SecondSource Morning Brief · August 29, 2026 | Watch list price and rate limits, not revenue
1. Revenue growth cannot tell you whether an AI lab has pulled compute back from the open market; the number looks the same under two opposite
At a glance
- Revenue growth cannot tell you whether an AI lab has pulled compute back from the open market; the number looks the same under two opposite stories.
- OpenAI will cut Cursor off from its models on November 12 — not because Cursor breached anything, but because SpaceX bought it.
- Of the more than US$51B in contracted revenue that Nscale — a British AI compute landlord aiming to list in the US as early as September 2026 — showed investors, about 88% traces to one customer.
This issue draws on our August 29 research digest and the deep column published today; the events run from August 17 to 28. Two sweeps, last night and this morning, took in 224 new pieces, and 20 clickable receipts made it into this issue. This is the email edition; the full edition of this issue is the archive of record.
Today's main line
1. [Today] (our 26th deep column, published today; comparison window February to August 2026) We are retiring the indicator we published for spotting when a lab pulls compute back in-house
One line has circulated in AI for a long time: don't worry too much about the labs getting bigger, because the people using them are the ones who actually make the money. Our August 28 issue argued that this is not a property of market structure but a decision the labs can reverse every quarter — a lab willing to rent its fleet out as compute today can stop being willing tomorrow. What is new today: we went back to the tracking indicator that judgment shipped with, and found it cannot decide anything.
Start with the terms. Inference is the compute that runs a trained model in service of users, generating an answer token by token. A lab's fleet has to be divided between its own research and inference sold to outsiders, and the size of the spillover is simply how much it is willing to sell. The indicator said: new compute keeps rising while revenue growth flattens, and the two together mean marginal compute has been pulled back into research.
The problem is that this reading looks identical under two stories that point in opposite directions. Story one: the lab has run the numbers, decided using the fleet itself beats renting it out, and taken it back in-house — the comforting line is being withdrawn. Story two: demand failed to fill the buildings it just put up, so the leftover capacity gets dumped into research — the comforting line is safer than ever, because the spillover is forced by competition. Anthropic's chief executive told story two on the long-form interview show Dwarkesh Podcast on February 13 this year, and said plainly that it is the side where you do not make money: "that gets determined by demand. It doesn't get determined by you" (the episode, 02-13). The two stories prescribe opposite actions for a buyer: one tells you to find a second supplier now, the other tells you to wait for better terms.
We also worked out a threshold. Dylan Patel, who founded the semiconductor and data centre research firm SemiAnalysis, gave a breakdown of the current split on August 25: 50% research, 10% development, 40% inference sold to outsiders, with lab fleets tripling in size over a year (the episode, 08-25). Inference compute sold equals fleet size times the inference share. Put his own two numbers together and the arithmetic falls out: for the absolute quantity of inference compute on the market to actually shrink, that 40% would have to drop below 13% inside a year. The threshold is not a standard we imposed; it comes from his two figures — and he has never argued the share would fall that far. His direction is that the inference share keeps shrinking. He never put a rate on it.
Verification: the two companies the indicator names gave opposite readings this year. First, what annualised revenue is: the most recent period's revenue multiplied out to a full year, not money actually received. Anthropic's figure moved from about US$9B at the end of 2025 to US$65B at the end of July, with the monthly increment falling from a peak of roughly US$17B to US$7–9B, a genuine halving (TechCrunch, 08-17). In the same month OpenAI's annualised revenue crossed US$40B, with a single-month July increment above US$6.6B, three times the monthly average of the preceding seven (PYMNTS, 08-17). ⚠️ Every figure here is an annualised run rate rather than recognised revenue, and the companies do not necessarily compute it on the same basis; subtract two numbers built on different bases to get an "increment" and the subtraction itself manufactures plateaus and cliffs.
