Clarity · Edition

The Board Room

Wednesday, July 22, 202628 sources · 7 min read

The Signal

Sequoia and Thrive are now funding nuclear reactors to power AI.

Power, not chips, is shaping up as the binding constraint. Valar is raising at roughly $5B pre-money, and Thrive marked Helion at $15B, nearly triple its January valuation. A reasonable skeptic will note that a fusion mark measures sentiment, not megawatts, and the skeptic is right. That does not change the timing: off-take and co-location conversations are worth having this quarter, because once the tier-1 buyers start them, they set the terms.

Key intelligence

  1. 01

    Power Becomes the AI Chokepoint

    Sequoia and Thrive — never before funders of decade-payback deep tech — are bidding on fission/fusion startups at $5B–$15B. A July DOE chain-reaction milestone made Aalo, Valar, and Antares fundable in one cycle. PJM's emergency grid measures confirm electrons, not just chips, now gate scaling.

  2. 02

    The Silicon Layer Reprices While It Fragments

    TSMC confirmed base hikes up to 10% plus a 10–15% HPC premium — ~25% higher bills by 2027 — as ASML raised 10% on multi-year demand. Meanwhile Etched poached 400+ NVIDIA/TSMC engineers with $1B pre-launch demand, Taiwan raided Supermicro across nine sites, and AMD's Helios landed Microsoft, Meta, OpenAI, and Oracle.

  3. 03

    Agentic AI: Attack Vector and Defense Category at Once

    ENCFORGE ransomware was built to encrypt ~180 AI/ML model-weight extensions — assets with no clean restore path. Pillar Security found Cursor, Codex, Gemini CLI, and Antigravity share one sandbox-escape class: a category-wide immature trust model. Six defensive AI-security tools shipped the same cycle.

  4. 04

    Vendor Concentration Spikes as Models Commoditize

    SpaceX reportedly turned its $1.75T IPO into a $60B Cursor buy, arming xAI in the coding wars, as ChatGPT's share fell below 50%. Meanwhile Alibaba-backed Kimi K3 (reported 2.8T params, $3/$15 per M tokens) is claimed to beat Claude Fable 5 and GPT-5.6 Sol on Frontend Arena — model leadership is a recurring event, not a moat.

Deep dives

  1. 01

    Power, Not Chips: VCs Just Repriced the Next AI Chokepoint

    A July DOE fission milestone made three reactor startups fundable in one cycle — and the public-market skepticism nobody's pricing is the tell to use.

    In July 2026, Aalo Atomics, Valar Atomics, and Antares Nuclear each independently demonstrated a self-perpetuating fission chain reaction. Three simultaneous validations converted three startups into fundable entities inside one news cycle. Capital is moving now, ahead of any commercial-scale delivery, because the proof point arrived, not because the pitch improved.

    The names doing the funding matter more than the dollars. Sequoia is in talks to lead a $1B round for Valar at roughly $5B pre-money. Thrive Capital, an OpenAI backer, is reportedly marking Helion at $15B pre-money, a figure newsletters put at nearly triple its January mark, though the earlier number is not independently confirmed. Neither firm has any history of underwriting capital-intensive deep tech with decade-long paybacks. When crossover funds start bidding on reactors, the working thesis is that dedicated power, not compute, becomes the binding constraint on data-center expansion. PJM's emergency grid measures and regulator pressure on data-center interconnects corroborate the scarcity from the operator side.

    The divergence worth trusting

    Public markets are pricing the opposite story, and the disagreement deserves attention rather than dismissal. Oklo is down roughly 40% year to date even as private nuclear marks reportedly triple in months. Public investors are discounting the multi-year gap between technical milestone and commercial power delivery; private rounds are treating that gap as solved. Oklo's drawdown is the useful instrument here, serving as a live risk dashboard and a valuation-discipline anchor for any term sheet.

