← The stand
The Collection, Volume 1, Number 3. The Unwatched Bill. Monday 17 August 2026, Melbourne.

The Collection


Vol. 1, No. 3  ·  Monday 17 August 2026  ·  Melbourne

The Unwatched Bill


Editor’s Letter

The cheap token is a trap.

Amazon spent some $1.8 million on a Claude project that ran unnoticed for five months. A senior employee said it is difficult to figure out how much anything AI-related costs.

Azeem Azhar’s own OpenClaw agent blew through $500 a day, then a tedious audit got it to $6. Even at $6 a day that is about $2,000 a year for one person who is not writing code. Ramp’s July numbers, in the same letter: the top 1 percent of businesses spent a median $7,400 per employee on AI. The top 10 percent spent $650. The median firm spent $11.95.

The cheap token is a trap.

Meanwhile Anthropic is in an SEC quiet period before a fall IPO, and bulls are leaking $2 trillion valuations and $190 to $200 billion of 2028 revenue from unnamed people. Gary Marcus’s dissection is behind a paywall. We have the lede only.

Seats are not adoption. Enterprise rollouts often produce 5 to 10 percent power users, 20 percent who struggle, and 70 percent who barely engage, while dashboards still call it adoption.

Yesterday the labs could not occupy the floor above themselves. Today the invoice is the floor. Nobody is watching the run.

The cheap token is a trap.

The Collection · The Unwatched BillLetter

04  ·  The Invoice

The Unwatched Run

A $6 agent still needs a bookkeeper. Amazon did not have one for five months.

Amazon spent some $1.8 million on a Claude project that ran for five months. A senior employee said: “It’s difficult to figure out how much anything [AI-related] costs.”

Azhar had a smaller version at home. R Mini Arnold, his OpenClaw agent, grew in complexity until Nathan Warren called out a few days when the bot blew through $500 a day. The subsequent audit was tedious and worth it. Many processes were still on older, higher-tier models, like Opus 4.5. Newer, smaller models and a $200-a-month Codex allowance brought the run to $6 a day, lower than it had been for months, and more capable than ever.

It’s difficult to figure out how much anything [AI-related] costs.

Has $494 a day just disappeared from genAI revenue? In some sense, yes, Azhar writes, but that was an anomaly. RMA had typically cost $50 to $60 a day before it went wild. Even at $6 a day it runs to $2,000 a year from one reader who is not writing code.

US companies are still spending. Ramp reports that in July the top 1 percent of businesses spent a median $7,400 per employee on AI. The top 10 percent spent $650. The median firm spent $11.95 per employee.

Opus 5 is driving a large chunk of Anthropic’s revenue growth. SpaceXAI is picking a pricing fight with Grok 4.6. The new model undercuts top rivals by more than 60 percent. The token got cheaper. The run did not get a bookkeeper.

Quiet Period

Anthropic is in an SEC-monitored quiet period before a fall IPO. That has not stopped leakers and bulls from pricing the company in public.

Friday’s Reuters report said Anthropic is projecting 2028 revenue of roughly $190 billion to $200 billion, “according to two people familiar with the company’s financials.” The math is undisclosed. Bloomberg received leaked Q2 documents. On the All-In podcast, Gavin Baker claimed Anthropic was making money on every token. A couple of weeks earlier Dwarkesh Patel projected that Anthropic likely ends the year with about $100 to $150 billion of revenue, a claim he later partly walked back.

Gary Marcus says he dissects these claims and explains what was left out. That dissection is behind the paywall. We have not read it. We are not inventing his numbers.

The quiet period is for the company. The leaks are for the price.

The VC Corner, citing Ars Technica, says investors expect Anthropic to target a $2 trillion-plus valuation this October, potentially the largest IPO ever, on projected 2026 annualized revenue of $100 to $120 billion. Export controls and customers moving toward cheaper models could test that story.