Judgment update: that comforting line is a statement about who decides, not a forecast about supply, and telling the two apart comes down to two numbers a buyer can see directly: the model's list price, and how much one account is allowed to use. In a withdrawal world, price rises and limits tighten. In a soft-demand world, price falls and limits loosen. Everything on the record from February to August 2026 sits on the second side. On February 7 a flagship revision shipped and the price per million tokens — the text unit models bill in — went from US$15/US$75 to US$5/US$25, down to a third. On May 6 Anthropic signed for the entire capacity of one data centre, live that same month, and on the same day permanently doubled the five-hour allowance on Claude Code, its own AI coding tool, and dropped peak-hour throttling (Anthropic's announcement, 05-06). Not one entry on that list falls on the withdrawal side. The single large-scale reallocation of compute happened on August 18, and the reason given was a safety incident, unrelated to return on investment (TIME, 08-18). If you are buying inference right now: the negotiating window is open, and there is no need to rush a long contract to lock a price.

Investor note: the prevailing narrative treats "AI keeps getting cheaper, application-layer margins keep improving" as a trend line you can write into a three-year base case. This evidence says it is a variable the seller re-decides every quarter — while also saying it is not being withdrawn right now. Unchanged for "model costs keep falling"; weaker for "a single revenue-growth number can detect supply being pulled back."
What would prove this wrong: any lab disclosing that its inference share fell from 40% to below 13% within four quarters, or a flagship list-price increase before the fourth quarter of 2026 together with a tightening of consumer-side limits over the same period — both at once, not either one — retires the threshold argument above. Verdict date: October 31, 2026 (the first quarterly re-check we set ourselves; if a company's listing documents or results land earlier, that date governs instead).
2. [Today] (announced August 28) An acquisition on its own can cost a company its model supply
OpenAI said on its blog on August 28 that it has notified SpaceX it will terminate the supply of OpenAI models to Cursor, with a planned shut-off date of November 12, 2026 (OpenAI's announcement, 08-28; Bloomberg's independent report, 08-29). Cursor is one of the leading AI coding tools and has until now been able to draw on several frontier models at once. And Cursor did nothing wrong. The mechanism sits in the contract: "Our custom agreement with Cursor gives us a limited time window to cancel it after a change of control."
What a change-of-control clause is: the contract provides that if control of one party shifts — an acquisition, a change of majority shareholder — the other party may terminate within a defined period. It does not require anyone to breach anything; the acquisition itself is the trigger, which is the fundamental difference from termination for cause. Cursor was bought by SpaceX, and X and xAI now sit under SpaceX as well. OpenAI says it cannot be confident SpaceX will use its technology within the bounds of the terms of service, and cites two precedents: Twitter violating its agreements after being acquired, and Musk's sworn testimony in April this year admitting xAI had violated OpenAI's terms of service (Forbes, 04-30).
Verification: the announcement is a primary document, the clause can be checked word for word, and Bloomberg's independent report the following day confirms the announcement exists. But two layers have to be kept apart. That this route works is now established — the clause exists and has been exercised once. That SpaceX will not honour the terms of service is OpenAI's assertion, not a fact — this announcement comes from a commercial rival with live litigation in the background, and a party's own account of its motive cannot be adopted as a neutral finding. ⚠️ The boundary that matters more: the announcement itself calls this a "custom agreement," so there is no second example establishing that frontier-model distribution contracts generally carry a clause like this, and that is the part of this item most likely to fail. ⚠️ How much damage Cursor actually takes, and how smoothly it can switch to other models, has no reading today, and we are not estimating it.
Judgment update: the nature of model supply has changed. The application layer used to treat it as procurement: I pay, you serve tokens, price and service level are the variables. It now has to be treated as a licence carrying a condition about who owns you — the contract is in your name, but its survival depends on your shareholders. The direct consequence is that application-layer acquisition pricing needs a line item that has been broadly missing: who the buyer is decides whether the target still has anything to sell once the deal closes. One thing you can do today: pull the change-of-control clause out of every model supplier contract and set it out on its own — whether it exists, how long the window runs, how long the notice period is — and ask the supplier at the term-sheet stage whether it would exercise, rather than finding out after closing. Read this with item 1: item 1 is about the allocation decision, whether to sell at all; this one is about the licensing decision, who to sell to. Two faces of the same power — and this face leaves evidence in black and white, harder than anything said in an interview.
Investor note: buyers have been treating frontier model supply as a neutral channel where only the price moves. What this announcement shows is that the channel can be withdrawn, and that the right to withdraw is tied to the identity of the counterparty. That weakens the assumption that application-layer companies dependent on frontier models carry a valuation discount only for margin compression — contingent interruption of supply is a separate discount item. What would prove this wrong: OpenAI reverses or delays the decision, or it turns out clauses like this are not common and this is a one-off.
3. [Today] (reported August 28) About 88% of that US$51B-plus in contracted revenue traces to a single customer
Our August 22 issue covered Nscale: a British AI compute landlord with no legacy cloud business to throw off steady cash, aiming to list in the US as early as September 2026, telling investors before the listing that it holds more than US$51B in contracted revenue — while what it actually has plugged in and running is 25,000 GPUs. What today's reporting adds is the identity of the denominator. The tech outlet The Next Web wrote on August 28 that the roughly US$45B six-year compute lease between Anthropic and Nscale is "the largest single entry in that column," meaning it is already counted inside that US$51B rather than added to it (The Next Web, 08-28). US$45B divided by US$51B is 88.2%. ⚠️ That ratio is our own arithmetic on figures from two different reports, not a customer-concentration number either party disclosed — numerator and denominator come from separate source chains.
We covered the lease itself in our August 28 issue: 460MW, six years, in West Virginia, running NVIDIA's Vera Rubin generation, which has not shipped, with an expected go-live at the end of 2027 (CNBC, 08-26). Which means not one chip of the compute behind that US$45B has been delivered. Today's piece also puts something on the table that had not surfaced before: Microsoft signed a letter of intent for that site in March and walked away over the summer. Anthropic is the replacement tenant, and no reason for the exit has been made public.
Verification: the two numbers are measured on different rulers, and separating them is the easiest thing in this item to get wrong. On how the US$51B is recognised, the original is explicit — "future revenue that counts in full the moment a deal is signed," not recognised across periods. It is not the expected value of money arriving over six years; it is six years of contract value booked in one go. What actually came in over the same stretch is about US$100M in a quarter (roughly US$37M the quarter before). Set a six-year commitment beside three months of receipts and any multiple you divide out of them means nothing. ⚠️ Two honest boundaries: our route to that US$51B figure is a semiconductor and AI infrastructure analyst relaying Bloomberg's August 6 report on social media rather than Bloomberg's own piece (the post, 08-06); and Microsoft's reason for leaving is not public, so it must not be read as a bearish signal — it may be nothing more than a change in its own capacity planning.
Judgment update: the phrase "contracted revenue" makes people assume there is diversified market demand behind it. This one says it can be a single customer. Whenever a compute landlord quotes contracted revenue of US$X, there is now one more question to ask: how many customers are in that denominator? And one thing that matters for weighing that 88% is entirely unknown today — how much of the US$51B is a hard commitment that gets paid whether or not the capacity is used, and how much is optional capacity paid for only on use. No public report breaks it out. The listing documents are the only plausible unlock: a US prospectus normally carries a section on customers accounting for more than 10% of revenue, which would settle this outright and may disclose the hard-commitment share alongside it.
Investor note: the prevailing narrative reads the scale of contracted revenue as proof of demand visibility. This evidence says the quality of that number has to be split into two columns — customer concentration and the share that is a hard commitment. That weakens the assumption that contracted revenue at scale equals confirmed demand. What would prove this wrong: the listing documents disclose customer concentration well below 88%, or disclose that the US$45B was never counted inside that US$51B.
