When a supplier puts its own balance sheet behind the building its customer lives in, and then sells the goods inside that building, we’re no longer looking at a normal investment cycle.
Let me be straight about this: when a supplier puts its own balance sheet behind the building its customer lives in, and then sells that customer the goods inside that same building, we’re no longer looking at a normal investment cycle. We’re looking at a circuit that feeds itself.
On Monday OpenAI, SB Energy and Nvidia closed the deal on the PORTS-Pike campus in Ohio: roughly eight IT gigawatts over a twenty-year lease, nine buildings, the first 800 megawatts in 2028, built on the site of a decommissioned uranium enrichment plant. Nvidia puts a billion and a half of equity into SB Energy, guarantees a minimum value of 105 billion dollars on the campus, and will sell GPUs and systems to OpenAI as each phase completes.
I’ve spent twenty years reading the accounts of companies far smaller than these, and the rule I learned the expensive way is always the same: when risk leaves the balance sheet it doesn’t disappear, it just changes address.
I learned this rule on a scale a thousand times smaller, watching a supplier stretch my payment terms with a generosity that at the time looked like friendliness and was in fact his way of keeping me hooked. It took me two years to work it out, and in the meantime I’d even gone round describing it as a negotiating win.
Except this time, and this is where the whole argument starts, we know the address.
The number we were told wrong
Almost everyone wrote that Nvidia is guaranteeing 105 billion of lease payments on OpenAI’s behalf. That isn’t the case, and the difference matters.
I know because the article you’re reading, in its first draft, opened with exactly that wrong sentence. I was extremely pleased with myself. Then I opened the rating note and discovered I’d built three paragraphs on a number that didn’t mean what I thought it meant, which is an elegant way of saying I was about to publish something inaccurate with great confidence.
It’s a residual value guarantee: Nvidia guarantees the owner that the property will be worth at least a certain figure, not that it will pay the rent in the tenant’s place. It takes effect building by building, as each of the nine structures reaches operational conditions, between 2028 and 2030.
And S&P, which on 18 August confirmed Nvidia’s AA rating in relation to this very transaction, has already measured that risk: a debt adjustment of 4.2 billion in 2028, rising to around 37.7 billion in 2031, then declining on a predetermined schedule. The method is stated: the difference between the guaranteed minimum value and the recovery value of the property, estimated with commercial real estate methodology and taxed at 21%.
Thirty-seven billion at peak, against an EBITDA that on the same agency’s estimates runs between 271 and 491 billion in those years, and against 106 billion in cash and marketable securities versus 33.5 billion of funded debt. Outlook stable.
There’s more. At the end of July the guarantee under discussion was around 250 billion. By 14 August it had already fallen below 120, after investors raised doubts about the exposure. At signing the number was 105. A hundred and forty-five billion evaporated in three weeks.
So the first conclusion, the uncomfortable one for anyone who loves the bubble story: here the market braked, an independent agency measured, and the resulting number is manageable.
Hold on to this sentence, because it’s the key to everything that follows: the dangerous risk is never the measured one.
Where nobody looked
Nine large tech companies carry around 3 trillion dollars off balance sheet. That’s 1.9 trillion of purchase commitments plus 1.2 trillion of leases not yet commenced: technically it isn’t debt, because the supply hasn’t started. Alphabet alone reported 811 billion as of 30 June, up 152% in a single quarter.
No agency has done on this mountain the work S&P did on Nvidia’s 105 billion. Nobody has said: here’s the difference between the notional and the expected loss, here’s the schedule, here’s the underlying asset and what it’s worth if you have to resell it.
And the number that worries me isn’t the absolute figure, it’s its derivative: a month earlier the estimate was around half that, across five companies instead of nine. When the measurement of a risk doubles in thirty days, the problem isn’t the risk itself. It’s that nobody yet knows how big it is.
Ray Dalio has explained the mechanism with disarming simplicity. You buy a share at a hundred, you borrow against it, and as long as the price rises it all looks brilliant. Then the market turns, everyone needs cash at the same moment, the price goes to twenty-five and the debt sits there, intact, waiting to be repaid. He compares this dynamic, as mechanics rather than prophecy, to 1929 and 2000, and sums it up in a sentence that has stayed with me: wealth is not the same thing as money.
The point of the bubble, then, was never the most visible transaction. It’s the trillions nobody has yet translated into expected loss, and that stand up only as long as the exponential narrative holds.
But wasn’t OpenAI supposed to list before Anthropic?
In June OpenAI signalled it would postpone its listing to 2027. The reason isn’t philosophical: SpaceX had listed a few weeks earlier in the largest debut in history, and the stock had gone from over 225 dollars to 103 in a handful of days. The advisors put Altman in front of the fork in the road, and he called any cut to the trillion a “nonstarter”.
Anthropic is running in the opposite direction: annualised run rate at 65 billion at the end of July, up from 47 in May and from 9 at the end of 2025, with investors who according to the Financial Times expect an October listing at around 2 trillion. The same company was worth 183 billion eleven months ago.
