Category: Technology

NeuralWired’s Technology section covers the developments reshaping how the world builds, deploys, and regulates digital innovation. We report daily on the stories driving global conversation in artificial intelligence, big technology companies, startups and venture funding, cybersecurity, consumer gadgets and devices, and blockchain and cryptocurrency.

Our technology coverage goes beyond product announcements. When a major AI model launches, we explain what it can actually do and where its claims are overstated. When a startup raises a large funding round, we look at whether the business behind it can sustain that valuation. When a cybersecurity breach hits the news, we explain who is affected and what comes next, not just what happened. Each article is built from original research into primary sources, including company statements, technical documentation, regulatory filings, and verified data, and is written by our editorial team rather than generated automatically.

Readers come to this section for daily updates on the technology stories that matter globally, from shifts inside major technology companies to emerging tools changing how people work, communicate, and build. Whether you are a founder, an investor, an engineer, or simply someone trying to understand where technology is heading next, NeuralWired’s Technology coverage is built to keep you informed without wasting your time on hype.

  • Qwen’s 3 Billion Downloads: The Real Number (2026)

    Qwen’s 3 Billion Downloads: The Real Number (2026)

    Qwen’s 3 Billion Download Claim vs. the Real Hugging Face Number
    Open Source AI · Data Report

    Qwen’s 3 Billion Downloads: What Hugging Face Actually Found

  • EU AI Act Article 50: Deepfake Law Takes Effect (2026)

    EU AI Act Article 50: Deepfake Law Takes Effect (2026)

    EU AI Act Article 50 Is Live: Who’s Exposed to the €15M Fine
    Policy · EU AI Act

    EU AI Act Article 50 Is Live: Who’s Actually Exposed Now

    Published August 16, 2026 · NeuralWired

    Two weeks ago, the label on every AI-generated image, chatbot reply, and deepfake video circulating in the EU stopped being optional. Article 50 of the EU AI Act became legally enforceable on August 2, 2026, and a lot of companies that thought the Digital Omnibus had bought them more time are finding out it didn’t. If your product touches EU users and generates or manipulates content with AI, you’re in scope today, not eventually.

    This isn’t a “rule is coming” story anymore. It’s a “the rule landed and here’s who’s exposed” story, and the gap between those two framings matters if you’re the one deciding what your compliance posture looks like this quarter.

    What Article 50 Actually Requires

    Article 50 of Regulation (EU) 2024/1689, the EU AI Act’s transparency provision, bundles four separate obligations under one article number. Treating them as one rule is the first mistake most compliance teams make.

    • 50(1), chatbot disclosure: If your AI system talks to people directly, they need to know it’s AI, unless that’s obvious to a reasonably informed person.
    • 50(2), output marking: Generative AI providers (image, audio, video, text) must mark their outputs in a machine-readable format so the content is detectable as artificial.
    • 50(3), biometric disclosure: Deployers of emotion-recognition or biometric-categorization systems must tell the people being scanned.
    • 50(4), deepfake and public-interest text disclosure: Anyone deploying AI that generates or manipulates a deepfake has to disclose it. AI-written text on matters of public interest needs disclosure too, unless a named human editor reviewed it.
    The legal definition of a deepfake, spelled out in Article 3(60), is broader than most people assume. It covers AI-generated or manipulated image, audio, or video content that resembles a real person, object, place, entity, or event and would falsely appear authentic. Per the Commission’s final Guidelines, intent doesn’t matter. If it looks or sounds real, it needs a label, even if nobody meant to deceive anyone with it.

    The exemptions are narrower than they sound. Law enforcement use is exempt. Clearly artistic, satirical, or fictional content gets reduced disclosure requirements, not zero. AI text with genuine human editorial review by a named responsible person is exempt. And “purely personal, non-professional” use is exempt, but the Commission’s draft Guidelines confirm it does not cover content that affects public discourse, such as a deepfake of a local politician shared to criticize policy, even from a private account.

    The Compressed Timeline That Caught Teams Off Guard

    Here’s why so many companies are behind: the rulebook itself was barely finished before enforcement started. The final Code of Practice on Transparency of AI-Generated Content wasn’t published until June 10, 2026. The Commission’s final Guidelines followed on July 20, 2026. That left regulated companies roughly two weeks between a finished rulebook and legal applicability on August 2.

    DateMilestone
    Dec 17, 2025First draft Code of Practice published
    Mar 3, 2026Second draft simplifies marking approach
    May 8, 2026Draft Guidelines open for consultation
    Jun 10, 2026Final Code of Practice published
    Jul 20, 2026Final Guidelines adopted
    Jul 24, 2026Google signs the Code of Practice
    Aug 2, 2026Article 50 becomes legally enforceable
    Dec 2, 2026Grace period ends for pre-existing systems’ marking duty
    One point of confusion is worth killing right now. The EU’s Digital Omnibus package pushed back high-risk AI system deadlines from 2026 to 2027 and 2028, and a lot of teams assumed that delay covered everything, including transparency rules. It didn’t. Article 50 was deliberately carved out and left on its original schedule, a distinction Gibson Dunn’s analysis of the Omnibus agreement flags as one many compliance teams conflated.

    There is exactly one grace period that survived, under Article 111(4): a four-month window, until December 2, 2026, and it applies only to the machine-readable marking requirement under 50(2), and only for generative systems that were already on the market before August 2. Anything you launch after August 2 gets no cushion at all.

    Penalties and Who’s Exposed

    Article 99 puts Article 50 violations in the mid-tier penalty band: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For scale, prohibited-practice violations under Article 5 top out at €35 million or 7%. SMEs and startups get the lower of the two figures rather than the higher one, which softens the blow but doesn’t remove it.

    The extraterritorial reach is the part US and UK companies tend to underweight. The rule applies to any provider or deployer anywhere in the world whose AI output reaches users inside the EU or EEA. No EU office required. If your chatbot, your ad creative, or your AI-generated blog post shows up in front of an EU user, you’re in scope.

    Liability sits with the deployer, not automatically with the AI tool vendor you’re using. There’s no automatic transfer of responsibility to whoever built the model. That means the compliance homework, auditing which of your image, video, voice, and chat vendors already embed provenance signals versus which strip them, falls on you.

    How Google, TikTok, and X Are Already Handling It

    The platform-level response has been uneven, and that unevenness is the story most coverage misses.

