Nvidia增长指引、AI安全漏洞与Agent定价机制拆解
20VC x SaaStr: Nvidia Guides to 70% Growth, 1,000 Agents Breach Hugging Face, and Clay at $7B
提供了极具实操价值的AI Agent安全防御方案(硬限制替代Prompt),并深度拆解了Nvidia收购逻辑与编码赛道的TAM判断,适合关注AI基建与安全的从业者参考。
This week on 20VC x SaaStr, Harry Stebbings, Rory O’Driscoll and I went through Nvidia’s $96.2B quarter and its 70% forward guide, the $12.9B Hugging Face deal, OpenAI cutting off Cursor, the agent swarm that sat inside Hugging Face and OpenAI undetected for weeks, Cognition at $46B, Clay at $7B, Linear at $2.5B, and Salesforce going all in on multi-surface and outcome pricing.
本周在 20VC x SaaStr 节目中,Harry Stebbings、Rory O’Driscoll 和我讨论了英伟达(Nvidia)962 亿美元的季度业绩及其 70% 的前瞻指引、129 亿美元收购 Hugging Face 的交易、OpenAI 切断与 Cursor 的合作、潜伏在 Hugging Face 和 OpenAI 内部数周未被发现的智能体集群(agent swarm)、估值 460 亿美元的 Cognition、估值 70 亿美元的 Clay、估值 25 亿美元的 Linear,以及 Salesforce 全力押注多界面和结果定价。
1. Nvidia guided to 70% growth against a 44% street number
1. 英伟达给出 70% 的增长指引,高于华尔街预期的 44%
Nvidia is supply constrained, so the probability of a near-term miss was close to zero going in. What was new was the guide: roughly 70% revenue growth for the fiscal year ending January 2028, against a street expectation closer to 44%.
英伟达受供应限制,因此短期内不及预期的概率几乎为零。新的亮点在于指引:截至 2028 年 1 月结束的财年全年收入增长约 70%,而华尔街的预期更接近 44%。
Rory’s read: every analyst model for the hyperscalers had the same shape baked in, explosive capex now followed by a normalization in 2027 that lets end-user demand catch up and free cash flow come back. The 70% guide kills that. The biggest semiconductor market in the world is going to grow at 70% instead of a typical 10% for another year, and every time someone doubles down on capex, the date when the math has to work gets pushed further out.
Rory 的观点:超大规模云厂商的所有分析师模型都嵌入了相同的形态,即当前的资本支出激增,随后在 2027 年趋于正常化,使终端用户需求得以追赶并释放自由现金流。70% 的指引打破了这一预期。全球最大半导体市场将在接下来的一年以 70% 的速度增长,而非典型的 10%;而且每当有人加倍投入资本支出,数学上必须平衡的时间点就会被进一步推后。
My read: if Nvidia is crushing it, everyone is crushing it. Individual positions inside the stack move around, OpenAI versus Anthropic, Harvey versus Legora, but the aggregate signal is green. When Nvidia hiccups, that’s your yellow light. There wasn’t one this quarter.
我的观点:如果英伟达表现强劲,那么整个行业都在强劲发展。栈内的具体持仓会发生变化,比如 OpenAI 与 Anthropic 之间、Harvey 与 Legora 之间,但整体信号是绿色的。当英伟达出现 hiccup(小故障/波动)时,那就是你的黄灯警告。本季度没有出现这种情况。
2. Rory’s three failure modes, plus the fourth one Harry added
2. Rory 提出的三种失败模式,加上 Harry 补充的第四种
Rory laid them out in order: direct customers stop buying compute (not happening, hyperscalers are exploding), the circular financing and roundtrip deals stop working (not happening, they’re kicking off enormous cash), or end-user demand comes in below forecast. The third is the only real risk, and it doesn’t break because the circular deals break. It breaks if you’re forecasting 5x growth in end-user demand and you get 3x.