When the central actor in a sector would rather stay private than have a price put on it, that silence is worth more than ten optimistic reports. And when another runs to list at a valuation up tenfold in a year, the right question isn’t which of the two is right, but what happens to the castle if the first serious public verdict goes badly.
Anthropic, the brake nobody can afford
Here comes the dot almost nobody connects to the others, and it’s the one that holds the picture together.
On 14 August Anthropic published its second corporate Risk Report, 186 pages. Inside is the disclosure of an internal model, called Model 2, which the company describes as more capable than its own flagship public model and which it states it has no plans to release. There’s also a technical detail that went almost unnoticed: the benchmark built internally to detect crossing the most dangerous capability threshold has saturated, meaning it no longer registers incremental improvements, precisely as the company says it is seeing the first signs of the acceleration that instrument was meant to catch. In the same document the rating for catastrophic misalignment risk rises from “very low” to “low”.
Let’s take it for what it is, without inflating it: a company keeping in the safe a capability it could sell is the exact opposite of a blind race. It’s a real brake, pressed voluntarily. And it isn’t isolated: in mid-August a Chinese lab released a model while holding back the open weights for two weeks, pending a safety review related to vulnerability discovery capability. A first, in those parts.
But here’s the paradox, and it’s the identical paradox of the 105 billion. Anthropic brakes while preparing to list at 2 trillion on a growth narrative of seven times in seven months. How long can a listed company afford to leave monetisable capability on the table, with public shareholders asking every quarter why the competitor is growing faster?
Daniel Kokotajlo, the former researcher who in 2024 left OpenAI, giving up around two million dollars of equity rather than sign a non-disparagement agreement, calls the worst path in his “AI 2027” scenario Plan D: no serious regulation, maximum speed. His public estimate puts roughly 70% probability on a catastrophic outcome along that trajectory. It’s a subjective probability, not a measurement, and it should be treated as an argument rather than a number. But the argument holds: slowing down to do safety means slowing down growth, and slowing down growth means putting at risk trillions of commitments that stand up only as long as the narrative doesn’t crack.
The technological brake and the financial one are the same pedal.
The dots connected
Here’s what emerges when you put the pieces together, and it isn’t the story I had in my head when I started writing.
Where risk is visible, the system works: investors cut a guarantee from 250 to 105 billion in three weeks, S&P measured it at 37.7 at peak and confirmed the rating, Anthropic kept a model in-house and wrote it down in a public document. Those are all real brakes.
The problem is that these brakes work one at a time, on things somebody has looked at. They don’t exist on 3 trillion of commitments nobody has yet turned into numbers, and they don’t exist on the structural incentive telling every player to run faster than the one next to them.
It looks to me like a car accelerating while weaving between obstacles that keep getting closer, with brakes that work beautifully on every single bend the driver sees coming. The walls it doesn’t see are three: Chinese open-weight models at a fraction of the cost, which if they prove you don’t need trillions of capex blow up the premise in an afternoon; an abrupt regulatory intervention, and this summer a temporary export control on Anthropic was enough to slow its revenue for a month; and the moment somebody has to show real margins on real revenue, a verdict that arrives all in a single day.
And the risk, at this point, isn’t working out which obstacle arrives first. It’s that when it does, the speed will be such that it hits nearly all of them at once.
So what do we do with all this
I don’t have a guru’s answer, and anyone who does probably hasn’t understood the question.
But I did take one operational lesson from this story, and it’s more useful than any forecast: before you get frightened by a big number, ask whether somebody with skin in the game has already priced it. On Nvidia the answer was yes, and the real risk was a third of the headline. On the 3 trillion the answer is no, and that’s where you should be looking. The notional is never the loss, and the difference between the two is where you win or lose.
The good part is that I’ve been teaching this lesson to others for years in due diligence, and I was the first to miss it myself, on a newspaper headline.
Michael Saylor, in his 6 August interview, described designing with ChatGPT a novel financial instrument with which he raised around 15 billion when the traditional routes were exhausted, and his summary is “don’t try to work harder than the robots”: ask the AI to do something that has never been done, instead of competing on repetitive tasks. Coming from someone who in the same period is sitting on a Bitcoin position with billions in unrealised losses, it should be taken for what it is: a method, not a gospel.
Seth Godin says instead that AI will reward the most human people. Not the fastest, not the most productive. The most human. While the financial machine accelerates, the one thing you can’t lever up is judgement, relationships, the taste to choose well. And the willingness to open the original document before forming an opinion, I’d add, which isn’t a technical skill but a form of respect for whoever is reading you.
I’ve spent more time than I’d like to admit chasing speed, convinced it was the decisive variable. The few times I genuinely made a difference were when I slowed down enough to understand where I was going.
I don’t think the ending of this story is written, and I don’t think it’s necessarily a bad one either: bubbles burn capital but leave the infrastructure standing. The British railway mania of the nineteenth century ruined thousands of investors and gave England the tracks it ran on for a century.
In the meantime, the only speed you genuinely control is your own. Use it well.