4. [This week] (reported August 27) Two NVIDIA vendor-financing instruments went opposite ways in ten days, and the dividing line is neither size nor risk
The Wall Street Journal reported on August 27 that NVIDIA has paused some deals under the GPU cloud "revenue sharing" scheme it launched only in July, and that the people who first flagged antitrust exposure were NVIDIA's own staff rather than an outside regulator (carried by Yahoo Finance, 08-27). The same report discloses three contract terms for the first time. Cloud operators "had to vet customers through an approval process." NVIDIA "wanted utilization spread across multiple smaller AI firms instead of concentrated with one large buyer." And the two sides first agree an hourly base rate covering the operator's costs, with NVIDIA taking half of the revenue above that line. The operators' objection was precise: choosing their own customers should still be their call.
The control group is ten days earlier. Our August 18 issue covered NVIDIA writing itself into a statutory filing on August 17 as the residual-value guarantor of an OpenAI campus lease in Ohio, with cumulative payment obligations capped at US$105B (SEC filing, 08-17). What changes the picture is what you see once you set the two side by side. A residual-value guarantee does exactly one thing: if the tenant defaults and both re-letting and sale fail, NVIDIA covers the gap between the guaranteed minimum value and what is actually recovered. It absorbs risk and it directs nobody. The paused instrument is a different animal: it asks NVIDIA to approve someone else's customers and to decide whose hands capacity lands in. Putting up money to carry demand risk raises no antitrust question by itself; an upstream firm with a dominant position deciding where downstream capacity goes looks, in competition law, like market allocation.
Verification: the evidence at the two ends is very unevenly weighted, and that has to be said first. The residual-value guarantee is a statutory filing signed by the chief financial officer, carrying legal liability. The pause rests on a single anonymously sourced reporting chain, and the party involved has denied it on the record — NVIDIA told the trade outlet Data Center Dynamics that the scheme "is still in place and continues to evolve due to high demand" (the report, 08-28). So "antitrust exposure decides the shape of the instrument" is our inference, not a statement by NVIDIA or by any regulator. ⚠️ Two definitions also have to be kept in mind: the report says paused, not cancelled, and says the scheme may be reworked or folded into another; and US$105B is a ceiling, not an expected loss, with the gap between the two unknowable until the exhibits to the next quarterly filing appear. ⚠️ Two alternative explanations cannot be ruled out: the retreat may be nothing more than operator pushback slowing the signing pipeline, or a capital-allocation adjustment after the quarter.
Judgment update: vendor financing — a chipmaker putting up money or credit to support the customers buying its chips — is not itself constrained by antitrust law. Trading it for a say over who the downstream customers are is. The visible consequence: in the same week, NVIDIA's full-stack partnership with its largest customer expanded as usual, with no customer-approval clause attached (see Chips & semiconductors below) — support concentrating on the largest counterparty, exactly the reverse of what that scheme said it was for. Read this with item 3: over the same period two frontier labs both anchored long contracts to a chip generation that has not shipped, and the difference is who carries the residual risk. The Ohio site has NVIDIA's name on a guarantee. The public record on the West Virginia one shows no third party backstopping anything.
Investor note: in July the market priced "NVIDIA stands behind it" as a general credit enhancement. What this pause shows is that it is not general. That weakens the read on supplier support available to smaller compute landlords and strengthens the read on the terms the largest customers obtain. What would prove this wrong: NVIDIA restores the scheme with the approval clause intact and actually signs new deals under it, or the residual-value guarantee runs into the same kind of resistance.
Also happened — not verified by us yet
- [This week] (reported August 27) The US administration is considering widening semiconductor tariffs from chips themselves to finished goods containing chips, possibly including data centre servers; the report says this is still at an early stage, and a White House spokesperson would not confirm that servers are covered. Two things to hold on to: tariffs are paid by the importer, not the exporter, so the payer is whoever buys the server; and the next event to watch is an executive order or a Section 232 investigation document landing, not any trade association's loss estimate (Data Center Dynamics relaying Politico, 08-28). Section 232 is the provision of the US Trade Expansion Act of 1962 that lets the president impose tariffs on national-security grounds.
Chips & semiconductors
[Tracking update] (announced August 27) AWS is building its own silicon and buying more NVIDIA at the same time — and this round it plugged its own component into NVIDIA's interconnect.
