Jensen Huang told the Goldman Sachs Communacopia + Technology conference in San Francisco on Thursday that cybersecurity will likely be AI’s next major use case. His reasoning was simple. AI now writes a big and growing share of the world’s code. That code ships faster than anyone can review it, and whatever flaws it carries can be found by the same kind of model that wrote them. Then he put it more bluntly: “What better way to create demand than to create a problem.”
He qualified it (there’s a responsible way to do this, he said, and an undesirable one). The line is still worth taking literally. It describes a market structure no other AI application has.
Every other use case Nvidia has put in front of investors needs AI to work. Coding agents have to ship features that run, and drug discovery has to produce molecules that survive trials. If the productivity doesn’t show up, the spending eventually stops; that’s the ROI argument that has hung over hyperscaler capex for two years. Security demand runs the other way. It grows when AI works well for attackers and when AI works badly for the developers shipping its code. It grows fastest when both are true at once, which is roughly what Black Hat described in August, when BTIG came back from Las Vegas saying AI agents had become the leading attack vector and the overall environment was meaningfully worse (CrowdStrike and Palo Alto both closed at records that Monday). Security is also the budget line enterprises cut last. Breach costs and board liability make it close to compulsory. So Huang is pointing at a market where AI adoption produces its own follow-on compute demand, whether or not the first round of adoption paid for itself.
The product design makes the loop explicit. At Fal.Con in Las Vegas last week, CrowdStrike launched SafeMind, a defensive system built on Nvidia’s open Nemotron models and set up so that offensive and defensive models keep attacking and patching each other in a continuous cycle. Huang described the Nemotron work as red teaming and blue teaming. Cisco will sell an Nvidia AI factory platform; Palantir builds on top of it for companies and governments. Both sides of that loop burn inference. The attacker’s model and the defender’s model run on the same silicon, and a stronger attacker justifies a bigger defender. For a company whose product is compute, that’s close to the ideal demand curve. Adversarial markets don’t saturate.
That context changes how the second half of the session reads. Huang dismissed the circular-financing charge with a ratio: “We put in 1 and 100 comes back in.” The off-take behind the projects Nvidia backs is $100 billion of lined-up contracts, he said, though he didn’t say whose or over what period. Nvidia only invests where customers are already queued, its money is a very small part of each project, and he says he isn’t taking risks.
The ratio is probably accurate, and it’s beside the point. A vendor that funded its customers’ entire purchase would be the textbook circular case; 1-to-100 looks like the opposite on paper. What critics care about is what the 1 does. In the neocloud layer (Huang named CoreWeave, Nebius, Nscale, Lambda and Firmus on Thursday) a small Nvidia equity check sits on top of a capital structure that is mostly debt, a lot of it secured on the GPUs themselves. Huang said Nvidia is working with the financial industry to make its systems “investable” and asset-backed, and pointed out that Volta and Ampere hardware still rents. He also said people have started to recognise that wherever he invests is a good place to invest. That’s the mechanism, described by the person running it. The 1 is a credit signal. Its job is to make the other 99 lendable, and the smaller it is relative to the stack, the more weight the stack puts on the signal and the less on Nvidia’s cash.
None of which makes the demand fake. The $100 billion may be exactly what he says it is. The ratio just can’t tell you how much of the 100 would exist without the 1, and that’s the only number that decides whether Nvidia’s revenue is organic. The roughly $13 billion Hugging Face acquisition announced last week sharpened the question, pulling Nvidia deeper into the model layer its own customers occupy.
Which is why the cybersecurity pitch was the better rebuttal, even though Huang didn’t frame it that way. Security spend comes out of enterprise operating budgets. It isn’t financed by a neocloud against GPU collateral, and it doesn’t depend on a frontier lab closing its next round. When a bank buys more AI-driven threat detection because AI-written code widened its attack surface, the money is end demand in the plainest sense: a customer paying from its own income statement for something it can’t skip. If Nvidia wants to shrink the share of its revenue that critics can call circular, the fastest route is growing the share that comes from compulsory spenders. Cybersecurity is the biggest pool of those it has named so far.
The market didn’t give him the credit on Thursday. Nvidia fell 2.5% and Palantir 2%, while CrowdStrike added 0.6% and Palo Alto 1%. The split is at least consistent with the argument: the security names got paid for the demand, and Nvidia got marked down for the financing. Huang repeated his $3 trillion to $4 trillion forecast for AI infrastructure spending by 2030 and said Nvidia can grow revenue 70% a year against unconstrained demand growth above 100%. None of that moved the stock the way the circularity question did.
The number to watch is whether CrowdStrike, Palo Alto or Cisco start reporting AI security revenue as its own line. That figure would do more against the circularity charge than any ratio Huang can offer from a stage.
It’s the one AI revenue line nobody can accuse Nvidia of funding.
Leave a Reply