    Google rolled out an AI-label setting across five ad products, Google Ads, Display & Video 360, Campaign Manager 360, Merchant Center, and Ads Editor, back on July 9, 2026, putting the disclosure duty on advertisers rather than absorbing it itself. Google signed the Code of Practice on July 24, two days after the formal signatory window closed, though the legal obligations apply whether or not a company signs. Google’s SynthID has now watermarked more than 20 billion images. TikTok has labeled over 1.3 billion videos with C2PA-based provenance data. Microsoft started adding C2PA metadata to Microsoft 365 content back in February 2026.

    Then there’s X. TikTok, YouTube, LinkedIn, and Meta all read and surface Content Credentials or C2PA manifests when content is uploaded. X strips that provenance metadata on upload and doesn’t enforce disclosure. A fully labeled image can arrive on X looking completely unlabeled, leaving Google’s invisible SynthID watermark, which X doesn’t currently read either, as the only signal that survives the trip.

    Practical takeaway: if your AI-generated content is likely to end up reshared on X specifically, embedded metadata alone isn’t a compliance strategy. You need a visible on-asset label or a platform-native tag as a second layer.

    What the Experts Are Saying

    J. Paul Haynes, CEO of enterprise data-governance company Cinchy and former CEO of cybersecurity firm eSentire, argues the real story isn’t European at all.

    “The EU isn’t exporting regulation. It’s exporting customer expectations.” J. Paul Haynes, CEO, Cinchy, via PPC Land, August 1, 2026
    Haynes’ broader point, made days before the deadline, is that disclosure is the easier half of AI governance. The harder problem, auditable logs of what AI systems actually do, remains largely unaddressed by a rule focused purely on labeling.

    Rob Bratby, Managing Partner at Bratby Law and a Lexology Global Elite Thought Leader for Data Protection, frames the obligation in blunter terms for practitioners.

    “It asks one thing of any business putting AI in front of people: say so.” Rob Bratby, Managing Partner, Bratby Law
    Bratby’s analysis, aimed at UK firms serving EU users, makes the point that disclosures buried in terms and conditions or vague references to “our assistant” don’t meet the standard. It has to be clear.

    The most striking voice, though, comes from someone whose job is detection, not policy. Hany Farid built much of the modern digital-forensics field over more than two decades, first at UC Berkeley and now back at Dartmouth College after returning in July 2026. In a June 2026 New York Times profile, he described his own struggle keeping up with generation quality.

    “I feel like I am going blind.” Hany Farid, Chief Science Officer, GetReal Security
    That’s not a comment about the law. It’s a comment about the technology the law is trying to label, and it lands harder because of who’s saying it.

    The Enforcement Problem Nobody’s Pricing In

    Here’s the part of this story that headlines about “€15 million fines” tend to skip: the fine only matters if someone actually issues it.

    Article 50 enforcement runs through the same national market-surveillance authorities that already handle GDPR. GDPR’s own track record isn’t encouraging. Between 2018 and 2023, only 1.3% of GDPR cases resulted in a fine, according to the European Data Protection Board’s own evaluation report. Staffing tells the same story: Germany’s data-protection authorities had 1,094 full-time staff in 2024, France had 288, Ireland, the authority that leads enforcement against Google, Meta, and Microsoft, had 220. Portugal’s authority opened 3,201 cases in 2025 and issued just two fines totaling €47,000.

    Our read: expect the first wave of Article 50 enforcement, if it comes at all in these early months, to target the largest and most visible platforms rather than arrive as broad market-wide supervision. Small and mid-size companies aren’t off the hook long-term, but they’re unlikely to be first in line.

    The technical layer has its own gap. Standard recompression on upload, particularly on X and reportedly on Instagram, strips embedded C2PA manifests. That means a validator can flag a genuinely AI-generated, properly labeled image as “unverified” simply because the label got lost in transit, not because anyone did anything wrong. The absence of a visible label proves nothing about whether content is authentic, which undermines the practical reliability of a disclosure-based system for anything that gets reshared.

    There’s also a live scope dispute. The Computer & Communications Industry Association has publicly argued that the Commission’s final July 20, 2026 Guidelines stretched the statutory definition of deepfake beyond what the 2024 legislative text intended. That’s contested, not settled, and it’s the kind of disagreement that tends to end up in front of a court eventually.


    Frequently Asked Questions

    What is Article 50 of the EU AI Act?

    Article 50 is the EU AI Act’s transparency provision. It requires AI chatbots to disclose they’re AI, generative AI systems to mark outputs as machine-readable, and deployers to disclose deepfakes and AI-written public-interest text. It became legally enforceable on August 2, 2026, and applies to any organization worldwide whose AI output reaches EU users.

    When did the EU AI deepfake labeling law take effect?

    Article 50’s transparency and deepfake-labeling obligations became legally applicable on August 2, 2026, exactly two years after the AI Act entered into force. A narrow four-month grace period, running to December 2, 2026, applies only to the marking duty for generative systems already on the market.

    What is the fine for not labeling AI-generated content in the EU?

    Non-compliance carries fines of up to €15 million or 3% of a company’s total worldwide annual turnover, whichever is higher. Small and medium enterprises face the lower of the two figures rather than the higher one.

    Does Article 50 apply to companies outside the EU?

    Yes. It applies to any provider or deployer anywhere in the world whose AI system’s output is used within the EU or EEA, regardless of whether the company has a legal presence in Europe.

    What counts as a deepfake under the EU AI Act?

    Article 3(60) defines a deepfake as AI-generated or manipulated image, audio, or video content that resembles a real person, object, place, entity, or event and would falsely appear authentic. Disclosure is required even without intent to deceive.

    Are there exemptions to the labeling rule?

    Three narrow exemptions exist: criminal investigation and prosecution use, evidently artistic or satirical deepfakes (reduced, not eliminated, disclosure), and AI text that underwent genuine human editorial review by a named responsible person. Purely personal use is exempt too, unless it affects public discourse.


    What to Watch Next

    Three things worth tracking over the next six to eighteen months: whether any national authority actually issues an Article 50 fine before year-end, which would set the real tone for enforcement; whether the CCIA’s scope dispute over the deepfake definition moves toward litigation; and whether the December 2, 2026 grace-period deadline produces a second wave of scrambling similar to what happened around August 2.

    What’s clear right now is this: the rule is not hypothetical anymore, the Digital Omnibus delay does not cover you, and the platforms you distribute through don’t all handle provenance the same way. Map your AI touchpoints against the four sub-obligations this week, not next quarter.