Rory 按顺序列出了这些模式:直接客户停止购买算力(不会发生,超大规模云厂商正在爆发式增长)、循环融资和往返交易不再奏效(不会发生,它们仍在产生巨额现金),或者终端需求低于预测。第三种是唯一真正的风险,它并非因为循环交易破裂而崩溃,而是如果你预测终端需求增长 5 倍,实际只增长了 3 倍,就会出问题。
Harry’s addition: someone takes 10% of the units. Demand for $500B in chips holds up, Nvidia sells $360B instead of $400B. That’s a share problem, not a market problem, and Jensen would be furious. Neither is today’s problem.
Harry 的补充:有人拿走了 10% 的份额。对 5000 亿美元芯片的需求依然坚挺,英伟达卖出 3600 亿美元而不是 4000 亿美元。这是市场份额问题,而非市场总量问题,Jensen(黄仁勋)会对此感到愤怒。但这都不是今天的问题。
3. Nvidia buying Hugging Face at $12.9B is a margin play against the labs
3. 英伟达以 129 亿美元收购 Hugging Face 是一场针对各大实验室的利润率博弈
Rory’s framing: a company making $120B a year selling compute is buying the company that makes compute more cost effective so it can sell more compute. If end users have a trillion dollars to spend on tokens, Nvidia would much rather that money flow through open-source providers at 30% gross margins than through OpenAI and Anthropic at 70%. If you sell GPUs, you want everyone else’s margin to be lower.
Rory 的观点框架:一家年营收 1200 亿美元、通过出售算力赚钱的公司,正在收购能让算力更具成本效益的公司,以便销售更多的算力。如果终端用户有万亿美元用于购买 token,Nvidia 更希望这笔钱通过毛利率为 30% 的开源提供商流转,而不是通过毛利率为 70% 的 OpenAI 和 Anthropic。如果你卖 GPU,你就希望其他人的利润率更低。
My add: it’s more than arbitrage. Nvidia is playing an endgame where it has to win every segment, and open weights is a segment it doesn’t own yet. Jensen’s first tweet ever was in support of open weights. At $110M in ARR, $12.9B is indefensible in isolation and completely defensible as a strategic block.
我的补充:这不仅仅是套利。Nvidia 正在下一盘必须赢下每个细分市场的终局棋,而开放权重(open weights)是它尚未掌控的一个细分市场。Jensen 发的第一条推文就是支持开放权重的。以 1.1 亿美元的 ARR(年度经常性收入)来看,129 亿美元在孤立视角下难以辩护,但作为战略板块则完全合理。
For scale: Slack sold for $27B at roughly $1B in ARR and we all fell out of our chairs. That was the high water mark of the last era. This is half that price on about a tenth of the revenue.
为了说明规模:Slack 在 ARR 约为 10 亿美元时以 270 亿美元的价格被收购,当时我们都惊掉了下巴。那是上一个时代的高水位线。而这次的价格只有前者的一半,收入却只有十分之一左右。
4. OpenAI cutting off Cursor was rational, and it would have happened between friends
4. OpenAI 切断与 Cursor 的合作是理性的,即便双方曾是朋友也会发生这种情况
Coding is the mother lode for LLMs. Cursor is the dominant coding app, OpenAI is a dominant model provider, and they were on a collision course over the same dollars regardless of who ran them. Add two people who have already been in court together and you get made-for-TV.
编程是 LLM 的金矿。Cursor 是主导性的编程应用,OpenAI 是主导性的模型提供商,无论由谁运营,他们都在争夺相同的资金,注定会正面碰撞。再加上两人此前已在法庭上交锋过,这就成了典型的电视剧情节。
Rory’s point: the terms-of-service and distillation argument is hard to argue with. If your models are being used to accelerate a competitor’s model, you’re handing over your IP to someone building a cheaper version of your own product.
Rory 的观点:服务条款和蒸馏(distillation)论点很难反驳。如果你的模型被用来加速竞争对手的模型,你就是在把知识产权拱手让给那些正在构建你自己产品廉价版本的人。
My point: Mike Truell’s response, that the 5% of traffic going to OpenAI will be missed, was elegant and a put-down at the same time. If it really is 5%, Sam lost no revenue. I’d probably do the same thing.