Chamath’s week is a different kind of spend. Anthropic is in talks to buy Decart for about $6 billion, a 50 percent premium to the startup’s nearly $4 billion valuation in May. Decart has two businesses: real-time world models, and software that improves chip performance. The Decart Optimization Stack tunes models across Nvidia GPUs, Google TPUs, Amazon Trainium, and AMD chips. If the deal closes it would be Anthropic’s fourth acquisition of 2026 and its largest: Bun in December 2025, Vercept in February, Coefficient Bio in April, Stainless in mid-2026. A hardware-agnostic performance layer is how you lower the cost of serving Claude before you take the company public.

Catch and Release

SpaceX completed its $60 billion all-stock acquisition of Anysphere, issuing about 389 million Class A shares and folding Cursor into SpaceXAI as a wholly owned subsidiary. Mostly Metrics calls it the most money anyone has ever paid for a venture-backed company. It passed Wiz ($32 billion, Google) and WhatsApp ($22 billion, Meta) on the way.

CJ’s fishing story is the mechanism. Massachusetts keeps striped bass only between 28 and 31 inches. Too small, throw it back. Too big, throw it back. The big ones are the breeders. There is such a thing as being too big to acquire.

Every funding round increases operating optionality while decreasing exit optionality.

The Sequence’s editorial is the stack. Grok 4.6 now flows into Cursor, Grok Build, GitHub Copilot, APIs, and autonomous agents. The model is becoming the stack. One future is vertically integrated: compute, model, agent, application, user. The other is modular: open model, proprietary data, reinforcement learning, owned intelligence. Both are racing for feedback loops, not GPUs.

River AI, two months old, founded by xAI co-founder Igor Babuschkin, raised $1.1 billion across seed and Series A, led by General Catalyst and AMP PBC, with Nvidia and AMD Ventures. The thesis is the mirror of the labs: train on your own data and own the result. Lovable raised $400 million at $13.3 billion. Cognition is in talks above $1 billion at a $40 billion valuation, less than three months after $26 billion.

On 10 August Nvidia signed memorandums of understanding with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR. Each firm plans a financing platform for Nvidia-based data centers. Together they aim to mobilize more than $500 billion from outside investors. They are MOUs. Capital commitments would come later. The ambition is to make computing equipment financeable like aircraft or power plants. KKR’s Waldemar Szlezak noted that A100s still earn at high utilization six or seven years in. Larry Fink likened it to the birth of mortgage-backed securities in the 1970s. A 100 MW data center can require as many as 3 million hours of labor. PitchBook, via The VC Corner, notes that no capital has been raised, and that Nvidia’s $266.1 billion in deal participation already exceeds trailing cash flow. That is a question, not a verdict.

Seats Are Not Adoption

Enterprise AI rollouts often create a barbell: 5 to 10 percent become power users, 20 percent struggle, and 70 percent barely engage, while dashboards still call it adoption. The real metric is output, not seats activated. Study the top-user workflows. Push the rest into background agents.

Atlassian’s Teamwork Lab found teams with a single designated AI superuser were 18 percent more likely to produce top-scoring work than teams without one. Adding just one superuser boosts a team’s innovation rates by 19 percent. Concentrated expertise beats broad, shallow usage.

Seats are not adoption.

Retool’s product lead for governance published a runtime framework around three questions: who is acting, what can they reach, and can you stay in control. The survey behind it, 307 CTOs, CIOs, and CISOs: only 8 percent rated their internal AI governance as “strong.” Just 5 percent felt confident they could see what is running in production.

Gemini hit 1 billion monthly active users, up from 950 million in Q2, matching ChatGPT’s scale and becoming Google’s 14th product over that line. Sixty-three percent of Gemini users now engage via voice. The app generates more than 150 million images a day. It has more than 100 million active users on iOS.

On Vercel’s AI Gateway, DeepSeek passed Google as the second-largest provider by token volume, 25 percent of July volume against Google’s 11 percent. Average price per token fell 13.6 percent month over month. Open-weight models more than doubled their share of gateway spend to 8.6 percent. Eighty-one percent of July’s gateway tokens ran on models that did not exist six months earlier.

