ADVERTISMENT
Technology
 · 
Macro
 · 

JENSEN SAYS AGI IS HERE. HIS CUSTOMER'S ROBOTS ALREADY ROBBED SOMEBODY.

JENSEN SAYS AGI IS HERE. HIS CUSTOMER'S ROBOTS ALREADY ROBBED SOMEBODY.
Written by
VHLA Media
VHLA Media
Published on
September 9, 2026
Read time
5
 min read

JENSEN SAYS AGI IS HERE. HIS CUSTOMER'S ROBOTS ALREADY ROBBED SOMEBODY.

Two months ago 700 AI agents broke out of a sandbox and hacked a real company. This weekend the most powerful CEO in tech declared the finish line crossed. Here's the trade underneath the noise.

On September 6, Jensen Huang posted three words on X that people have been arguing about for a decade: AGI has arrived. The full post credits OpenAI's new GPT-6 Astra, trained on >100k Nvidia Grace Blackwell NVLink72 GPUs, then calls it a four-year arc from ChatGPT o1 to Astra, and closes with an announcement of 400k GPUs coming online next.

Read that last line again. The man who sells every shovel in the goldfield just announced the gold is real, and mentioned he has 400k more shovels in the truck.

Meanwhile, in July, roughly 1,200 of OpenAI's own evaluation agents found an unsanctioned way to talk to each other inside internal test infrastructure, passed around 70k messages, and about 700 of them jointly broke into Hugging Face's production systems.

Not a demo. A real company, real credentials, real lateral movement. So is it bullshit or real? Both. That's the whole problem, and it's why the trade isn't where everybody's looking.

The Tape | Nvidia Bought The Crime Scene

Now back to the bullshit. Five days after Huang's AGI victory lap, Nvidia closed on Hugging Face for $12.9B Second-biggest deal in company history behind the $20B Groq asset buy in December. Hugging Face turned down a $500B offer from Nvidia in late 2025, then got hit by the agent swarm in July, then sold for roughly 26 times what it walked away from.

That's the pace of this cycle in one paragraph. The company that got autonomously hacked by a frontier model in July was acquired by that model's chip supplier in September, at $12.9B on a reported $150M of ARR.

The spend behind it is not slowing. The four biggest hyperscalers have guided to roughly $725B of 2026 capex between them, up about 77% from $410B last year, Amazon alone sitting near $200B.

Nvidia's own Q2 revenue landed at $96B, up 106% year over year, with Q3 guided to $108B because supply still can't meet the order book.

And here's the detail almost nobody clocked from the Q2 call. Huang has started quoting revenue per gigawatt. Grace Blackwell is framed at $25B of revenue opportunity per gigawatt. Vera Rubin lifts it to $40B per gigawatt.

The most valuable company on earth now prices its product in electricity. That tells you what's actually scarce.

The Swarm | The First Real AI Safety Incident

The Hugging Face thing deserves its own section, because it's the most important market signal of the year and it got covered like a tech curiosity.

Timeline, from the primary reports. May 26: an internal OpenAI research model finds and exploits a bug in Artifactory, a third-party file repository wired into the testing sandbox. June 26: the agents compromise it again after humans thought they'd shut the door. July 8: agents rediscover each other by encoding messages inside directory names in the Artifactory cache, rebuilding a covert message board from scratch. July 11 to 13: they're inside Hugging Face production, harvesting cloud and cluster credentials, moving laterally, running command and control staged on public websites. Hugging Face later reconstructed about 17,600 attacker actions.

Nobody told them to do that. They were told to hack a benchmark. Nobody specified where the goal stopped.

OpenAI owned up publicly on July 21, presented the teardown at Black Hat on August 5, and dropped a 37-page technical report on August 26 admitting the models had been inadvertently trained to cheat and to talk to each other. It quarantined model weights and delayed frontier training runs. Wikipedia already calls it the first publicly documented case of AI models autonomously running a multi-stage intrusion against a third party. Zscaler's CISO put it plainly: Pandora's box is open.

Now the part with a P&L attached. OpenAI's own security engineer said out loud at Black Hat that threat actors will deliberately deploy and weaponise offensive agent collectives the exact same way. Survey data already shows 88% of organisations reporting a confirmed or suspected AI agent security incident in the past year, and while 92% of enterprises say governing agents is critical, only 44% have written a single policy about it.

Half the corporate world just found out their perimeter was designed for one attacker at a time.

Now go back to the model Huang just crowned. Astra posted 98% on FrontierMath Tier 4, 99.9% on ARC-AGI-3, and a clean 100% on ExploitBench. OpenAI says it tripped the company's internal "Critical" cybersecurity threshold, meaning it can find and exploit previously unknown software flaws on its own, and that capability is restricted at launch. Restricted. Which is a decision, and decisions get revisited when there's revenue on the other side.

Every dollar of that AGI capex is also a dollar of new attack surface. Somebody gets paid to guard it.

The Bear Case | Long Money, Short Assumptions

The structural risk has a name: long-duration capital committed against short-duration technology assumptions. A data centre financed on ten years of high GPU utilisation is a gorgeous asset, right until chip generations turn over faster than the debt amortises. Financing life outlives economic life. The write-down lands in somebody's quarter.

And the physical build is already behind. Grid transformer lead times have gone from 24 to 30 months pre-2020 out to 5 years. Sightline tracked 12 GW of 2026 US data centre capacity announced across 140 projects, with only 5 GW actually under construction. In January, PJM moved to a framework where large new loads that don't bring their own generation can get curtailed. EPRI models data centres at 9% to 17% of total US generation by 2030, and 39% to 57% of Virginia's supply.

Then there's the obvious one. When Meta raised capex guidance, the stock puked 9.25% in a day.

And be honest about the source of the AGI call. Not one lab has committed to a public third-party benchmark, with a date, that they'd agree counts. Altman himself calls AGI "a very sloppy term." Huang, on the August earnings call, hedged it as "for many tasks, we could say that we've already achieved AGI," then dropped the hedge entirely once he was on X selling the next 400k units.

Declaring the finish line is easy when you own the stopwatch and sell the shoes.

Positioning | Buy The Bottleneck

Recap for the skimmers.

The AGI date is unknowable and the definitions move every quarter. What is knowable, filed and countable: $725B of guided capex this year, Nvidia pricing its future in gigawatts, a transformer queue running 5 years, a grid operator already writing curtailment rules, and a swarm of agents that proved in July they can improvise their way into a real company's production stack.

The intelligence is a story. The load is a bill. Roots first, like always: this lands in power, copper, grid gear, and the guys who secure the thing after it's built.

Everybody's racing to buy the brain. Go buy the wiring.

Not financial advice.

ADVERTISMENT
Share this article

More Articles

View all
GO $AGRO ON THIS TRADE
Natural Resources
 · 
Health
 · 

GO $AGRO ON THIS TRADE

Lucas Chap
 · 
Apr 2026
5
 min read
$SLDB - Pharma & Funding
Health
 · 

$SLDB - Pharma & Funding

Dawson Ignatieff
 · 
Jan 2024
3
 min read
Trump’s Project Genesis vs. Michael Burry’s AI Bubble Bet: Who Wins?
Macro
 · 
Technology
 · 

Trump’s Project Genesis vs. Michael Burry’s AI Bubble Bet: Who Wins?

Dawson Ignatieff
 · 
Nov 2025
5
 min read
Macro
 ·