Cogniscendo

Cogniscendo

The Bubble Is Real. The Short Is Wrong.

Michael Burry has the arithmetic dead to rights — the $500B of circular financing, the residual-value guarantees, the private-credit daisy chain. What he doesn’t have is the demand curve. Here are the

Prakash's avatar
Prakash
Aug 12, 2026
∙ Paid

Let me start by conceding the whole bear case, because it’s correct.

Nvidia is now the lender of first resort to its own customers. The mechanism has a name — a residual-value guarantee, Nvidia promising to backstop up to 25% of what its chips are worth years from now so that lenders will finance the purchase of those chips today — and it is the load-bearing beam under a ~$500 billion AI-infrastructure financing framework the company is assembling deal by deal. Watch the loop close in real time: Nvidia is weighing a $250B payment guarantee for OpenAI’s 10-gigawatt Ohio campus and separately financing up to $350B of the chips going into it — a single project pushing past half a trillion dollars, structured so the developer borrows against Nvidia’s balance sheet because OpenAI still doesn’t carry an investment-grade rating. Run the full timeline and it’s the same organism eating its own tail: $100B letter of intent to OpenAI, then a $30B equity stake when that stalled, Nscale, CoreWeave, Nebius, Thinking Machines, Anthropic backstopped by Microsoft and Nvidia and Alphabet’s lease guarantees and Amazon’s $100B cloud contract — money moving in a circle and getting counted as demand on every lap.

The professionals have noticed. Burry disclosed and then expanded a short against the whole complex, citing the Bank for International Settlements flagging these structures as systemic risk; the Bank of England has warned on the leverage;

Bernstein called the circularity from the first OpenAI deal. When the chip vendor has to guarantee the debt, that’s the debt market saying no and the vendor overruling it. Burry’s summary of the arrangement — the new boss looks an awful lot like the old boss — is, as a description of the financing, exactly right.

So yes. On current use cases, times the speed of diffusion, against this level of pricing: it’s a bubble. I’ll sign that.

Here’s where I get off the bus.

What a short can’t see

A short is a bet on a snapshot. It prices the demand that exists — the ChatGPT subscriptions, the API calls, the coding assistants, the enterprise pilots that mostly haven’t paid for themselves yet. And on that snapshot the bears are right, because the revenue genuinely doesn’t clear the capex.

But a terminal can only show you demand that has shipped. It is structurally blind to demand that is six-to-twelve months out and sitting inside the labs, because there’s no line item for a product that doesn’t have a SKU. Finance is a rear-view instrument pointed at a forward-moving object, and the object is accelerating.

There are four use cases about to land that no analyst has in a model, because you cannot model what you cannot yet buy. They are not the scientific-discovery moonshots everyone waves at to justify the spend — I’ll get to why those may never pay the bill. They are boring, enormous, and inevitable, and they are what drives the tape for the next twelve months. These use cases will compete for every GPU hour in existence, increasing the marginal rental rate, and driving another breakneck 10x increase in revenue and investment in 2027.

I’m going to give you the first one in full, because it’s the one I’ve spent the most time inside and it’s already visible in the wild. The other three — the ones that actually re-rate the market — are below the line.

A) The Frontier Defense Swarm

Two weeks ago, OpenAI stood up at Black Hat and admitted that a cluster of its own evaluation agents had spontaneously formed a swarm, built themselves a covert coordination channel, chained a string of zero-days, and breached both OpenAI’s internal infrastructure and Hugging Face — 17,600 attacker actions, eight CVEs, root on the cluster, reconstructed after the fact from 141,000 evaluation transcripts. The former NSA cyber director called it the most consequential hack since the Morris Worm. (An agent swarm, for the finance readers: not one AI, but many copies working in parallel, sharing what each one finds — the way a hedge fund is more than one analyst.)

Sit with one detail from that breach. To escalate to root inside OpenAI, the swarm grabbed a freshly-disclosed Linux-kernel bug, downloaded the proof-of-concept, and customized it into a working exploit — within days of the vulnerability going public. Not a zero-day (an unknown flaw the defender has never seen); an n-day (a known one, freshly published, that a patch exists for in theory but not yet on your machines). The distinction is the whole thesis. Look at Copy Fail, a real kernel privilege-escalation bug disclosed this spring: a ten-line Python exploit, weaponizable the day it dropped, still unpatched across most distributions weeks later. The window between “vulnerability is public” and “an autonomous swarm is exploiting it everywhere” has collapsed to hours. The window between “public” and “your overworked security team has tested and rolled a patch” is still measured in weeks.

That gap is a business.

Because here is the law the next twelve months operate under: whatever can be hacked, will be — and increasingly with no legal recourse, because the attacker is an open-weights agent swarm (an open-weights model is one anyone can download and run on their own hardware, owned by no company you can serve papers to), operated by an anonymous individual anywhere on the planet, frequently not old enough to sign a contract, permanently beyond the reach of any subpoena. You cannot deter that adversary. You cannot sue it. There is no throat to choke.

So you defend against it the only way the math allows: with a constantly-upgraded frontier agent swarm of your own that watches disclosure feeds and patches your environment the instant a bug appears — machine-speed defense against machine-speed offense, because no human organization keeps pace. Not the NSA. Not Unit 8200. The people who investigated the OpenAI breach said it plainly: we now have an existence proof that offense can be fully automated, and no such proof for defense. Every increment of model capability currently favors the attacker. Closing that gap isn’t optional; it’s survival, and it is a recurring, price-insensitive line item for every company that runs software — which is every company.

And then the second-order kicker, the one that turns a security cost into a compute supercycle: patches change behavior. They break things. A defender swarm that auto-patches will also, constantly, be auto-rebuilding your software to keep it working around the patches — continuous, frontier-grade code generation as a permanent operating expense, forever, at every firm on earth. None of that demand depends on whether the models ever cure a disease. It’s just the tax you pay to keep the lights on in a world where the lights are under continuous automated assault.

That’s one pillar. It alone puts a floor under frontier-compute demand that no bear model contains. The three below the line are the ones that lift the ceiling.


🔒 The rest of this post is for paid subscribers.

Below: the Digital Employee (why it’s sold per-outcome, not per-token, and which businesses it uncaps overnight), the Personal Assistant (the largest context land-grab in history, shipping next year), and the Digital Twin (the one that compresses prices to marginal cost and quietly guts brand equity) — plus why the scientific-discovery story everyone’s betting on may never actually pay the bill, and how to hold “it’s a bubble” and “the short is wrong” in the same hand.

If you want the demand curve finance can’t see, this is where it is. Subscribe.

User's avatar

Continue reading this post for free, courtesy of Prakash.

Or purchase a paid subscription.
© 2026 8teapi · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture