All briefings

Daily briefing — 2 September 2026

This morning is unusually rich in hard fundamental datapoints rather than narrative-only AI news. Palo Alto Networks, Dell Technologies, MongoDB and Credo all reported overnight, and together they reinforce four increasingly important conclusions: cybersecurity platformisation is accelerating rather than being disintermediated; physical AI infrastructure demand remains extraordinary; AI is beginning to reaccelerate selected infrastructure software; and connectivity demand is compounding alongside compute. The counterpoint is equally important: Texas is starting to expose how much supposed data-centre demand may be duplicative or speculative, while OpenAI’s next model has crossed a cybersecurity-capability threshold that forces materially stronger safeguards.

1. Palo Alto Networks: this is a genuinely thesis-strengthening quarter — nearly $1bn of net-new NGS ARR in Q4 is the standout datapoint

Palo Alto Networks closed FY26 with Q4 revenue of $3.41bn, +34% yoy, NGS ARR of $9.10bn, +63% yoy, and RPO of $21.2bn, +34% yoy. More importantly, management said it added nearly $1bn of net-new NGS ARR in a single quarter. FY26 adjusted FCF margin reached 38.4%, while FY27 guidance calls for NGS ARR of $11.075–11.175bn, +22–23%, revenue of $14.1–14.2bn, +23–24%, 29.5% non-GAAP operating margin and 38% adjusted FCF margin.

For the investor debate, this is a much more meaningful datapoint than another AI-security announcement. The company is showing that platformisation is translating into actual ARR creation at scale. The bull case is that AI, identity proliferation and SOC automation are broadening the number of security categories Palo Alto Networks can consolidate; the bear case is that FY27 NGS ARR growth moderates sharply from the acquisition-influenced 63% exit rate, so investors still need to disaggregate organic growth from CyberArk/Chronosphere contribution. But against recent strong CrowdStrike results, this quarter reinforces the idea that large cybersecurity platforms are gaining wallet share, not being displaced by frontier models.

The company also acquired Console, an AI-native platform for enterprise agentic workflows that Palo Alto Networks says will extend Cortex beyond traditional security operations. That is strategically interesting: Cortex increasingly looks less like a SIEM replacement and more like an enterprise automation/control layer.

2. Dell Technologies: a $95bn AI-server backlog is probably the strongest downstream confirmation yet that Nvidia demand is translating into system-level orders

Dell reported record Q2 revenue of $47.0bn, +58% yoy, with Infrastructure Solutions Group revenue up 89% to $31.8bn. AI-optimised server revenue reached $16.4bn, AI-server orders were $60.9bn in the quarter, and backlog exited at an extraordinary $95bn. Dell raised FY27 revenue guidance by $25bn to $192bn, implying +69% yoy, and lifted expected FY27 AI-server revenue from $60bn to $74bn, +200% yoy.

This materially reduces one of the bear arguments around AI infrastructure: that upstream accelerator orders are merely inventory accumulation without end-system conversion. Dell’s numbers suggest actual enterprise/hyperscale system demand is absorbing accelerators at enormous scale.

The more interesting debate now becomes economics rather than demand. AI servers contain vast amounts of Nvidia silicon, HBM and networking, which can make reported revenue explode while leaving system-vendor gross margins structurally lower than traditional enterprise hardware. Dell’s operating leverage this quarter was nevertheless strong: ISG operating income rose 225% to $4.8bn. That is a significant positive read-through for Super Micro, HPE and Lenovo and, upstream, for Nvidia, Broadcom, Arista Networks, Credo, SK Hynix, Micron Technology and Vertiv.

3. MongoDB delivered perhaps the most important infrastructure-software print overnight: 30% growth plus RPO +91% suggests genuine reacceleration

MongoDB reported Q2 revenue of $771.8m, +30% yoy, its fastest growth in several years. Atlas grew approximately 29%, Enterprise Advanced and other revenue 36%, non-GAAP operating margin expanded to 24% from 15%, and FCF almost doubled to $137.6m. The most striking datapoints, however, were RPO +91% to $1.52bn and cRPO +73% to $797m. MongoDB raised FY27 revenue guidance to $2.99–3.03bn, with the second-half increase primarily driven by Atlas.

That is significant for the AI/software debate because MongoDB sits directly underneath applications rather than charging primarily for human seats. AI agents need operational data, retrieval, embeddings and real-time context; MongoDB has now made Search and Vector Search available across self-managed/private-cloud environments and launched an MCP service connecting agents including Claude Code and Codex directly to live Atlas data.