Our August 28 issue noted in the "Also happened" section that AWS committed to deploying another 2 million NVIDIA GPUs across 2027 and 2028. What needs adding today is the other half of that joint announcement: it is not just buying cards. The partnership also extends to NVIDIA's Vera CPU (the CPU half of the Vera Rubin generation, the same not-yet-shipped generation the Nscale lease in item 3 is built on), plugs AWS's own custom high-bandwidth memory into NVIDIA's NVLink Fusion, brings NVIDIA's open-weight Nemotron model family onto AWS, and puts NVIDIA's robotics AI platform into Amazon's warehouse robots (Data Center Dynamics, 08-27). NVLink Fusion is the high-speed interconnect that lets many chips compute as though they were one.
⚠️ Three definitions first. This is a commitment, not a delivery — the 2 million is a two-year total with no annual split, while the comparison base of "more than 1 million in 2026" is a single-year figure. Different populations, so you cannot divide one by the other and announce a multiple. No value, payment terms or cancellation terms were disclosed either, so none of this can be used to model NVIDIA's revenue. And both sides have an incentive to inflate a headline quantity.
What this means for you: AWS has been building Trainium, its own AI training chip, for years, and the market has read that line as a transitional arrangement on the way to replacing NVIDIA. Plugging your own component into the other side's interconnect ecosystem is a deeper commitment than buying cards, and it runs the opposite way to replacement: the doubling-down has moved off the purchase order and into the architecture. An anchor you can watch yourself: in the next announcement, whether AWS's own components move one step further into NVIDIA's interconnect ecosystem, or start growing a stack of their own.
Named commentary
No named commentary this issue. On the named-speaker line we came away with nothing usable today. Transcripts from eight podcast feeds were blocked on their usual route — Ben Thompson's Sharp Tech, 20VC, All-In, a16z, Google DeepMind's show, Acquired, Cognitive Revolution and Gooaye — and only the Gooaye episode was recovered through speech-to-text. The one named analyst we did have material from is Dylan Patel, and that interview is precisely what item 1 of the main line is checking.
Model watch
[This week] (paper posted August 2026) Someone has demonstrated how to plant a backdoor through the memory layer while a model is in the middle of answering a question.
Four researchers at Northeastern University, a research university in Boston, posted a paper called ROBBIN to the arXiv preprint server in August (the paper, August 2026; we came to it through a summary published by the semiconductor trade outlet Semiconductor Engineering on August 29, the summary, 08-29).
First, what Rowhammer is: a memory attack technique known for more than a decade. Hammering one row of memory at high speed flips bits in the physically adjacent rows, which means changing someone else's data in a place you have no permission to touch. What is new here is the order of operations. The usual approach designs a hardware-agnostic backdoor first, then works out how to realise it with bit flips, treating the flips that land badly as a side effect. This paper inverts that: it first measures where the target memory flips, then uses that map to decide which pages the model weights sit on. The abstract treats every flip as "an integral part of the attack design," and the authors claim the backdoor built this way holds up across devices.
⚠️ The honest boundaries in full: this is a preprint with no peer review; we read the abstract only, not the full paper, and have seen no independent replication; and the two abbreviations in the abstract — ASR and TA, which in this literature usually mean attack success rate and normal-task accuracy — carry no numbers at all, so how well this actually works has no answer today.
What this means for you: one more question when you buy inference capacity — who shares memory with the GPUs you are renting. An anchor you can watch yourself: whether a second team reproduces the result on different hardware. Until someone does, this is a demonstration of what is possible, not a risk known to be occurring in the wild.
Product moves
No product news this issue. Last night's sweep turned up five new pieces on the product-company side, and the only one carrying any judgment — OpenAI's decision on Cursor — is already item 2 of the main line. The other four were feature explainers for existing products, a customer case study, a developer tooling release and an ecosystem partnership announcement: two from Databricks, one from NVIDIA, one from OpenAI. Under our own rule of taking only new developments or changes of direction, none of them makes a section.