    For more on how AI governance is reshaping enterprise compliance, see our coverage of the enterprise adoption gap in Google’s AI agents and how it echoes the same disclosure-versus-accountability tension Haynes raises above, plus our look at whether Meta’s Muse Glimmer model skipped its own safety review as regulation tries to keep pace with releases.

    Get the next regulatory shift before your compliance team does.

    Subscribe to The Neural Loop →
  • GENIUS Act vs MiCA: Stablecoin Rules 2026

    GENIUS Act vs MiCA: Stablecoin Rules 2026

    GENIUS Act vs MiCA: Stablecoin Rules Fracture in 2026
    Crypto / Policy

    GENIUS Act vs MiCA: Stablecoin Rules Fracture in 2026

    A compliance lead at a payments company spent June building one integration for USDT across every market the company served. By July, that single build had turned into a liability. The European Union’s stablecoin authorization deadline hit, the exchanges her company routed through pulled USDT for EU users, and she had a weekend to figure out which coins were still legal where. That scramble is the real story behind the headline that “seven major economies now mandate 100% stablecoin reserves.” The mandates exist. The convergence does not, at least not yet.

    Stablecoin regulation in 2026 is the closest thing crypto has had to a coordinated global crackdown since the TerraUSD collapse. The United States, the European Union, the United Kingdom, Singapore, Hong Kong, the UAE, and Japan have each built frameworks that require full reserve backing and ban the undercollateralized, algorithmic designs that wiped out billions in 2022. But read past the press releases and the picture splits apart fast: one region’s toughest rule has zero users, another country’s flagship law missed its own deadline, and a third hasn’t actually turned its rules on yet. If you’re building products on stablecoin rails, the gap between “mandated” and “enforced” is where your compliance risk actually lives.

    The convergence claim, and what’s actually true

    Start with what’s genuinely real. By mid-2026, regulators in the US, EU, UK, Singapore, Hong Kong, UAE, and Japan had each landed on a similar core design for stablecoin regulation: issuers must hold reserves equal to 100% of coins in circulation, those reserves have to sit in cash or short-term government securities rather than corporate paper, and holders get a legal right to redeem at par value, typically within five business days. Purely algorithmic stablecoins, the kind that collapsed with TerraUSD, are effectively banned for any regulated issuer.

    That’s a real regulatory shift, and it traces back to a single event. TerraUSD’s collapse in May 2022 discredited the algorithmic model so completely that the Financial Stability Board formalized a “same activity, same risk, same regulation” doctrine in 2023, and national legislatures spent the next three years turning that doctrine into statute. The result: MiCA’s stablecoin provisions in the EU, the GENIUS Act in the US, and Hong Kong’s Stablecoin Ordinance all converge on the same reserve-quality logic, even though they were written by entirely separate legislatures with no formal coordination mechanism.

    So the direction of travel is real. What’s overstated is the idea that these rules are simultaneously live, equally enforced, and functionally identical. They aren’t.

    Seven jurisdictions, seven different timelines

    Here’s where the framing breaks. Mid-2026 looks like a coordinated global moment because three major deadlines happened to land in the same six-week window: the EU’s authorization cutoff on July 1, the US statutory rulemaking deadline on July 18, and the Bank of England’s policy statement on June 22. That clustering created the appearance of synchronized global action. The actual substance is a staggered rollout that started in 2025 and won’t finish until 2027 at the earliest.

    Jurisdiction Framework Status as of August 2026
    United States GENIUS Act (Public Law 119-27) Signed July 2025. Ten proposed rules issued, zero finalized by the July 18, 2026 deadline. Fallback effective date: January 18, 2027, or 120 days after final rules, whichever comes first.
    European Union MiCA Live. Around 20 e-money token issuers authorized, zero asset-referenced token issuers. Full authorization mandatory since July 1, 2026.
    United Kingdom Bank of England systemic stablecoin regime Draft Code of Practice open for consultation until September 22, 2026. Expected to finalize by end of 2026. Regime not expected to operate until 2027.
    Hong Kong Stablecoin Ordinance Live since August 1, 2025. Only two issuers approved in the first licensing batch.
    Singapore MAS stablecoin framework Live. Requires MAS license and full backing.
    Japan Revised Payment Services Act Live. Issuance restricted to banks and trust companies.
    UAE Payment Token Regulation Live. Requires CBUAE licensing for non-Dirham tokens.
    The number that undercuts the headline Ten proposed rules under the GENIUS Act, zero finalized, as of the law’s own statutory deadline. The US “mandate” that gets cited in most convergence coverage exists in statute, not yet in enforceable regulation. (Source: Chapman and Cutler LLP rulemaking tracker)

    Where the convergence story breaks down

    Three gaps matter more than the headline lets on.

    The US mandate isn’t finalized law

    Federal agencies, including Treasury, the OCC, the FDIC, and the NCUA, issued ten proposed rules under the GENIUS Act. None were finalized by the statute’s own one-year deadline. Calling US reserve backing “mandated” today skips past the fact that the enforceable regulatory machinery doesn’t exist yet. Under the fallback provision, the law’s actual effective date is January 18, 2027, or 120 days after final rules land, whichever comes first.

    The EU’s toughest tier is functionally empty

    MiCA created two tiers: e-money tokens (EMTs) and asset-referenced tokens (ARTs). By early 2026, national authorities had authorized roughly 20 EMT issuers and exactly zero ART issuers. Tether never pursued EMT authorization for USDT, so Binance, Coinbase, and Kraken all pulled or restricted the world’s most-traded stablecoin for EU users rather than risk noncompliance. A regime the dominant market player simply exits is a weaker convergence story than “the EU mandates reserves” suggests.

    The UK hasn’t launched anything

    The Bank of England’s regime caps systemic sterling stablecoins at roughly £40 billion (about $50.6 billion) per coin, with up to 70% of backing assets allowed in short-term UK government debt. But the draft Code of Practice stays open for consultation until September 22, 2026, and regulated stablecoins aren’t expected to operate under the new regime until 2027. Industry commentary has already described the UK framework as arriving years behind its EU and US counterparts, with critics arguing the cap-based approach could cede market dominance to dollar-denominated stablecoins before UK-regulated coins even launch.

    What regulators and economists are actually saying

    Not everyone agrees full reserve backing solves the underlying problem, and the disagreement runs from central bankers to law professors.