The bull interpretation is that AI is becoming an incremental database workload rather than a substitution threat. The bear case is that extraordinarily strong RPO growth can partly reflect contract duration and Enterprise Advanced timing rather than underlying consumption growth. Nevertheless, this is a very constructive read-through for Snowflake, Datadog and Elastic and further evidence that the market should distinguish infrastructure software from generic seat-based SaaS.

4. Credo: +115% revenue growth confirms that connectivity is scaling almost as aggressively as compute

Credo reported Q1 revenue of $479m, +115% yoy, non-GAAP net income of $236m, +140%, and non-GAAP gross margin of 68%. Q2 revenue guidance of $525–535m implies another substantial sequential increase.

The central investment implication is that AI clusters are not simply buying more accelerators; they are creating a much larger bandwidth and interconnect problem. As clusters scale to hundreds of thousands of accelerators, power-efficient copper links, optical connectivity, retimers and DSPs become increasingly valuable.

The bull case therefore extends beyond Credo into Arista Networks, Broadcom, Marvell Technology, Coherent, Lumentum and Astera Labs. The bear case is valuation and eventual optical migration: active electrical cables have exceptional economics today over shorter distances, but the architecture moves progressively towards optics as bandwidth and distance increase.

Still, seven consecutive quarters of triple-digit-type growth would indicate that connectivity is not a secondary afterthought in the AI architecture; it is becoming a first-order bottleneck.

5. OpenAI’s Astra crossing its own high-risk cyber threshold is one of the most important cybersecurity developments of 2026

OpenAI says its forthcoming Astra model can discover previously unknown vulnerabilities and develop exploitation methods across well-protected systems with little or no human direction. It is the first OpenAI model to trigger the company’s stronger safeguards under its formal safety protocol. OpenAI restarted its largest training run on 28 August after pausing much of its model development following the earlier Hugging Face incident. Astra itself was not involved in that incident.

This is a material inflection point.

Until recently, the cyber bull case rested partly on an assumption that more capable AI would eventually automate offensive security. OpenAI is now explicitly saying one of its models has crossed a threshold where autonomous discovery and exploitation are sufficiently capable to require special controls.

The second-order beneficiaries are not simply application-security vendors. More capable autonomous attackers increase the need for endpoint telemetry, identity governance, network/runtime enforcement, machine-speed SOC and recovery — strengthening the structural case for Palo Alto Networks, CrowdStrike, CyberArk, Zscaler, Cloudflare, Rubrik and SentinelOne.

The bear case for individual vendors remains consolidation: if response must operate at machine speed, enterprises are likely to favour fewer, larger platforms with unified telemetry.

6. Texas’s “ghost demand” crackdown is the first serious challenge to headline data-centre pipeline numbers

Reuters’ review found more than 700GW of large-load electricity requests across parts of the US — more than 10× estimated current US data-centre power use. In Texas alone, large-user requests have risen from roughly 48GW in 2023 to more than 474GW. Texas has frozen new data-centre grid connections while auditing projects, and other states are imposing deposits and stricter qualification requirements.

This is extremely important for investors because AI infrastructure forecasts increasingly extrapolate proposed MW/GW pipelines directly into future semiconductor, server, cooling and power-equipment revenue.

Some of that pipeline is clearly not real. Exelon reduced its high-probability data-centre demand by roughly 40% to 11GW after tightening collateral requirements, while AEP Ohio’s pipeline more than halved after connection fees were imposed.

This does not invalidate the AI-capex thesis — confirmed projects still overwhelm available grid capacity. But it argues for separating: signed/financed/powered projects from connection requests and speculative land positions.

That distinction matters increasingly for Vertiv, Eaton, Equinix, Digital Realty, CoreWeave, Nebius and private data-centre developers.

7. Google’s 396MW Fervo geothermal agreement shows hyperscalers are increasingly becoming power-market makers

Fervo Energy agreed to supply 396MW of geothermal power from its Utah Cape Station project to Alphabet’s Google.

The deal matters less for its absolute MW than for what it says about hyperscaler behaviour. Amazon, Microsoft, Alphabet and Meta increasingly cannot simply buy whatever electricity happens to be available on the grid. They need to underwrite incremental generation, whether through nuclear, gas, renewables, batteries or geothermal.

That creates a second AI-capex cycle running parallel to semiconductors.

The semiconductor cycle is: accelerators → HBM → networking → servers.

The physical-infrastructure cycle is increasingly: land → grid → generation → substations → switchgear → UPS → cooling.

This remains structurally favourable for Eaton and Vertiv, while also increasing the strategic value of utilities, independent power developers and energy-storage infrastructure located near data-centre hubs.

