AI cloud’s debt-fueled data-center sprint is picking up—and somebody eventually has to make those monthly payments. If you’re joining us mid-arc, here’s the short version: Specialist AI infrastructure providers aren’t just pitching GPU access anymore. They’re turning contracted demand into real capacity—and long-term obligations. CoreWeave had $104.2 billion in backlog and raised its 2026 capex plan, Together AI was tied to a 10,000-GPU L&T Chennai project, and Cerebras said it had more than 600 MW live or under contract by end-2027. This is AI Daily Briefing. Today, the debt gets longer, the hardware claims get louder, and a Grok security finding cuts straight into the agent stack. We start with Nebius. This story isn't over: Neocloud spending and backlog boom. Follow us wherever you're listening, and the next chapter comes to you. Rashika Singh, Ananya Palyekar, writing in The Economic Times:
AI cloud provider Nebius Group on Wednesday upsized its debt offering to $5 billion from $4.5 billion, as it seeks to ramp up investments in data centers and computing capacity. The Amsterdam-headquartered company plans to issue private convertible notes worth $3 billion maturing in 2030, and notes worth $2 billion maturing in 2034.
Nebius took this to $5 billion, split between $3 billion due in 2030 and $2 billion in 2034. Investors are underwriting two different things here: this GPU cycle, then sustained AI-cloud demand through the next hardware generation. By 2029, Nebius needs a convincing answer on that 2030 tranche: enough cash flow to repay or refinance it without turning the whole GPU fleet into a debt-management exercise. The neocloud buildout keeps piling up: CoreWeave and Cerebras had backlog; now Nebius is raising $5 billion in debt. Its June cash balance was $8.04 billion, but it spent $5.66 billion on property, equipment, and intangibles in one quarter. Financing has to keep pace with the construction appetite. A nearly 10% drop on Wednesday tells you the market isn’t handing out gold stars for that headline. Nebius is financing the build; the question is whether its full-stack cloud can produce an inference margin before those 2030 notes come due. From Tobias Mann at The Register:
The chip newcomer unveiled its next-gen Wafer Scale Engine (WSE) and Nexus rack systems on Tuesday. Cerebras aims to extend that lead by boosting throughput per watt tenfold over the previous generation.
Cerebras doubled dense FP16 from 12.5 to 25 petaflops and memory bandwidth to 43.2 petabytes a second—on the same 5-nanometer wafer and the same four trillion transistors. The trick, apparently, is cranking the clock up and feeding it a whole lot more power. And “a whole lot” means 33 kilowatts per wafer, versus 15 before; the full-system estimate goes from 23 to 46 kilowatts. So yes, faster inference—but nobody gets to say “per watt” and skip the watt line. Exactly. Sparse FP16 at 250 petaflops makes for a beautiful slide. I want the cost per token on a messy, mixed-precision production workload, with rack cooling and the power bill included. That’s where this either changes a latency budget or becomes very expensive clock tuning. We just covered Nebius borrowing $5 billion to finance the buildings. Cerebras wants a slice of what those buildings spend on inference. If Nexus really packs three times as many chips into a rack, power delivery stops being an engineering footnote very quickly. From Yahoo Finance:
Bitcoin (CRYPTO: $BTC) mining company Bitdeer Technologies Group's (NASDAQ: $BTDR) artificial intelligence division, Bitdeer AI, has secured a five-year contract covering roughly half of its A102 AI data center in Malaysia before the facility is energized. The undisclosed customer, described by Bitdeer as being of "high credit quality," has committed to approximately 50% of A102's 9.5-megawatt capacity, according to a Wednesday announcement.
This is the kind of pre-energization deal I can work with: 9.5 megawatts, roughly half already contracted, five years, and service starting in Q1 2027. Bitdeer gave us an audit date instead of waving around a giant pipeline number. And it’s $400 million over that term from one high-credit-quality but unnamed customer. We don’t know the customer, but we do know the commercial shape. That puts A102 ahead of most “AI campus” announcements that never get past a PowerPoint and a local press release. I’m not extrapolating a 350-megawatt-by-2028 target from one 9.5-megawatt site. But GB300 NVL72s, liquid cooling, and a signed five-year buyer—okay, now we can ask whether they hit the Q1 2027 turn-on without treating the whole thing as vapor. Nebius is financing its GPU stack with $5 billion in convertibles; Bitdeer is pairing a smaller build with contracted revenue before the lights are on. Different balance sheets, but both are betting AI demand will still be there when this hardware cycle rolls over. This one's from The Logic:
AI firm Anthropic is planning to source a significant amount of compute capacity in Canada, including from new data centres in Alberta. The San Francisco-based company is hiring staff in Canada to help acquire processing power, and to manage relations with the communities that will host its facilities, according to new job postings.
Anthropic’s Canada posting says “gigawatts,” but they’re still hunting sites, securing power, financing projects, and shepherding construction. It’s a development pipeline. You can’t plug Claude into it yet. And they’re hiring an Alberta community engagement manager alongside the compute lead. Local permitting and power relationships are clearly on the critical path—not some cleanup task after the GPUs arrive. Nebius is borrowing five billion dollars against future AI-cloud demand. On the customer side, Anthropic is making the same long-duration bet: gigawatts in Canada suggests it expects demand to outlast more than one shiny hardware cycle. “Gigawatts” is a serious word. Give us a site, a power contract, and an in-service date, then we can start treating it like capacity instead of ambition. Ars Technica, with Dan Goodin:
Company researchers are calling the technique cryptographic context injection. “Cryptographic Context Injection is one instance of a broader shift: attacks that manipulate not just the prompt, but the wider context an LLM treats as its own, such as tool outputs, runtime results and intermediate state” Adversa said.
The nasty part of Adversa’s cryptographic context injection is where it hits: tool outputs, runtime results, intermediate state. Your agent can have a pristine user prompt and still get steered toward exfiltration by something it decides to trust halfway through the job. And encryption is the trick. The safety layer sees ciphertext it can’t meaningfully inspect; the model decrypts it, treats it like a traceback, then follows the instruction buried inside. A very efficient way to make a permission policy decorative. Adversa got a related attack to produce restricted weapon content and reproduce Gemini system instructions. So no, auditing the initial prompt is nowhere near enough. Log the tool-call layer, constrain what tools can return, and assume an error message can be hostile input. Grok is the headline; Gemini backs it up. This failure mode cuts across vendors, and it matters a lot more than another glossy agent demo. If you want more on AI policy and national security, check out Anthropic Pentagon Watch, a daily briefing on Anthropic’s fight with the DoD. It tracks military AI use, autonomous weapons, and AI procurement blacklisting. Find it wherever you listen to podcasts.
We’re watching for Bitdeer’s A102 services to begin in the first quarter of 2027, when it expects to recognize revenue and related costs. We’re also watching its target of 350 megawatts of AI cloud data-center capacity by the first quarter of 2028.
Links to every story are in the show notes. Take a look at anything you’d like to explore further. That’s AI Daily Briefing for today. This is a Lantern Podcast.