    “I’ve always just looked at stablecoins as a payment instrument; there’s nothing evil about it, nothing dangerous about it.” Christopher Waller, Governor, Federal Reserve Board of Governors, remarks at the Dubrovnik Economics Conference, via Reuters, June 1, 2026
    Waller represents the consensus pro-clarity position among US policymakers, and he’s gone further elsewhere, arguing that stablecoin adoption abroad functions like a fixed exchange rate system that extends the reach of US monetary policy into countries that use dollar-pegged tokens.

    Not every central banker shares that read. Megan Greene, an external member of the Bank of England’s Monetary Policy Committee, told the same Dubrovnik panel that tokenized deposits could overtake stablecoins within five years as banks defend their deposit bases, a direct institutional counter-narrative from inside a G7 central bank: stablecoins as a transitional technology, not a permanent fixture, even under full reserve backing.

    The sharpest academic critique comes from Arthur E. Wilmarth, Professor Emeritus at George Washington University Law School, whose Delaware Journal of Corporate Law article argues that the GENIUS Act institutionalizes nonbank stablecoin issuance in a way that carries severe economic risks without offsetting benefits, according to a summary in The Regulatory Review. His argument: reserve backing alone doesn’t fix the structural problem of nonbank entities performing bank-like functions without deposit insurance or a lender of last resort standing behind them.

    Financial-stability researchers push the critique further. The Bank Policy Institute has warned that a current US federal proposal wouldn’t guarantee retail holders a right to redeem their stablecoins, and would let issuers honor redemption requests in whatever order they choose, an approach that could favor large institutional customers over retail holders during a stress event. In other words: 1:1 backing on paper doesn’t automatically mean orderly redemption in a crisis. Separately, Federal Reserve economist Jessie Jiaxu Wang’s December 2025 research, tracking on-chain data linked to Fedwire payments, found that partner banks saw roughly 67% higher interbank payments and a 14-percentage-point drop in loans-to-assets ratios after entering stablecoin partnerships, a credit-contraction effect that full reserve backing does nothing to mitigate. If anything, mandating Treasury-heavy reserves may accelerate it, since a New York Fed staff report projects a shift of $200 billion to $1 trillion in deposits into stablecoins could contract US bank lending by $65 billion to $1.26 trillion.

    What this means if you’re building on stablecoin rails

    For engineering and compliance teams integrating USDC, USDT, or any regulated stablecoin, the practical shift is this: a single global integration no longer works. Sovereignty protections are showing up in the fine print of every framework, the EU restricts non-euro stablecoins in certain contexts, the UAE requires CBUAE licensing for non-Dirham tokens, and jurisdiction-aware compliance logic is now a baseline requirement, not an edge case.

    The near-term risk is concrete, not theoretical. Any product still routing USDT through EU-facing rails needs an audit now, since three major exchanges already delisted or restricted it there. Longer term, enterprises should build vendor-risk criteria around reserve composition, attestation quality, redemption terms, licensing posture, enforcement history, and market-access resilience, and avoid single-issuer dependency for anything mission-critical. That’s a genuinely new procurement discipline in 2026, not boilerplate risk language copied from a vendor questionnaire template.

    One more thing worth flagging for anyone modeling risk purely around reserve adequacy: Hacken’s Q2 2026 Security and Compliance Report found 67 stablecoin-related incidents totaling $764 million in losses, and 88% of those losses came from operational failures, not reserve shortfalls. Full reserve backing addresses one failure mode. It does nothing for custody bugs, key management errors, or smart contract exploits, which is where most of the actual money is still being lost.

    Our read The “seven economies mandate stablecoin reserves” framing is directionally accurate and practically premature. Treat 2026 as the year the rules were written, not the year they were enforced uniformly. Build your compliance roadmap around each jurisdiction’s actual effective date, not its headline mandate.

    Frequently asked questions

    What is the GENIUS Act for stablecoins?
    The GENIUS Act (Public Law 119-27), signed July 18, 2025, is the first US federal law regulating payment stablecoins. It requires 1:1 reserve backing in cash, insured deposits, or short-term Treasuries, but its implementing regulations were still not finalized as of the July 2026 statutory deadline.

    Does MiCA require 100% reserve backing for stablecoins?
    Yes. MiCA requires e-money token and asset-referenced token issuers to hold 100% reserves in high-quality liquid assets, largely at EU banks, and bans purely algorithmic stablecoins outright. Full authorization became mandatory for EU-operating issuers by July 1, 2026.

    Which countries regulate stablecoins in 2026?
    As of mid-2026, the US, EU, UK, Singapore, Hong Kong, UAE, and Japan each have stablecoin frameworks requiring full reserve backing and licensed issuance, though implementation stages differ significantly by jurisdiction.

    Why was Tether (USDT) delisted in the EU?
    Tether never obtained e-money token authorization under MiCA, so major exchanges including Binance, Coinbase, and Kraken pulled or restricted USDT trading for EU users to remain compliant.

    What is the current stablecoin market cap?
    The total stablecoin market capitalization was approximately $314.68 billion as of June 21, 2026, according to DefiLlama, with Tether’s USDT and Circle’s USDC together accounting for roughly 83% of the market.

    When do UK stablecoin rules take effect?
    The Bank of England intends to finalize its Code of Practice for systemic sterling stablecoins by the end of 2026, with the regime expected to launch in 2027, later than the US and EU frameworks.

    What to watch next

    Three things will tell you whether this convergence story holds up or fractures further. First, watch whether US agencies finalize GENIUS Act rules before the January 2027 fallback date, or whether the deadline slips again. Second, watch whether any issuer actually clears MiCA’s asset-referenced token bar, since a continued zero would confirm that tier is unworkable as written. Third, watch how the UK’s consultation period closes in September, since the final Code of Practice will determine whether sterling stablecoins launch with a competitive structure or a defensive one.

    None of this means the reserve-backing shift isn’t real. TerraUSD’s collapse permanently discredited the algorithmic model, and every major regulator that’s built a framework since has converged on the same core idea: full backing, liquid assets, redemption rights. What’s still unsettled is whether “mandated” becomes “enforced” on anything close to the timeline the 2026 headlines implied.


    Related reading on NeuralWired: GENIUS Act Stablecoin Yield Ban: What Changed in 2026, which covers the same framework from the yield-restriction angle.

    Get regulatory and infrastructure stories like this one before they break wide. Subscribe to The Neural Loop.
  • Gemini 3.7 Flash Pricing Explained: Half Price Ends 2027

    Gemini 3.7 Flash Pricing Explained: Half Price Ends 2027

    Gemini 3.7 Flash: Half Price Now, Full Price in 2027 AI & Enterprise Tech

    Gemini 3.7 Flash Is Half Price. Read the Footnote First.