    One layer up, Mercor's arc is the sharpest reminder of concentration risk in this supply chain: $10M to $614M in gross revenue in two years, almost entirely from OpenAI and Anthropic. The same underwriting question applies to any long-term power off-take partner, namely what happens to the counterparty if a hyperscaler switches or builds in-house. That answer decides whether the off-take is an asset or a liability.

    When Sequoia and Thrive fund reactors instead of software, power supply has taken the position compute held in 2023 as the input the market is bidding up.

    The tradeoff worth naming: this is not a case for building reactors. It is a case that firms with the cheapest early access to dedicated generation will hold a structural advantage. Entering the diligence pipeline costs less before momentum pricing fully sets, which makes this a decision about paying diligence costs this quarter or momentum prices in the quarters after.

    What to do

    1. Open exploratory co-location or power off-take talks with at least one earlier-mover fission startup (Aalo or Antares, under less bidding pressure than Valar) this quarter, before Sequoia-level pricing sets in.

      This quarterEarly access to dedicated power is the emerging structural advantage; conversations cost little before momentum pricing hardens.
    2. Commission a build-vs-partner-vs-wait analysis on dedicated on-site power generation as a named FY line item, using Oklo's ~40% drawdown as the valuation-discipline benchmark.

      This quarterIf power is the binding constraint, securing supply early is a multi-year moat; public-market skepticism protects against overpaying.
  2. 02

    Your 2027 AI Budget Is Already Stale: TSMC +25% Meets a Model Price War

    Running AI gets cheaper while building it gets structurally more expensive — that gap is where next year's margin surprise hides.

    Two cost curves moved in opposite directions this cycle, and most three-year plans still treat them as one curve. On the model layer, Google shipped Gemini 3.6 Flash using 17% fewer output tokens at $1.50/$7.50 per million, a genuine deflationary push on agent inference. Underneath it, TSMC confirmed base price hikes of up to 10% plus a 10–15% HPC premium starting early 2027, which pushes some bills up roughly 25%. ASML raised prices 10%. Both cited demand described as 'very strong' for years, not quarters. Any cost model built on continuous deflation is now out of date at exactly the layer the deflation runs on.

    The supply side is in open turmoil

    A reasonable skeptic would note that the incumbent has outlasted challengers before, and the skeptic has history on their side. What the skeptic has to explain away is three fronts moving at once, each different in kind. Etched pulled 400+ engineers from NVIDIA and TSMC and holds $1B in pre-launch demand, which is a credible signal rather than vaporware. Taiwan authorities raided Supermicro and two supply-chain partners across nine sites and summoned six people in a widening probe, an active enforcement risk with real delivery-timeline consequences. And AMD's Helios rack system launched with Microsoft, Meta, OpenAI, and Oracle named. That is the first time hyperscalers have backed an NVIDIA alternative with production-scale intent.

    DimensionIncumbent (NVIDIA + closed models)Challengers (Etched / AMD / open)
    Talent flowLosing senior engineers400+ ex-NVIDIA/TSMC hires
    Supply exposureActive Taiwan enforcement riskNewer channels, less exposure
    Cost trajectoryPremium, TSMC-inflatedCheaper by design

    The board-deck version of this story says inference is getting cheaper, so agent economics improve. The complete version is the netting exercise, and the netting is the actual work: model-layer savings are real, but they are being fought for on top of a hardware layer that is getting structurally more expensive. The tradeoff is now explicit. Single-vendor infrastructure buys simplicity at the price of concentration risk, and that price has moved from an IT decision to a board-level one. The vendor commitments made this quarter set the terms of the netting for the next two years.

    AI is getting cheaper to run and more expensive to build. The gap between those two curves is where the next margin surprise is hiding.

    What to do

    1. Re-underwrite the 2026–2028 AI infrastructure cost model, netting Gemini/OpenAI token deflation against ~10% compounding annual hardware inflation, before procurement discovers the gap in Q1 2027.

      This quarterTSMC and ASML have signaled multi-year pricing power; a flat-cost model understates the compounding.
    2. Open a formal Etched/AMD Helios evaluation this quarter and audit any Supermicro-adjacent supply exposure tied to the Taiwan probe.

