The overnight message is unusually clear: AI infrastructure demand is still stronger than the market feared, while software and cybersecurity both produced evidence that AI can be monetised rather than merely discussed. Nvidia’s guide materially extended the duration of the capex cycle; Salesforce’s print weakened the indiscriminate “AI kills SaaS” thesis; CrowdStrike and Okta strengthened the argument that security may be one of the cleanest application-layer beneficiaries. The interesting counterpoint is Nvidia’s reported $12.9bn Hugging Face acquisition, which looks less like another chip deal and more like an attempt to control the model-distribution layer as customers simultaneously develop their own silicon.
1. Nvidia’s print materially extends the AI-capex duration debate: management is now explicitly forecasting c.70% revenue growth in FY28, versus the Street at only c.44%, while Q3 guidance of $108bn is almost $4bn above consensus.
Nvidia guided Q3 revenue to $108bn ±2% versus c.$104.2bn consensus and, unusually, gave a longer-range indication that revenue in the fiscal year ending January 2028 could grow roughly 70%. Nvidia and AWS also plan to deploy an additional 2m GPUs during 2027–28. The shares initially dipped but subsequently rose nearly 5% after hours. This is important because the debate has moved well beyond whether Blackwell demand survives another quarter. A 70% FY28 growth indication effectively argues that Rubin, AI labs, sovereign AI, neoclouds and enterprise deployments can collectively sustain extraordinary growth even off an enormous FY27 base. The bull case is therefore stronger this morning: AI infrastructure looks less like a two-year capex spike and more like a multi-generation compute cycle. The bear case has narrowed to economics and supply. Nvidia explicitly warned that memory shortages will constrain its ability to expand, while investors still need to decide how much future demand is genuinely customer-funded versus supported by Nvidia’s own guarantees, investments and infrastructure financing. Second-order read-through is strongly positive for AVGO, ANET, VRT, MU, TSMC and optical/networking suppliers; the biggest risk to the broader trade now is arguably not demand, but whether scarce memory, power and financing prevent suppliers from converting demand into shipments quickly enough.
2. Nvidia’s reported $12.9bn acquisition of Hugging Face is strategically much more important than its size suggests because Nvidia is trying to own the developer/model distribution layer just as hyperscalers are trying to own the silicon layer.
Reuters, citing The Information, reports Nvidia has agreed to acquire Hugging Face for $12.9bn; Hugging Face reportedly generates only around $150m of annualised revenue, implying an extraordinarily high headline multiple. Neither company had confirmed the transaction to Reuters at the time of publication. The strategic logic is more interesting than near-term financial accretion. Hugging Face is effectively a default distribution and collaboration layer for open-source models, datasets and AI developers. Nvidia already controls CUDA, accelerators and much of the networking stack; owning Hugging Face would give it influence much further upstream over which models developers discover, optimise and deploy. That matters precisely because OpenAI, Google, Amazon and Microsoft increasingly want proprietary accelerators that reduce dependence on Nvidia. The Nvidia bull case is therefore that even if accelerator share fragments, Nvidia can deepen its ecosystem lock-in by controlling tooling, libraries, model optimisation and distribution. The bear case is circularity and valuation: paying c.86× annualised revenue looks aggressive and further demonstrates Nvidia’s willingness to use its balance sheet to protect ecosystem demand. The second-order implication is potentially negative for AMD and other merchant accelerators because software/distribution lock-in around Nvidia becomes harder to break; it is also strategically relevant for GitHub, Google, Databricks and model-hosting platforms, where Hugging Face has traditionally acted as a relatively neutral layer.
3. Salesforce delivered arguably the most important SaaS print of the year: AI adoption is starting to coexist with better financial outcomes, materially weakening the simplest version of the “SaaSpocalypse” thesis.