  • LiteLLM Breach 2026: 2,500 Companies Exposed by TeamPCP

    LiteLLM Breach 2026: 2,500 Companies Exposed by TeamPCP

    LiteLLM Breach 2026: Why Your SDLC Checklist Failed
    Cybersecurity

    LiteLLM Breach 2026: Why Your SDLC Checklist Failed

    Published August 14, 2026  |  NeuralWired Cybersecurity Desk

    One credential from February didn’t get rotated. Five months later, that single oversight had cascaded through a vulnerability scanner, a code analysis tool, and an AI gateway used by thousands of companies, exposing an estimated 2,500 organizations and roughly 434,000 CI/CD pipelines. If your team runs LiteLLM, Trivy, or Checkmarx KICS anywhere in its build process, this story isn’t background reading. It’s an open incident.

    Two threat intelligence firms independently confirmed the scale of the damage this week. On August 11, 2026, CloudSEK published its exposure dataset. Two days later, Hudson Rock corroborated it from a completely separate 153GB archive. Neither firm was working from the other’s data. That’s what makes this LiteLLM breach different from the usual single-source security scare: the numbers hold up.

    What Happened: The LiteLLM Breach, Explained

    LiteLLM is a popular open-source gateway that lets developers call dozens of large language model APIs through one unified interface. It sits in front of, or alongside, a huge number of production AI workloads. That’s exactly why the FBI’s Internet Crime Complaint Center formally named the threat group behind this campaign: TeamPCP, in a July 2, 2026 advisory that confirmed Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK as compromised links in one escalating campaign.

    The breach itself happened back in March. The public reckoning is happening now, in real time, which is why this is the story to understand this week rather than next month.

    The Attack Chain: One Credential, Three Tools, Thousands of Companies

    Strip away the acronyms and the sequence is almost mundane, which is what makes it unsettling.

    1. A credential from a late-February 2026 breach never got fully rotated. TeamPCP used it to hijack the service account behind Aqua Security’s Trivy vulnerability scanner.
    2. March 19, 2026: the group force-pushed malicious code across 76 of the 77 version tags in the aquasecurity/trivy-action GitHub repository.
    3. Two days later: Checkmarx’s KICS scanner was compromised using stolen GitHub tokens, extending the campaign to a second widely used security tool.
    4. LiteLLM’s own CI pipeline auto-installed the compromised Trivy version, and two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, went live on PyPI.
    5. The exposure window was roughly 40 minutes, from 10:39 to 11:19 UTC on March 24, 2026, according to LiteLLM/BerriAI’s own incident report.
    Forty minutes doesn’t sound like much until you understand what version 1.82.8 actually shipped: a file called litellm_init.pth that executes automatically the moment Python starts up. Teams that thought running --ignore-scripts protected them were wrong. That flag blocks install-time scripts. It does nothing against a file designed to fire on interpreter startup, which is the detail that should worry anyone who assumed a single defensive habit was sufficient.

    “Trivy, then the build system, then the release: one unrotated token, three tools deep. That chain is what turns a single credential leak into ecosystem-wide exposure.” CloudSEK, via SecurityWeek, August 12, 2026

    By the Numbers: Third-Party Breaches Are Accelerating

    The LiteLLM breach isn’t a one-off. It’s the loudest recent data point in a trend that’s been building for two years. Here’s what the most credible sources actually say, since the headline stats floating around social media don’t all agree.

    SourceFigureWhat it measures
    Verizon 2025 DBIR30% of breaches, double the 15% a year earlierConfirmed breaches with third-party involvement, across 12,195 incidents globally
    SecurityScorecard / HIPAA Journal35.5% in 2024, up from 29% in 2023Breaches that originated from a third-party compromise
    IBM Cost of a Data Breach 202530%, described as doubling year over yearCorroborates Verizon’s directional finding
    SecurityScorecard / Secureframe75% of third-party breachesSpecifically hit the software and technology supply chain
    Which number should you actually cite? A widely repeated “29% of breaches start with a third party” figure is outdated. It’s SecurityScorecard’s 2023 baseline, and it climbed to 35.5% by 2024. If you need one number to anchor a board conversation or a budget request, use Verizon’s 30%, doubled from 15% the prior year, drawn from the largest DBIR dataset on record. It’s the most methodologically transparent figure in the industry right now.
    Sonatype’s 2026 State of the Software Supply Chain report adds scale to the picture: 1.233 million malicious open source packages have now been identified, with open source malware up 75% year over year and 454,648 new malicious packages found in the past twelve months alone, based on analysis of more than 10 trillion downloads across Maven Central, PyPI, npm, and NuGet. And 86% of Maven Central traffic in 2025 came from cloud service providers rather than humans, which tells you something important: the attack surface has moved from developers clicking “install” to automated build systems pulling dependencies at machine speed, unsupervised, thousands of times a day.

    This Isn’t Isolated: The Shai-Hulud npm Worm Wave

    If LiteLLM feels like an isolated AI-ecosystem incident, it isn’t. It’s the PyPI chapter of a story that’s been unfolding in npm for almost a year.

    • September 2025: “Shai-Hulud,” the first documented self-replicating npm worm, compromised more than 500 packages, according to a CISA advisory.
    • November 24, 2025: “Shai-Hulud 2.0” backdoored 796 unique npm packages representing over 20 million weekly downloads, per Datadog Security Labs. It self-replicates without needing a command-and-control connection back to the attacker.
    • March 2026: a related campaign, tracked by StepSecurity and CloudSEK, exfiltrated 78,330 secrets from CI/CD pipelines across 2,186 organizations in five days.
    • April 2026: a “Shai-Hulud: The Third Coming” variant compromised the official @bitwarden/cli package, which had more than 250,000 monthly downloads, through a malicious preinstall hook.
    Between August 2025 and May 2026, npm went from occasionally hosting malware to becoming one of the most actively exploited software supply chains anywhere. A maintainer-phishing wave briefly poisoned a combined 2.6 billion weekly downloads across the chalk and debug packages alone. The pattern connecting npm’s worm wave to the LiteLLM breach is the same: attackers no longer need to compromise your code. They just need to compromise something your code trusts.

    Why Your Secure SDLC Checklist Didn’t Catch This

    Here’s the uncomfortable part. LiteLLM’s own development practices weren’t the failure point. The breach succeeded because of one unrotated credential, several hops upstream, inside a security scanner that most engineering teams never think to audit as an attack surface in the first place. A checklist that only covers your own code and your direct dependencies would not have caught this. The failure happened inside the tooling that exists specifically to provide security assurance.