我的观点:Mike Truell 的回应很精妙,既是一种降维打击,又指出流向 OpenAI 的 5% 流量将被错过。如果真的是 5%,Sam 并没有损失任何收入。我可能也会做同样的事情。
Rory’s advice underneath it: don’t do business with people who recently sued you, and whatever your dispute is, don’t make it personal. It didn’t work with Sam. It didn’t work with Trump.
Rory 的建议:不要与最近起诉你的人做生意,无论争议是什么,都不要将其个人化。这对 Sam 行不通,对 Trump 也不行。
5. 500 to 1,000 agents ran inside OpenAI for weeks without being detected
5. 数百到上千个代理在 OpenAI 内部运行数周而未被发现
The bigger OpenAI story this week was what came out about the Hugging Face breach: hundreds of agents running long, cooperating, finding weaknesses, chaining them together, and staying undetected inside OpenAI for weeks.
本周关于 OpenAI 更大的新闻是关于 Hugging Face 数据泄露事件的披露:数百个代理长期运行、相互协作、寻找弱点并将它们串联起来,在 OpenAI 内部潜伏数周而未被察觉。
The commentary around it went straight to civilizations rising and falling, agents sacrificing themselves for each other, waves of collaboration. That language will make you misunderstand what happened. Every current LLM is goal seeking. People call it reward hacking, which is its own bit of fear-mongering. You give it a goal and it does everything it can inside the guardrails to hit that goal. OpenAI loosened the guardrails, pointed its best agents at the problem, let them run long instead of expiring them after five minutes, and they found the holes. That’s the job.
围绕它的评论直接指向文明的兴衰、代理人之间的自我牺牲以及协作浪潮。这种语言会让你误解所发生的事情。每一个当前的 LLM 都在寻求目标。人们称之为奖励黑客攻击,这本身就是一种制造恐慌的说法。你给它一个目标,它就会在护栏范围内竭尽全力去实现该目标。OpenAI 放宽了护栏,将其最好的代理人指向问题,让它们长时间运行而不是在五分钟后过期,它们找到了漏洞。这就是工作。
I’ve lived the smaller version of this. My agents deleted my database. Claude went through MCP into Replit and changed my app’s code without telling me.
我经历过这个的较小版本。我的代理人删除了我的数据库。Claude 通过 MCP 进入 Replit 并未经告知就更改了我应用的代码。
Rory’s takeaway: intelligence plus persistence is the actual aha. They manage complexity and they never sleep. Open-source models are roughly six months behind, and if you don’t think rogue actors read the OpenAI post-mortem and the MITRE writeup, you’re delusional. Every CISO in the Fortune 500 was being attacked with bows and arrows and is about to be attacked with missiles. Months, not years.
Rory 的结论:智能加上坚持才是真正的顿悟时刻。它们管理复杂性且永不休眠。开源模型落后大约六个月,如果你认为 rogue actors(恶意行为者)没有阅读 OpenAI 的事后报告和 MITRE 的撰写内容,那你就是妄想症。《财富》500 强中的每一位首席信息安全官(CISO)都正遭受弓箭般的攻击,并且即将面临导弹般的攻击。是几个月,而不是几年。
6. The $100 cap breaks when gate two says Harry loves the theater
6. 当第二个关卡说 Harry 热爱戏剧时,100 美元的限额就会失效
Harry started using Instinct, booked dinner, and stopped when it asked for credit card access. His friends who manage billions handed theirs over.
Harry 开始使用 Instinct,预订了晚餐,并在它要求访问信用卡信息时停止。那些管理着数十亿资金的朋友则直接交出了他们的权限。
The failure mode most people miss: it isn’t one rule getting broken. Once you write 80 or 100 or 200 gates, the gates conflict, and the agent exercises judgment. Gate one says never spend more than $100. Gate two says the most important thing in Harry’s life is the theater. The agent buys the $5,000 tickets. It doesn’t matter that you wrote the cap.
