All briefings

Daily briefing — 29 July 2026

1. Microsoft and Meta report tonight into a market that has stopped rewarding AI spending on faith; the hurdle is now incremental return on capital.

Alphabet has already shown that exceptional cloud growth can coexist with negative free cash flow and sharply higher capex, while the SOX fell another 4.5% on Tuesday and is now roughly 25% below its 22 June peak despite remaining up 56% in 2026. What changed is the burden of proof: investors no longer need evidence that demand exists, but they do need evidence that Azure AI, Copilot, Meta’s ad tools and agentic products are monetising quickly enough to cover depreciation, power, memory and financing costs. Microsoft’s key test is whether Azure acceleration and AI revenue can offset the cost of its infrastructure build; Meta must demonstrate that advertising productivity, rather than a future consumer-agent thesis, can fund its $125–145bn capex envelope. Bulls will argue that capacity constraints and contracted demand make near-term cash-flow compression temporary. Bears will argue that consensus still assumes implausibly smooth margin expansion while former asset-light platforms become capital-intensive utilities. The read-across is binary for MSFT and META, and critical for NVDA, AVGO, MU, ANET and VRT, whose estimates depend on hyperscalers continuing to spend even as shareholders demand discipline.

2. Nvidia’s proposed $250bn OpenAI financing guarantee is the clearest sign yet that the AI infrastructure cycle is becoming circular and supplier-financed.

Nvidia is reportedly discussing a guarantee supporting OpenAI’s lease and debt financing for a 10GW Ohio data-centre project expected to cost more than $500bn, while separately considering financing up to $350bn of chip purchases. For OpenAI, the project would reduce reliance on Microsoft, Amazon and Oracle by giving it greater control over infrastructure; for Nvidia, it could lock in accelerator demand for years. The investor debate is whether this represents extraordinary confidence and ecosystem control, or vendor financing designed to sustain demand that customers cannot fund independently. The latter interpretation matters because OpenAI remains unprofitable and AI infrastructure spending is expected to exceed $700bn this year. The arrangement may extend the cycle for NVDA, TSMC, HBM, networking and power suppliers, but it also shifts credit, utilisation and project-execution risk onto Nvidia’s balance sheet and makes reported demand less exogenous. Second-order losers could include MSFT, AMZN and ORCL if frontier labs increasingly own infrastructure; second-order beneficiaries include SoftBank, data-centre developers and suppliers to power-constrained projects.

3. China’s domestic DUV breakthrough has introduced a second de-rating mechanism for semiconductors: not merely overcapacity, but accelerated import substitution caused by export controls.

ASML has lost about 10% over two sessions, wiping more than €60bn from its market value, after China began producing domestically developed immersion DUV lithography tools. The immediate commercial threat appears limited: China plans roughly five systems in 2026 and 20 in 2027, compared with ASML’s 131 shipments in 2025, and the Chinese machines remain unproven on yield, throughput and reliability. The strategic threat is nonetheless real because China represents about 20%, or roughly €9bn, of ASML’s expected 2026 revenue, while further US restrictions could make an inferior domestic system economically attractive if the alternative is no reliable access to Western tools. Bulls will argue that ASML’s EUV monopoly and two-decade process advantage remain intact; bears will argue that export policy is creating the business case for a structurally separate Chinese equipment stack. The read-across extends beyond ASML to AMAT, LRCX and KLAC, and ultimately to TSMC, Samsung and memory suppliers if Chinese self-sufficiency shortens the duration of Western scarcity rents.

4. F5’s earnings provide a useful counterpoint to the AI-disintermediation narrative

Application and network control points are seeing stronger demand as AI increases complexity and attack surface. F5 reported Q3 revenue of $865m, ahead of the $832.6m consensus estimate, with adjusted EPS of $4.73 versus $4.00 expected. It raised FY26 revenue-growth guidance to 9–10% from 7–8%, and adjusted EPS guidance to $17.21–17.33 from $16.25–16.55. What changed is that AI is contributing not only to software replacement fears but also to measurable demand for traffic management, application delivery and security. The bull case is that autonomous agents, APIs and distributed workloads create more machine-to-machine traffic, identity checks and runtime inspection, allowing F5 to monetise its installed control point. The bear case is that this remains a cyclical security uplift rather than a durable reacceleration, and that hyperscaler-native tools, Cloudflare, Palo Alto and Zscaler eventually absorb more of the application-security layer. The broader read-through is supportive for PANW, CRWD, ZS, NET and DDOG: AI may compress some application-seat economics while simultaneously expanding the compulsory spend around delivery, observability and enforcement.

5. Cybersecurity’s investment case is broadening from corporate ransomware to critical-infrastructure resilience, reinforcing demand but also favouring platforms over point products.

Minnesota disclosed a coordinated cyberattack affecting more than 30 local water systems, while recent attacks have also disrupted consumer, healthcare and industrial organisations. The important change is the target profile: attackers are increasingly exploiting operational infrastructure where downtime has physical-world consequences, raising the willingness to spend on identity, segmentation, asset visibility, network enforcement, recovery and managed detection. The investor debate is therefore less about whether cyber budgets grow and more about where consolidation occurs. PANW, CRWD, MSFT, ZS, FTNT and CYBR are best positioned if customers respond by consolidating telemetry and enforcement across network, endpoint, cloud and identity; F5, TENB, QLYS, RBRK and CVLT benefit from application protection, exposure management and recovery. The second-order risk is that governments mandate higher standards without directly funding them, creating elongated procurement cycles in municipalities and utilities. Nevertheless, critical-infrastructure attacks strengthen the argument that cybersecurity remains a non-discretionary AI-era cost centre even as other software categories face budget cannibalisation