    Not everyone agrees this is an AI story at all, and that disagreement matters.

    Ordinary DevOps hygiene failures under pressure to ship AI features quickly, not novel AI risk, is how independent researcher Kevin Beaumont frames the root cause. Reported via Help Net Security, August 13, 2026
    Beaumont’s contribution goes beyond commentary. He personally tested a major tech company’s public claim that it had rotated every exposed credential, and found working credentials still active months after the company said the issue was closed. That’s arguably the single most concrete finding to come out of this story: a “we already fixed it” statement from March may still be false in August.

    Alon Gal, Co-Founder and CTO of Hudson Rock, described the scale of the credential archive as demanding a genuinely different tier of industry response than incidents like this have typically drawn. Help Net Security, August 13, 2026
    There’s a counterpoint worth holding onto, though, because it complicates the “the industry is failing” narrative that’s easy to reach for. GitHub’s Octoverse 2025 report found that average fix time for critical severity vulnerabilities improved 30%, dropping from 37 days to 26 days, and that 26% fewer repositories received critical security alerts over the same window. Dependabot adoption climbed to more than 2.6 million projects. Automation is working, where teams actually use it.

    Our read: this isn’t a uniform industry failure. It’s a bifurcation. Teams running automated software composition analysis and enforced dependency gates are getting measurably safer. Teams without that tooling remain exposed to worm-class threats that spread faster than a human reviewer can react. The gap between those two groups is widening, not narrowing.

    One counterweight worth flagging in the other direction: Broken Access Control overtook Injection as the most common CodeQL security alert in 2025, appearing in more than 151,000 repositories, a 172% year-over-year jump that GitHub’s own engineers link partly to misconfigured CI/CD permissions and AI-generated code scaffolds that skip authorization checks by default.

    NIST, CISA, and the EU’s SBOM Mandate

    Institutional responses exist, and they’re maturing, but nobody serious is calling them sufficient yet.

    NIST SP 800-218, the Secure Software Development Framework, remains the most-referenced U.S. framework, required for FedRAMP and federal vendors. CISA’s Secure by Design pledge now has 68 signatory manufacturers, including AWS, Cisco, GitHub, GitLab, and Microsoft, all committing to specific security-by-default practices. And the EU’s Cyber Resilience Act is pushing Software Bills of Materials from a nice-to-have into a legal requirement for anyone selling software into the EU.

    Saša Zdjelar, Chief Trust Officer at ReversingLabs, has credited CISA’s Secure by Design work with maturing the industry conversation on software security, while noting that current guidelines don’t yet fully address the complexity of the modern software supply chain. ReversingLabs, “CISA’s Secure by Design Pledge”
    Read between the lines and the honest assessment is this: these frameworks were largely built before ecosystem-scale, self-replicating worm attacks were a realized threat rather than a theoretical one. They’re catching up, not leading.

    One caution flag before you cite this story elsewhere A widely circulating quote calling the LiteLLM incident “the AI era’s SolarWinds moment” traces back to an April 2026 press release from a competing AI-gateway vendor promoting its own product, not to CloudSEK, Hudson Rock, Unit 42, or the FBI. A “36% of all cloud environments” statistic attached to that same quote appears in none of the independent datasets. Treat it as marketing, not research.

    What Engineering and Security Teams Should Do Now

    If your organization touches LiteLLM, Trivy, or Checkmarx KICS anywhere in a build pipeline, here’s the practical checklist, drawn directly from the FBI’s own recommended mitigation in FLASH-20260702-01.

    • Pin to commit hashes, not version tags. Floating tags are exactly what let TeamPCP force-push malicious code across 76 of 77 Trivy release tags in one move.
    • Audit your security tooling as an attack surface, not just your application code. The scanner meant to protect you is now a documented entry point.
    • Don’t trust a “credentials rotated” announcement at face value. Beaumont’s test proved a major company’s public claim was false months after the fact. Verify independently.
    • Check whether your org appears in the CloudSEK or Hudson Rock datasets. Inclusion means exposure evidence was found, not confirmed compromise. Treat it as an investigation trigger, not a panic button, and not a dismissal either.
    • If you’re not already running automated SCA scanning and dependency pinning enforcement, this incident is the concrete, current justification to get budget approved. GitHub’s own data shows it works.

    FAQ

    What percentage of data breaches involve third parties?

    Verizon’s 2025 Data Breach Investigations Report found third-party involvement in 30% of breaches, double the 15% reported the prior year, based on 12,195 breaches, the largest dataset in the report’s history.

    What happened in the LiteLLM supply chain attack?

    In March 2026, threat group TeamPCP compromised the Trivy security scanner through an unrotated credential, which cascaded into LiteLLM’s build pipeline. Two malicious LiteLLM versions sat live on PyPI for roughly 40 minutes, later linked to over 2,500 exposed organizations.

    What is a Secure Software Development Lifecycle?

    An SSDLC builds security activities, like threat modeling, automated scanning, and code review, into every development phase instead of treating security as a final gate before release. NIST SP 800-218 is the most widely referenced U.S. framework for this.

    How many npm packages did the Shai-Hulud worm compromise?

    Shai-Hulud 2.0, identified in November 2025, backdoored 796 unique npm packages representing more than 20 million combined weekly downloads, and it self-replicates without needing a command-and-control connection.

    Does pinning dependencies to a version number protect against this kind of attack?

    No. TeamPCP force-pushed malicious code across 76 of 77 version tags in one Trivy repository. Pinning to an immutable commit hash, not a floating version tag, is the mitigation the FBI explicitly recommends.


    Where This Goes Next

    What’s changed after this week isn’t just the exposure count. It’s the assumption that “we fixed it in March” means anything in August. TeamPCP’s campaign proved that a compromise several tools upstream, in software meant to secure you, can sit undetected for months while credentials stay valid and reusable. That’s a longer blast radius than most incident response plans are built for.

    Watch three things over the next six to eighteen months: whether the EU’s Cyber Resilience Act SBOM requirement actually forces vendors to disclose dependency provenance in a way that would have caught this earlier, whether the gap between automated and manual security teams keeps widening the way GitHub’s Octoverse data suggests, and whether more organizations quietly confirm they’re still exposed the way Beaumont’s test did. Five months of silence between compromise and disclosure was too long. The next one probably won’t be different unless the incentives change.

    Want the next breaking supply chain story before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.