From the archive
No archive pick this issue. We have used up the older material worth reusing from our own back catalogue; the last pick ran on July 30, and this is the tenth consecutive issue with the column empty. We would rather leave it blank than replay an item we have already run.
Sources & accounting
The past 24 hours. Two sweeps, last night and this morning, took in 224 pieces: 127 social posts, 50 selected papers, 22 industry news pieces, 8 company blog posts, 8 newsletters and personal blogs, 7 podcast transcripts, 1 company filing and 1 paper retrieved on a retry. The names: Data Center Dynamics, Semiconductor Engineering, Latent Space, Newcomer, Marcus on AI, Don't Worry About the Vase, Simon Willison, Alignment Forum, and Stratechery (a paid subscription — we describe direction only and quote nothing). On company filings we swept 27 companies in the SEC's public database, and only Marvell had anything new. On the social side we reached 374 X accounts, 14 of which we could not verify. Five pieces were read all the way through and judged by hand today, two of them August 27 material that only came up a day later: the Anthropic–Nscale lease and the AWS–NVIDIA announcement.
What you are not getting today. First and most important: the overnight run on August 28 stopped halfway through. The back half of that night — podcasts, company filings, social posts — never ran, and was only completed early on August 29, so this issue's material is two sweeps combined. That is where the two pieces handled a day late came from. Second: OpenAI's blog and Qualcomm's investor relations feed both blocked our retrieval today, returning 403. Fortunately the Cursor announcement quoted here was obtained in full on August 28, so the verbatim quotes were checked against the full text rather than reconstructed from a headline. Third: transcripts from eight podcast feeds were blocked today — the list is in Named commentary above — and one further show took a third-party proxy to yield five episodes. Fourth: no new papers arrived on either night, so "no new academic material today" is a fact rather than something we failed to look for. Older material added by hand: none today.
Source concentration. Three things we have to say about ourselves. One, three of the seven units a reader sees today use Data Center Dynamics as the retrieval vehicle — over 40%, above our one-third warning line, so our own rule says to state it plainly. Two, in two of those three it is only the relay and not the origin: item 4 of the main line originates with the Wall Street Journal, and the item in "Also happened" with Politico, the US outlet that covers the White House and trade policy. Traced back to origin, today's sources are in fact spread out. Three, exactly one item rests on a single source: the AWS–NVIDIA announcement of 2 million GPUs, with no second reporting chain. One more thing worth saying: our route to Nscale's US$51B-plus figure is a relayed social post rather than Bloomberg's own piece, and half the denominator of that 88% comes from there.
The sources we track. After de-duplication the roster covers 529 sources; a separate ledger organised by channel holds 722 records: 302 X accounts, 90 podcasts, 77 institutional and company blogs, 51 outlets and press rooms, 48 personal blogs, 48 paper authors, 46 newsletters, and 60 others covering earnings calls, keynotes, books and government documents. One person may hold an X account, have appeared on a podcast and have published a paper, and gets counted three times: 722 counts records, 529 counts sources after de-duplication, and the two do not add together. The same applies to last night's 374 X accounts reached, which is not the 302 X sources on the roster: the first is how many accounts actually returned data that night, the second is what we track over time. Newsletters work the same way — the few read last night are a daily quantity, the 46 on the roster are the total. Four readings, four different populations: this issue uses 20 receipts in the body, last night and this morning added 224 pieces, the roster holds 529 sources after de-duplication, and the channel ledger holds 722 source records.
I finished today's issue / I didn't finish
This is not a news digest: we hunt each day's AI firehose for the insights that actually matter and the practitioner judgments worth tracking over time, and we show how every item was verified — the point is always "which judgment got harder, and who's been right," never "what happened today."
— SecondSource · generated by our research system · 20 sources · Got a view? Reply and tell us
Written from the same research and judgments as the Traditional Chinese edition; every claim links to a primary document.
SecondSource publishes industry analysis, not investment advice. We do not evaluate, rate, or recommend any specific security, and nothing here should be treated as financial guidance — verify independently and use your own judgment.
EN English edition|繁 中文版 Traditional Chinese →