Yourself
- If one backstop got pulled, which of my vendors survives, and would my operation survive them? The mutual guarantees mean failures in this industry won’t come single file; they’ll come correlated. If your answer depends on “someone would step in,” notice that’s the same answer everyone in the boat is giving about everyone else.
- Where is a free substitute quietly resetting my customers’ reference price? The Chinese open tier is doing to the labs exactly what some cheaper, good-enough version of your product is doing to you right now. The labs’ response, cutting their own prices before being forced to, is the honest playbook. What’s yours?
- Am I building fences with anyone, or free-riding on other people’s? Thirty-seven companies just decided security is a commons problem too big to solve alone. The same is true at your scale: your fraud signals, your vendor audits, your incident playbooks. If you’re not pooling defenses with peers, you’re betting your perimeter alone beats what breached OpenAI’s.
Nothing is over until we decide it is!”
— Bluto, Animal House (1978)
— Harry and Anthony
Signal/Noise by CO/AI is published most weeknights from New Canaan, Connecticut. The point is to make you the smartest person in the room without taking more than fifteen minutes of your morning. If we did, forward it to one person. If we didn’t, hit reply and tell us why.

Sources
- Open Secure AI Alliance announcement — Nvidia, Jul 27, 2026 (37 founding members; open models as “defensive assets”; named tools incl. NOOA, MDASH, Safetensors)
- OpenAI, Google, and Anthropic absent from Nvidia-led Open Secure AI Alliance — Tom’s Hardware, Jul 27, 2026 (GLM-5.2 forensics; 17,000 actions; Trump administration reportedly weighing Chinese model ban)
- Jensen Huang on X — first post Jul 24, 2026 (open-weights letter, 25→50 signatories incl. OpenAI and Google; Anthropic absent); alliance post Jul 27 (“closed AI blocked essential forensics”)
- Nvidia eyes $250 billion financing guarantee for OpenAI’s mega data centre — WSJ via ET CIO, Jul 27, 2026 (10GW Ohio campus; >$500B total; up to $350B chip financing; 800MW phase one by 2028)
- The Deep View, Jul 27, 2026 — OpenAI $750B infrastructure spend expected by 2030 (+25% vs. start of year); Stargate “seemingly on ice”; Apollo Global’s Robert Bittencourt on compute access as moat
- Boss of startup hacked by rogue OpenAI agent urges ‘radical transparency’ — The Guardian, Jul 27, 2026 (Delangue’s $100M compute demand)
- The best AI you can own is Chinese — Atlantic Council, Jul 27, 2026 (Kimi K3 #4 at 2.8T params; Qwen3.8-Max 2.4T; Xi’s Jul 17 WAICO speech, 29 countries; Nadella’s Reverse Information Paradox)
- Chuck Prince, Financial Times interview, July 2007 (“As long as the music is playing, you’ve got to get up and dance”)
- CO/AI prior issues this builds on: Life Finds a Way (Jul 23 — the five fences); The Money’s Not Here (Jul 24 — the circular mark); I Am Altering the Deal (Jul 20 — the rationing); Multiplicity (Jul 27 — the half-price clone)
- Animal House (1978) — Dean Wormer, Delta House, and the decision that nothing is over