8. Broadcom is turning VMware into an enterprise private-AI platform — potentially a more important long-run VMware monetisation lever than cost cutting

At VMware Explore, Broadcom unveiled VMware Private AI Cloud and VMware AI Factory, positioning VMware Cloud Foundation as infrastructure for enterprises that want to run AI models and agents privately rather than push every workload into hyperscaler public clouds. Broadcom’s investor site lists a broad set of related launches spanning private AI cloud, AI data foundations and model availability.

This matters because enterprise AI architecture is unlikely to be purely public-cloud. Regulated datasets, intellectual property, latency-sensitive workloads and inference economics all create incentives for some models to run on-premises or in private cloud.

That potentially gives Broadcom three simultaneous AI profit pools: custom accelerators + networking + VMware private AI infrastructure.

The bull case is that VMware becomes an enterprise AI orchestration/control plane rather than merely a mature virtualisation asset. The bear case is that enterprises increasingly standardise around hyperscaler Kubernetes/AI platforms and bypass VMware.

Broadcom reports Q3 results later today, and that print is now the next major earnings event. The key datapoints are AI semiconductor revenue, custom-accelerator ramps, networking growth, VMware revenue/ARR and whether management moves its already very large 2027 AI outlook higher.

9. US–Europe AI regulation is diverging sharply, which increasingly becomes a competitive variable for OpenAI, Anthropic, Alphabet and Meta

At the G20 technology meeting on 1 September, the US pushed a set of “Carolina Principles” advocating a relatively hands-off approach to AI regulation, arguing that governments should avoid creating new rules unless genuinely novel risks require them.

That is increasingly at odds with the European trajectory.

The investor debate is not simply philosophical. Regulatory intensity affects model-release speed, training-data access, open-weight distribution, compliance costs and potentially where frontier labs deploy new capabilities first.

The bull case for lighter US regulation is faster innovation and stronger domestic frontier-model leadership. The bear case is that Astra-like autonomous cyber capabilities demonstrate exactly why regulators may ultimately intervene more aggressively.

Either way, large labs such as OpenAI, Anthropic, Google DeepMind and xAI have an advantage because compliance and safety infrastructure carry significant fixed costs. Regulation may therefore paradoxically make the frontier-model industry more concentrated, not less.

10. Google’s AI-search antitrust problem is becoming a direct test of who captures the economics when AI replaces web clicks

EU regulators are questioning publishers about Google’s proposal to let them opt out of AI-generated search features without damaging conventional search ranking. The Commission is examining whether AI Overviews / AI Search reduce publisher traffic while using publisher content to answer queries directly.

This matters because generative search changes Google’s fundamental ecosystem bargain.

Historically: publisher content → Google index → traffic returned to publishers → advertising economics shared indirectly.

AI search increasingly looks like: publisher content → model/context → answer delivered inside Google.

The bull case for Alphabet is obvious: AI answers can preserve Google’s consumer search interface and potentially create new high-value commercial formats. The bear case is regulatory intervention plus erosion of the publisher ecosystem that supplies fresh high-quality information.

The second-order implication is relevant to Cloudflare as well. Content owners increasingly want technological and contractual mechanisms controlling AI crawler access and monetisation. What begins as a Google antitrust issue could become a broader machine-access pricing layer for the internet.

Bottom line

Three datapoints matter most this morning.

First, Palo Alto Networks. Nearly $1bn of net-new NGS ARR in one quarter is very strong evidence that platformisation is converting into wallet consolidation. Combined with CrowdStrike’s recent results, cybersecurity increasingly looks like one of the clearest areas where AI is expanding, rather than cannibalising, software spend.

Second, Dell Technologies. A $95bn AI-server backlog makes it increasingly difficult to argue that the accelerator cycle is being driven principally by speculative semiconductor orders. There is enormous downstream system demand.

Third, MongoDB. Revenue accelerating to 30%, alongside RPO +91%, provides another datapoint that infrastructure software tied to machine data and production applications can reaccelerate as AI scales rather than simply endure the transition.

The market hierarchy therefore looks increasingly coherent: compute and physical bottlenecks remain strong; cybersecurity enforcement is gaining strategic importance; databases/observability benefit from machine-generated workloads; systems of record remain defensible; and generic human-seat workflow software remains the area requiring the most caution.

The new caveat is data-centre pipeline quality. Texas’s crackdown suggests investors should stop treating every announced GW as equivalent. Financed + contracted + powered capacity deserves a premium; speculative connection queues do not. That distinction may become one of the biggest sources of dispersion across AI infrastructure over the next 12–24 months.