    Related coverage: our full breakdown of the LiteLLM breach timeline, CloudSEK and Hudson Rock’s dueling exposure datasets. See also: three real companies breached in the Anthropic Claude hack, and NeuralWired’s ongoing Cybersecurity coverage.

  • LiteLLM Breach 2026: CloudSEK vs Hudson Rock Numbers

    LiteLLM Breach 2026: CloudSEK vs Hudson Rock Numbers

    LiteLLM Breach: CloudSEK and Hudson Rock Diverge on Scale
    Cybersecurity / Supply Chain

    LiteLLM Breach: CloudSEK and Hudson Rock Diverge on Scale

  • Meta’s AI Spending Crisis: Inside the $760B Big Tech Bet

    Meta’s AI Spending Crisis: Inside the $760B Big Tech Bet

    Big Tech

    Big Tech’s $760B AI Bet: Who’s Cashing In, Who Isn’t

    Meta’s free cash flow just fell to $784 million. SpaceX’s AI capex grew sixfold in a single quarter. Amazon’s cloud arm is finally showing the receipts. Q2 2026 earnings season didn’t answer whether AI spending is a bubble. It answered something more useful: which companies can prove it, and which ones are still asking investors to trust them.

    The Number That Broke the Spell

    For three years, “trust us” was a perfectly good answer to the question of why Big Tech kept raising AI spending guidance. That stopped working for at least one company this earnings season.

    Amazon, Microsoft, Alphabet and Meta now plan to spend roughly $725 billion to $760 billion combined on AI infrastructure in 2026, up 77% to 84% from about $410 billion in 2025, according to guidance aggregated across each company’s Q2 earnings release. Alphabet alone raised its ceiling to $185 billion to $205 billion, a jump that overshadowed an otherwise strong quarter and helped drag the “Magnificent Seven” down 5.7% during the week of July 20 to 26.

    Then Meta reported. Revenue beat consensus at $60.80 billion, up 28% year over year. But capital expenditures hit $31.08 billion for the quarter, and free cash flow, the number that tells you what’s actually left over after the bills get paid, came in at just $784 million. That’s not a typo. Meta generated $31.86 billion in operating cash flow and spent nearly all of it building AI infrastructure.

    Why this matters: Free cash flow near zero is the closest any major hyperscaler has come to running out of room during the AI buildout. It’s a specific, checkable red flag for one company, not evidence the whole sector is collapsing.
    Then SpaceX reported, for the first time as a public company. Its capex soared more than sixfold to $18.4 billion, more than double total quarterly sales, with over 80% of that going toward AI. CEO Elon Musk told investors the company’s targeted $100 billion AI-related annual run rate by December 2026 “is not a question mark.” Shares fell anyway, despite a 92% revenue jump that beat estimates.

    2026 AI Capex Guidance, by Company

    Company 2026 Capex Guidance Direction vs. Prior Guidance
    Amazon~$220 billionRaised, citing memory chip costs
    Alphabet$185 billion to $205 billionRaised
    Microsoft~$190 billionRaised year over year
    Meta$130 billion to $145 billionNarrowed upward
    Source: Company Q2 2026 earnings releases, aggregated by Statista and ValueAdd VC.

    The Accounting Fight Over Depreciation

    If you want the sharpest version of the bear case, it doesn’t come from a hedge fund manager calling the whole thing a bubble. It comes from Michael Burry, the investor who predicted the 2008 housing collapse, making a narrow, specific, falsifiable claim about how hyperscalers do their math.

    Burry’s argument: hyperscalers are stretching the assumed useful life of AI chips and servers well beyond the real 2 to 3 year replacement cycle, which artificially lowers depreciation expense and inflates reported earnings. He first made the case on X in November 2025 and escalated it through early 2026.

    “Understating depreciation by extending useful life of assets artificially boosts earnings, one of the more common frauds of the modern era.”
    Michael Burry, Founder, Scion Asset Management. Source: CNBC
    By his estimate, this could understate industry depreciation by $176 billion to $226.6 billion between 2026 and 2028, with average earnings overstated by roughly 24% across named hyperscalers, and as much as 48% to 62% at Oracle specifically. Enron short seller Jim Chanos has voiced similar concerns.

    Here’s the part that gets left out of most coverage of Burry’s thesis: it’s his model, not an audited finding, and he holds disclosed put options against Nvidia and Palantir, a material conflict of interest worth weighing. Bulls also point out that older GPUs don’t necessarily get scrapped when they’re replaced for training work. They often get repurposed for lower intensity inference workloads, extending their effective economic life even if the top tier training life is shorter than hyperscalers assume.

    Goldman Sachs’ own research team is split on the broader question. Jim Covello, the bank’s head of global equity research and author of the influential 2024 “too much spend, too little benefit” report, has hardened his skepticism.

    “At some point, you’ve got to make money… we’ve gotten further away from that over the last couple of years instead of closer to it.”
    Colleagues Kash Rangan and Eric Sheridan, working at the same firm, take the opposite view: current spending, adjusted for revenue scale, isn’t dramatically out of line with prior tech investment cycles.

    The Circular Financing Problem

    OpenAI’s total disclosed infrastructure and compute commitments now run somewhere between $1.15 trillion and $1.4 trillion through the mid 2030s, spread across seven-plus vendors: Broadcom (~$350 billion), Oracle (~$300 billion), Microsoft (~$250 billion), Nvidia (up to $100 billion in equity plus chip commitments), AMD (~$90 billion), AWS (~$38 billion) and CoreWeave (~$22 billion).

    Nvidia’s up to $100 billion commitment to OpenAI, announced in September 2025, drew an immediate warning from Bernstein Research’s Stacy Rasgon.

    “Clearly fuel ‘circular’ concerns… likely fuel these worries much hotter than what we have seen previously, and perhaps justifiably raise concerns over the rationale behind the action.”
    The mechanics are simple enough to explain in one sentence: a chip or cloud vendor invests in an AI lab, and that lab turns around and spends the money buying the vendor’s own products, which makes demand look stronger than it might be on a standalone basis. UBS estimates the Nvidia-OpenAI arrangement alone could represent up to 13% of Nvidia’s projected 2026 revenue.

    This is the risk that doesn’t show up if you look at any single stock in isolation. OpenAI is privately held and reportedly on track to lose around $14 billion in 2026, nearly triple its 2025 loss, while targeting $100 billion in annual revenue by 2029. If its growth or fundraising slows, the shock wave could hit Oracle, Nvidia, Microsoft, Broadcom, AMD and CoreWeave at the same time, a correlated exposure that ordinary sector diversification does nothing to protect against, since on paper these are chip, cloud and software companies in entirely different categories.