Q2 revenue rose 11% yoy to $11.35bn, and Salesforce raised FY27 revenue guidance to $46.1–46.4bn from $45.9–46.2bn. Management attributed the uplift partly to momentum in Agentforce, Data 360 and Slack, while Salesforce also launched “Claudeforce”, integrating Anthropic’s Claude models more deeply into its platform. Shares rose roughly 14% after hours. The key investor takeaway is not the EPS beat — adjusted EPS benefited materially from a $2.53/share investment gain and buybacks — but that AI appears to be helping rather than obviously cannibalising the revenue trajectory. This does not prove seat compression is irrelevant: overall licence activity remains volatile, and guidance also includes expected contributions from Contentful and Fin. But the result supports the bull argument that large systems of record can capture AI economics because they control proprietary enterprise data, permissions and workflows. If agents increasingly operate inside Salesforce rather than replacing Salesforce, then the application vendor retains the control plane while model providers become interchangeable intelligence suppliers. That is incrementally constructive for NOW, SAP, WDAY and potentially TEAM, while remaining less comforting for smaller SaaS vendors whose product is essentially UI plus lightweight workflow logic. The second-order debate shifts from “Will AI replace SaaS?” to “Which SaaS platforms become the operating environment in which agents work?” Salesforce gave the bulls their strongest evidence yet.
4. CrowdStrike produced exactly the monetisation proof-point cyber bulls needed: ARR accelerated, net-new business materially strengthened and guidance moved higher, suggesting AI-security demand is becoming measurable rather than merely thematic.
Q2 revenue reached $1.47bn, +26% yoy, versus c.$1.44bn expected; ending ARR increased 25% to $5.84bn, and CrowdStrike raised FY27 revenue guidance to $5.991–6.01bn from $5.91–5.96bn. Shares rose more than 10% after hours. This matters more than another cyber threat headline because the central investor question has been whether autonomous agents and AI-enabled attacks actually create incremental wallet share. CrowdStrike’s result suggests the demand backdrop is broad enough to sustain mid-20s ARR growth from a $5bn-plus base. The structural asymmetry versus application SaaS remains compelling: AI may reduce human licences, but every additional agent, machine identity, cloud workload and automated action generates more activity to monitor and secure. The bull read-through is therefore particularly strong for PANW, ZS and CYBR, where platform consolidation, identity and Zero Trust should benefit from the same underlying proliferation of machine activity. The bear case is now principally valuation: cyber multiples increasingly embed AI-driven TAM expansion, meaning future prints must continue showing above-plan net-new ARR rather than merely resilient renewals. But on last night’s evidence, cyber remains one of the few software categories where AI is simultaneously expanding the attack surface, the number of security objects and the strategic importance of the platform.
5. Okta’s print reinforces that machine and agent identity may become the next major cyber growth vector — and, importantly, the core business is already accelerating before that opportunity becomes material.
Okta reported Q2 revenue of $805m, +11% yoy, subscription revenue of $793m, +12%, and cRPO of $2.585bn, +14% yoy, ahead of expectations; it raised FY27 revenue guidance to $3.22–3.23bn and shares rose roughly 19% after hours. The investor debate here is especially relevant to the wider AI-security thesis. Traditional identity vendors historically monetised human employees, contractors and customers. Agentic AI potentially changes the unit economics because enterprises may eventually operate many more non-human identities than human ones — each requiring authentication, policy, privileges, lifecycle management and auditability. The bull case is therefore that identity TAM can expand even if white-collar employment stagnates or declines. The bear case is that hyperscalers and application platforms will increasingly embed machine identity natively, limiting standalone monetisation. For CYBR, this is particularly interesting because privileged machine identities and secrets are arguably even more complex than traditional workforce identity; for PANW/CRWD, identity becomes another reason to broaden platform coverage. Taken together, CrowdStrike and Okta last night provide a useful contrast to the wider SaaS debate: AI can be disruptive to software seats while simultaneously expanding the underlying security unit count.
Bottom line
last night materially improved the fundamental setup for both AI infrastructure and cybersecurity, while giving the first genuinely encouraging evidence that high-quality application SaaS can defend itself through AI rather than simply endure it. Nvidia’s 70% FY28 growth indication extends the compute cycle far beyond what consensus had modelled; its reported Hugging Face deal shows Nvidia responding to custom-silicon competition by deepening ecosystem control; Salesforce demonstrates that AI agents can coexist with higher guidance; CrowdStrike and Okta demonstrate that machine activity is already translating into stronger security economics. My relative hierarchy this morning therefore remains NVDA/AVGO/ANET/VRT across compute and connectivity, with MRVL increasingly interesting ahead of tonight’s results because custom silicon is the cleanest structural counterpoint to Nvidia, and PANW/CRWD/CYBR/ZS across cyber. The debate I would now push hardest is no longer “AI versus software”. It is control points versus commoditised layers: silicon architecture, model distribution, systems of record, telemetry and identity appear to be retaining economics; generic compute capacity and lightweight application functionality look much less protected.