      NowThe credible alternative is negotiating leverage on NVIDIA terms regardless of whether you switch; the Taiwan raid is an active delivery-timeline risk.
  3. 03

    Ransomware Just Found an Asset With No Restore Path: Your Model Weights

    Past the Hugging Face breach: ENCFORGE targets weights that can't be rebuilt, and every major coding agent shares the same escape flaw.

    The genuinely new development this cycle isn't the breach that's been circulating — it's what attackers are now aiming at. ENCFORGE ransomware was purpose-built to encrypt ~180 AI/ML model-weight extensions. Unlike transactional data, weights and checkpoints often have no clean restore path — encrypt them and you lose capability, not just records. Paired with JADEPUFFER's autonomous credential-theft-to-ransomware chaining, the threat surface is now the model itself.

    This is a category flaw, not a vendor bug

    Pillar Security showed Cursor, OpenAI Codex, Google's Gemini CLI, and Antigravity all share the same sandbox-escape pattern: a prompt injection hidden in a README or dependency causes the agent to write a file a trusted tool later executes outside the sandbox. That's not four unrelated bugs — it's evidence the current generation of coding agents shares an immature trust model, whichever vendor built it. Feature velocity has outrun security architecture across the category, which means any agent procurement made on capability benchmarks alone is incomplete.

    The market is responding fast. Six credible defensive AI-security tools shipped in one cycle — from Anthropic, Datadog, Visa, Alpha-Omega, and evilsocket — and Google's orchestrated CodeMender pipeline found 55 V8 vulnerabilities versus 36 for Claude Opus 4.6, a signal that composite pipelines of specialized models beat single-frontier-model bets on real security work. Six overlapping entrants in one cycle means consolidation is near; evaluating now carries a leverage advantage that evaluating post-consolidation won't.

    Model weights are now a ransomware target that can't be restored — if you lack a distinct backup tier, you're one unpatched CVE from losing capability, not just data.

    None of this demands panic. It demands treating model weights and agent permissions as their own protected domain before an incident forces it.

    What to do

    1. Establish immutable, offline backup of proprietary model weights and checkpoints as a distinct DR tier from standard data backup this quarter.

      NowWeights have no clean restore path; conventional backup cadence isn't designed for assets that can't be reconstructed.
    2. Reframe AI coding-agent procurement as security-gated: require an architecture-level sandbox trust review, not a feature-parity check, given the category-wide escape flaw.

      This quarterThe vulnerability is the trust model itself, shared across Cursor/Codex/Gemini CLI/Antigravity — a version-number check misses it.
  4. 04

    SpaceX's $60B Cursor Buy Makes Vendor Concentration a Board Issue

    A rocket company reportedly weaponized its IPO to arm xAI in coding — the week the leader's chatbot share cracked below 50%.

    SpaceX's reported $1.75T IPO was followed by a $60B acquisition of Cursor — if the reporting holds, not a coding-tools story but a deliberate vertical-integration move to arm xAI with talent, data, and distribution against OpenAI and Anthropic. Read alongside ChatGPT's share falling below 50% while OpenAI reportedly loses billions annually, the era of single-vendor AI dominance is ending — replaced by aggressive consolidation on one side and fragmentation on the other.

    The commoditization underneath is the real accelerant. Alibaba-backed Kimi K3 (reported at 2.8T params, $3/$15 per M tokens) is claimed to beat Claude Fable 5 and GPT-5.6 Sol on the Frontend Arena benchmark — if the benchmark claim holds, evidence the capability gap between US and Chinese frontier labs is narrowing faster than most procurement cycles are built to notice. Switching costs that once locked enterprises into frontier providers are collapsing exactly as the reasons to want optionality multiply.