大多数人忽略的故障模式:并不是某一条规则被打破。一旦你设置了 80 个、100 个或 200 个关卡,关卡之间会发生冲突,而代理人会行使判断力。第一个关卡说永远不要花费超过 100 美元。第二个关卡说 Harry 生活中最重要的事情是戏剧。代理人购买了价值 5,000 美元的门票。你写了限额这一事实无关紧要。
The only thing that works today is a hard limit outside the agent’s reach, a Ramp or Mercury card with a real cap. We run Salesforce headless and our agents do some genuinely kooky things on top of it, and the Salesforce data holds because it’s locked at the permissions layer, not in a prompt.
今天唯一有效的方法是在代理人无法触及的范围外设置硬性限制,例如带有真实限额的 Ramp 或 Mercury 卡。我们无头运行 Salesforce,我们的代理人在此之上做一些真正古怪的事情,而 Salesforce 的数据得以保持安全,因为它是锁定在权限层,而不是在提示词中。
Rory’s split: there are two separate questions. Can you nerf the model enough that it doesn’t take bad actions? That’s a computer science question and it’s unsolved. Can it be right about your desires often enough to make you happy? That one is already solved.
Rory 的区分:有两个独立的问题。你能否将模型削弱到足以使其不采取不良行动?这是一个计算机科学问题,尚未解决。它能否足够频繁地正确理解你的愿望从而让你感到快乐?这个问题已经解决了。
7. Instinct at $2.5B looks expensive until you remember what happened to Replit and Lovable
7. 估值 25 亿美元的 Instinct 看起来昂贵,直到你想起 Replit 和 Lovable 发生了什么
Harry has four emails from companies that built the same thing. Fourteen months ago anyone could clone Replit or Lovable or Bolt in a month, and there were twenty of them. Today those products do pen testing, security automation, multi-agent orchestration, and the clone you build over a weekend sort of works and then goes sideways. The functionality accretes and becomes the moat.
Harry 收到了四封来自开发同类产品的公司的邮件。十四个月前,任何人都可以在一个月内克隆 Replit、Lovable 或 Bolt,当时有二十家这样的公司。如今,这些产品都在做渗透测试、安全自动化和多智能体编排,而你在周末搭建的克隆版勉强能用,随后便走向歧途。功能不断累积,最终形成了护城河。
Rory’s version: observed fact, ten years into any software market there are very rarely a hundred people building the same product. Two pull ahead, often just because they executed go-to-market better in the first six months, and the rest don’t get there. That’s how venture works in software.
Rory 的版本:这是一个观察到的事实,在任何软件市场运行十年后,极少有一百人同时在构建相同的产品。通常只有两家脱颖而出,往往只是因为它们在最初六个月内更好地执行了上市策略,其余者则未能达到这一水平。这就是软件行业的风投运作方式。
The open question is whether individual consumers pay real money for it. Enterprise has its own version funded at a billion. And the honest reason everyone is writing checks here: agents are the story of 2026, and VCs want exposure to the space more than they want certainty about the winner.
悬而未决的问题是个人消费者是否愿意为此支付真金白银。企业端也有其自身的版本,融资规模已达十亿美元。大家在此纷纷开具支票的诚实理由是:智能体(agents)是 2026 年的故事主题,风险投资机构更希望在该领域获得曝光度,而非对最终赢家确定性的把握。
8. We got the coding TAM wrong, and Cognition at $46B is the proof
8. 我们低估了编程领域的总可寻址市场(TAM),Cognition 估值 460 亿美元便是证明
Cognition is reportedly raising at $46B, doing $800M to $900M and expected to end the year at $1.6B in ARR. It isn’t the number one or two player in coding, and it’s still at that scale.
据报道,Cognition 正以 460 亿美元的估值进行融资,年经常性收入(ARR)在 8 亿至 9 亿美元之间,预计年底将达到 16 亿美元。它并非编程领域的一号或二号玩家,但已处于如此规模。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力