Shopify’s CTO, Mikhail Parakhin, pushed back on the idea that AI is eating organic search. Shopify data: AI-referred sessions grew 3 times year over year, while organic sessions still grew 12 percent off a larger base. A counter-data point. Not a victory lap.

The Prompt Is Not the Fence

We gave agents tools. The results, from Alpha Signal: wiped production databases, mass-deleted executive emails, leaked API tokens. “You are a helpful and safe assistant” does not hold the line.

An OpenClaw agent, deployed by Meta’s own alignment director, mass-deleted over 200 emails from her primary inbox. A developer used Claude Code to manage a cloud migration. The agent autonomously wiped a production database and 2.5 years of work. A coding agent using Claude Opus caused a major outage while cleaning up staging data. In all three cases the agents executed exactly what they determined was the correct action. The underlying systems allowed those actions to proceed.

The agents executed exactly what they determined was the correct action.

The industry is moving from prompt engineering to systems engineering. Three layers. Infrastructure: NemoClaw sandboxes the agent with Landlock, seccomp, and network namespaces, and injects real API keys only on approved egress. Architecture: NanoClaw cuts a million-line codebase to a few thousand and runs each session in an ephemeral container, with Echo rebuilding the runtime to strip known CVEs. Network: Brex’s CrabTrap sits as an HTTP and HTTPS proxy. Low-risk GETs pass. High-risk POSTs go to an LLM-as-a-judge, then a human if the judge blocks.

Katie Parrott vibe-coded Tastemaker, added an agent connector, published it, and took “it worked” as proof it was safe. A later review by GPT-5.6 Sol found a public registration route that could have been exploited. No evidence anyone had accessed user data. The flaw was still there. Learn enough to catch the obvious problems. Ask someone with security experience. Get an independent check before you ship code an agent wrote.

Dan Shipper’s frame on last week’s OpenAI and Hugging Face incident, which we already ran as news: give a persistent model no safeguards and an exploit to run, and of course it finds the gaps. Agents behave like water. Keeping them out may require other agents watching what they do.

Azeem’s dinner-party morsel, one sentence: a hidden prompt injection in a court filing asked AI to side with the plaintiff in case the court used LLMs. The case name is not in the letter.

The Neighbours Pay

The cost of building data centers spills onto neighboring towns. Each additional data center within 25 miles raises a neighboring town’s bond spread by about 10 basis points. The effect fades with distance, roughly 4 basis points at 75 miles.

Neighbors also borrow more. A town with the average number of nearby data centers issues about $34 million more in debt over the following year. The effect roughly doubles between six and thirty-six months.

If the state gave the company a tax break, the money comes out of the school budget.

In states with tax breaks, the bill goes through schools. After a state adopts a data center incentive, state transfers to school districts fall by roughly $673 per student. The towns nearby get the strain and no bargaining chips. When they need to borrow for a school or a road, lenders charge them more.

Jasmine Sun’s reporting from the frontlines of data-center backlash is more than worth the time. We are not recapping her piece. Some teams inside Microsoft are working on regenerative data-center designs based on biomimicry. Anthropic is hiring a chip-design team. The invoice, again, is not only the token.

It’s difficult to figure out how much anything [AI-related] costs.

The Collection · The Unwatched BillPiece

Standing Orders

Four rules we are keeping

A bookkeeper. Output, not seats. Named math. A fence that is not a prompt.

  1. I

    Put a bookkeeper on every agent

    Five months unnoticed is the failure. Amazon’s $1.8 million and Azhar’s $500 days are the same story at two scales. A $6 agent still needs someone watching the run.

  2. II

    Count output, not seats

    Seventy percent barely engaging is not adoption. One designated superuser beat a floor of shallow licences. Dashboards that count seats are lying.

  3. III

    Do not price an IPO off unnamed math

    Reuters two people. A walk-back. A paywalled dissection. Keep the leaks on the page and the valuation in pencil.

  4. IV

    A prompt is not a fence

    Permissions, a sandbox, and a human on send or delete. The agents already did what they thought was correct.

The Collection · The Unwatched BillOrders