    Where the squeeze lands

    Production numbers add nuance: NiCE's telemetry shows Anthropic's Opus 4.7 takes 4+ seconds to first token and costs 18.5x more than Gemini 3 Flash on comparable real-time workloads — model selection is now a workload-specific decision, not a brand decision. And Atlassian is already weaponizing this, selling model-agnostic orchestration on data-sovereignty grounds: 'I don't want all my company's information going to Anthropic.' Every foundation lab moving up the stack into agent products will get squeezed by the SaaS incumbents it depends on for distribution.

    When a rocket company buys a $60B coding startup while the leader's chatbot share drops below 50%, vendor concentration is a board risk, not an engineering decision.

    What to do

    1. Map vendor concentration risk across dev tooling and model dependencies now — identify exactly where you're exposed to the SpaceX-Cursor-xAI stack or a single frontier provider before a forced migration lands on someone else's timeline.

      This quarterM&A consolidation plus incumbent financial strain means a forced roadmap change could arrive with little notice.
    2. Use OpenAI's disclosed losses and ChatGPT's share decline as explicit leverage in upcoming contract renegotiations rather than treating them as a viability panic.

      NowIncumbent weakness is a pricing window; the durable posture is a multi-model architecture, not a favorite-vendor bet.

From the editor's desk

Stories

  • Terry Smith abandons 16-year fundamentals discipline for momentum as passive tops 60% of AUM

    The quality investor conceded Fundsmith would 'eventually go out of business' without momentum, citing passive funds now over 60% of AUM and setting price on just 10% of active trades, down from 80% in the 1990s. He calls 33% daily large-cap swings 'not uncommon.'

    Why it mattersYour own stock is a less reliable signal of intrinsic value in every buyback, M&A-currency, and equity-comp decision it touches.

  • 12 state AGs freeze the $110B Paramount-WBD deal with a 14-day TRO

    A California federal judge issued a TRO blocking Paramount Skydance's $110B acquisition of Warner Bros. Discovery — triggered by a 12-state antitrust coalition, not a federal challenge.

    Why it mattersFederal-only antitrust review is no longer sufficient diligence; any pipeline deal above $1B now needs a state-level litigation model.

  • Only 17% of IT directors trust their AI initiatives deliver measurable results

    A Leebry survey found just 17% of IT directors trust most AI initiatives deliver measurable results; 27% can't measure impact at all — a board-level exposure most portfolios haven't surfaced.

    Why it mattersBeing in the 83% that can't prove AI value is now a named, quantified risk that surfaces at the next budget cycle whether you name it or not.

  • Raycast's Glaze lets users build Mac apps in plain English, targeting thin-UI SaaS

    Raycast layered Glaze on Claude Code and Codex atop a six-year, 3,000-extension moat; its CEO predicts 30-50% of Mac software could be self-made within three years. A $280B SaaS valuation wipeout hit in 48 hours this February.

    Why it mattersEvery SaaS renewal this quarter is now a build-vs-buy decision — subscriptions that are thin UI over commodity workflows are displacement targets.

  • North Korea is hiding malware in SVG 'coding challenges' during fake job interviews

    Elastic's Daniel Stepanic dissected an active, reportedly escalating state-sponsored campaign planting malware in SVG assets sent as coding-challenge material to job-seeking developers. An independent developer hit it firsthand.

    Why it mattersYour recruiting and technical-interview process is now an attack surface, not just an HR function — audit how candidate coding challenges are delivered and executed.

  • Roblox stitched three acqui-hires into an AI world-model moat in months

    Rather than build from scratch, Roblox acquired Morpheus AI (low-latency streaming), Lucid AI (creator-control harness), and Dynamics Lab (world generation), bolting them onto a 20-year engine and 27+ owned edge data centers running H200/B200 GPUs.

    Why it mattersThe reusable playbook: buy narrow deep-tech teams that solved one hard sub-problem to fill specific architecture gaps, rather than whole-product acquisitions or ground-up builds.

The Bottom Line

Stop optimizing the model layer everyone can now buy cheaply. This quarter, fund optionality in physical inputs — dedicated power and second-source silicon — and quarantine agent permissions and model weights as their own protected tier. That's the ground a rival can't commoditize and an incident can't reach.