Three numbers this week, in order: $205 billion, $750 billion, $5 billion. Alphabet raised its 2026 capex guidance to as much as $205 billion on its Q2 earnings call — revenue and cloud growth both beat estimates, and the stock still fell nearly 5% after hours, because free cash flow went negative $5.9 billion and nobody’s quite sure when this spending turns into a return. The same day, the Wall Street Journal reported OpenAI has lifted its own compute-spending forecast to $750 billion through 2030, up a quarter from the $600 billion figure it was using four months ago — money that now includes OpenAI building and owning its own data center in Georgia rather than just renting capacity. And AMD said it will invest up to $5 billion in Anthropic, tied to Anthropic deploying 2 gigawatts of Instinct MI450 GPUs starting next year — a bet that buys AMD a beachhead against Nvidia and buys Anthropic a hedge against depending on one supplier.
Add it up and you get the shape of the year: the frontier labs have stopped behaving like software companies and started behaving like utilities, sinking hundreds of billions into physical infrastructure years before it’s clear the revenue follows. One financial analyst put it bluntly: OpenAI now spends like a utility but is still valued like software. Alphabet at least has a cash-generating ads business underwriting the bet; OpenAI’s own CFO, per reporting this week, isn’t fully sure how the company covers a bill this size.
The same week supplied a reminder of what happens when the build-fast instinct outruns the build-carefully one. Security researcher Oren Yomtov disclosed “SharedRoot,” a flaw in Anthropic’s Cowork product where the agent’s Linux sandbox exposed the entire host Mac filesystem through a writable mount meant to be root-only inside the guest. Chained with a Linux kernel bug, it let an escaped agent read SSH keys and cloud credentials on any of the roughly 500,000 Macs running local Cowork sessions before Anthropic patched it. It’s a useful contrast to the capex headlines: the money is going into GPUs and gigawatts, and the sandbox around the agent using them turned out to be the weak point. A new arXiv taxonomy published days earlier had already mapped this exact category of risk — memory-based attacks that incubate inside an agent’s persistent state long before they trigger, distinct from ordinary session-scoped prompt injection. The theory arrived just ahead of the practice.
Money is chasing hardware everywhere else in the ecosystem too. Etched doubled its valuation to $10.3 billion in seven months on a bet that transformer-specific inference chips can undercut Nvidia, and Travis Kalanick’s Atoms raised $1.7 billion — with Uber, the company that pushed him out in 2017, now on the cap table. Even the capex-adjacent worries are compounding: a BloombergNEF report out this week says US data centers are on pace to consume a fifth of the country’s electricity by 2035, a forecast that keeps getting revised up faster than anyone expected.
None of this is exactly new — AI has been an expensive habit for years now. What’s new is the scale crossing into territory where a single earnings call moves markets on capex alone, and a single filesystem bug touches half a million machines. The industry is placing bets sized like national infrastructure projects while still shipping products with sandbox bugs. Both things are true at once, and this week made the gap between them harder to ignore.