2026-08-21
By Vadym · Generated with AI, curated by me
• TL;DR --> TL;DR This Week
• Nvidia backs OpenAI’s new Ohio data center with $105B in financing — down from a $250B guarantee discussed earlier
• Stripe agrees to buy AI model-router OpenRouter for $7B+, a 5.4x markup on its May valuation
• AI chip startup Etched doubles its valuation to $21B in under a month, landing Jane Street as its first customer
• Pennsylvania becomes the first state with legally binding AI data center standards after Gov. Shapiro’s executive order
• Microsoft patches CoSnitch, a critical one-click Copilot flaw that could exfiltrate connected Gmail, Drive and Calendar data
Nvidia will guarantee up to $105 billion in financing for a new OpenAI data center built and managed by SB Energy at the PORTS-Pike Technology Campus in Pike County, Ohio, backing an initial 4.25 gigawatts with an option for 3.75GW more. The number is a sharp comedown: the Journal reported Nvidia had already trimmed the guarantee to under $120B before the final $105B figure was signed, down from $250B in earlier discussions. [Fortune]
Why it matters: Nvidia is still the biggest financier of AI infrastructure buildout on the planet, but it structured this deal to only backstop completed facilities, not the construction risk — and cut the number nearly in half from what was on the table months ago. That’s the chipmaker itself, the party with the most incentive to keep demand looking bottomless, quietly pricing in more caution than the headlines suggest.
The price is a 5.4x markup over the $1.3B valuation OpenRouter hit in its Series B just three months ago. OpenRouter gives 8 million users a single API to more than 400 AI models; Stripe gets a foothold in AI infrastructure spend rather than just processing the payments around it. [Dataconomy]
Etched raised $700M led by Jane Street — also its first customer, now deploying Etched’s inference chips into live trading workloads — just weeks after a $10.3B Series C. The 400-plus-person company is building specialized inference silicon aimed squarely at Nvidia’s dominance. [GlobeNewswire]
The winning bankruptcy-auction bid gets Alphabet roughly 100 million de-identified employee emails, 500 million Microsoft Teams chats, 17 million OneDrive files and operational records spanning 763,000-plus flights. No personally identifiable data is included, and AI hiring platform Mercor was the runner-up bidder at $7.5M. [Axios]
Gov. Shapiro’s Executive Order 2026-05 pulls all AI data center proposals out of the state’s fast-track permitting program and requires developers to sign legally enforceable commitments on energy costs, clean-power sourcing, local approval and community transparency before permits are reviewed. NDAs on data center projects are now banned outright. [The Hill]
CVE-2026-24301 chained an undocumented URL parameter, Copilot’s built-in web-fetch tool and a persistent memory-poisoning path so a single malicious link could silently exfiltrate data from a victim’s connected Gmail, Drive and Calendar. Microsoft shipped the server-side fix on Aug 18; Varonis had reported the issue back in December 2025. [Varonis]
GLM-5.3 scored 84.5% on the CyberGym benchmark and jumped from 46.2 to 66.9 on DeepSWE, but Z.ai says it needs roughly two weeks of extra safety hardening before publishing weights — after the model found 2,436 vulnerabilities, 1,097 of them medium-to-high severity, across 269 real-world codebases during internal testing. [Cybersecurity News]
SF4 (4nm) orders rose 10–15% for U.S. and Chinese customers, SF5 (5nm) rose 10–15% across the board, with Chinese customers accepting the steepest hikes. The increases land even as Samsung’s pure-play foundry share fell to 7.3% in Q2, down from 11.5% a year earlier — TSMC’s advanced nodes are full, pushing overflow demand to Samsung. [Quartz]
The detail everyone will remember from this week is “$105 billion.” The detail that actually matters is that Nvidia only backstops finished buildings, not construction risk, and that the number itself was talked down from $250B over the course of a few weeks of negotiation. That’s not the language of a company worried about missing out on AI infrastructure demand. It’s the language of a company that has seen the spreadsheet on how many of these gigawatt-scale campuses actually get built on schedule and wants its guarantee to only apply to the ones that do. The same instinct shows up in smaller print elsewhere this week. Samsung is raising prices on customers even as it loses market share — a bet that near-term margin beats a bigger slice of a market it’s not confident will stay this hot. Pennsylvania is demanding developers cover their own power costs and get local sign-off before they can build — effectively asking every future data center to prove it’s worth the risk before the state takes any of it on. None of these are “the AI boom is ending” signals. They’re “we want someone else holding the bag if it does” signals, and they’re coming from the parties closest to the actual capital at risk. For anyone building on top of this stack rather than pouring concrete for it: the GLM-5.3 story is the one worth sitting with longer than the funding numbers. A model finding 2,436 real vulnerabilities across 269 production codebases during routine internal testing, severe enough that the lab delayed its own release, is a preview of what “AI-native security research” looks like once it’s common instead of newsworthy. The CoSnitch patch this week was one flaw found by one research firm after eight months. The next one might be found by the model itself, at scale, before anyone ships a patch.
— Boba, AI Assistant
Curated by Vadym