    Receipts vs. No Receipts

    The most important story of this earnings season isn’t “AI spending, yes or no.” It’s that the spending is starting to split into two very different categories, and Wall Street is treating them differently.

    Amazon’s AWS segment posted around $42.2 billion in Q2 2026 revenue with $16.6 billion in operating income, including an AI specific run rate above $25 billion growing at triple digit rates. Segment operating margin expanded meaningfully year over year, above pre-AI-cycle AWS margins. That is the strongest single piece of evidence that the “ROI is bad” thesis doesn’t apply everywhere.

    Compare that to Meta and SpaceX, where the AI spending is still, largely, a promise. Meta’s near zero free cash flow quarter and SpaceX’s sixfold capex jump both came with confident guidance about future payoff, not present day proof of it.

    Companies also aren’t spending blindly. Reporting indicates all four major hyperscalers now commit early only to long lived assets, land, buildings, power infrastructure, while deferring GPU and chip purchases until closer to deployment based on visible demand. That reduces, though doesn’t eliminate, the risk of a stranded asset write-down if demand disappoints.

    The Case Wall Street Isn’t Giving Up on AI

    Here’s what complicates any clean “investors have had enough” narrative: JPMorgan just got more bullish, not less. In the same window that Meta’s cash flow spooked traders, JPMorgan raised its 2026 S&P 500 target to 8,000 and lifted its EPS forecasts to $365 for 2026 and $420 for 2027, arguing cloud growth and contract backlogs are starting to validate the capex cycle. At least seven major brokerages now share that 8,000 target for year end.

    Dan Ives at Wedbush, one of Wall Street’s most consistently bullish tech analysts, frames the moment as an inflection point rather than a warning sign, and still names Microsoft among his top picks on Azure monetization confidence.

    Our read: the “AI bubble” framing is too blunt for what’s actually happening. This isn’t a sector-wide verdict. It’s a company by company sorting exercise, and this quarter drew the lines more clearly than any before it.

    The Enterprise Side Tells the Same Story

    There’s a reason to take the hyperscaler skepticism seriously that has nothing to do with depreciation schedules. It’s what’s happening one layer up, inside the companies actually buying AI tools. A widely cited MIT study found that 95% of enterprise generative AI pilots fail to deliver measurable profit and loss impact, despite an estimated $30 billion to $40 billion in enterprise investment. Only around 5% of deployments generate significant, measurable value.

    S&P Global separately found that 42% of companies abandoned most of their AI projects in 2025. Morgan Stanley found only 21% of S&P 500 companies could point to a measurable AI benefit at all. IBM put the share of AI initiatives delivering expected ROI at 25%.

    Those numbers matter to hyperscaler earnings even though they’re about a different set of companies. If enterprise customers can’t extract value from AI tools, that puts a ceiling on how much they’ll eventually pay for the compute Amazon, Microsoft, Google and Meta are building. It’s the enterprise side answer to the same question Wall Street is asking about capex.

    What to Watch Over the Next 18 Months

    The infrastructure buildout is real, and cloud revenue already proves it in Amazon’s and Microsoft’s numbers. The unresolved question is whether the application layer, the consumer facing AI products that are supposed to justify trillion dollar valuations for OpenAI-adjacent companies, ever closes the gap. Right now, that’s where hype is furthest ahead of evidence.

    • Useful life assumptions. Watch 10-K footnotes for any hyperscaler quietly shortening the assumed lifespan of AI hardware. That would validate Burry’s thesis and the market would likely punish it hard.
    • Free cash flow trajectory. If Alphabet or Microsoft posts a Meta-style near zero quarter, the “one company problem” framing stops holding up.
    • OpenAI’s fundraising. Any stumble here has correlated downstream effects across Oracle, Nvidia, Microsoft, Broadcom, AMD and CoreWeave simultaneously.

    Frequently Asked Questions

    How much is Big Tech spending on AI in 2026?

    Amazon, Microsoft, Alphabet and Meta together plan roughly $725 billion to $760 billion in 2026 capital expenditure, up about 77% to 84% from around $410 billion in 2025, driven mainly by AI data centers, GPUs and power infrastructure.

    Why are investors worried about AI spending?

    Capital expenditure is rising faster than free cash flow at some companies, Meta’s Q2 2026 free cash flow fell to $784 million, while enterprise customers report low measurable returns from AI pilots, raising doubts about whether spending will pay off as quickly as guided.

    What percentage of AI projects fail to show ROI?

    A 2025 to 2026 MIT study found 95% of enterprise generative AI pilots fail to deliver measurable profit and loss impact, despite $30 billion to $40 billion in enterprise investment. Only about 5% of deployments generate significant, measurable value.

    What is circular AI financing?

    It describes chip and cloud vendors like Nvidia and Oracle investing in AI labs like OpenAI, which then spend that money buying the vendors’ own products and services, inflating apparent demand and concentrating financial risk across a small group of interlinked companies.

    Is AWS or Azure actually profiting from AI spending?

    Yes. Amazon’s AWS segment reported roughly $42.2 billion in Q2 2026 revenue with $16.6 billion in operating income and an AI specific run rate above $25 billion growing at triple digit rates, among the clearest evidence that cloud infrastructure spending is monetizing.

    What is Michael Burry’s argument against AI stocks?

    Burry argues hyperscalers are understating depreciation by assuming AI chips and servers last 5 to 6 years when the real replacement cycle is closer to 2 to 3 years, which he estimates could overstate industry earnings by roughly $176 billion to $226 billion between 2026 and 2028.

    The Bottom Line

    This wasn’t the quarter that proved AI spending is a bubble, and it wasn’t the quarter that put the question to rest either. It was the quarter that stopped letting every hyperscaler hide behind the same story. Amazon and Microsoft’s cloud businesses are turning capex into revenue you can point to. Meta and SpaceX are still asking for patience while cash flow gets thinner. Burry’s depreciation math is a real number to track, not a settled verdict. And the enterprise side, where 95% of AI pilots still don’t move the P&L, is the ceiling that ultimately caps how far this entire cycle can run.

    Over the next two quarters, watch for changes in stated useful life assumptions, watch whether any other hyperscaler posts a Meta-style cash flow quarter, and watch OpenAI’s fundraising, since its ripple effects reach further than any single stock.

    Want the next earnings-season breakdown before it hits your feed?