ProBackend
cloud security incidents
12 hours ago10 min read

The AI Bubble Popping: What Security & Compliance Analysts Need to Know

As big tech's AI capex promises collide with reality, security & compliance analysts face a volatile market. This article examines the AI bubble popping, enterprise AI ROI, and practical guidance for managing AI risk in 2026.

The AI Bubble Popping: What Security & Compliance Analysts Need to Know

You've seen the meme floating around AI forums: "AGI is already here, we just don't realize it yet." It's become an inside joke—an ironic wink at how impressive these systems have gotten. But here's the thing: while the AI community debates whether we've crossed some invisible threshold, the market is telling a different story. The AI bubble is already popping; we just don't realize it yet.

As a security & compliance analyst, you're not here to debate AGI timelines. You're here to figure out what happens when the money stops flowing, when the capex promises don't materialize, and when the tools you're evaluating today might not exist—or might cost ten times more—by next quarter. That's the real question, and it's the one nobody in Silicon Valley wants to answer.

Big tech's Q2 2026 earnings have been pouring in, and the numbers are ugly. We're not talking about penny stocks here—we're talking about the massive cap tech stocks that represent most of the value of the stock market, acting like they're on the brink of collapse. Apple is down 10% in a single day because they warned that next quarter might not be as good as expected due to memory and component prices. IBM lost more value in one day after its earnings warning than it had since Black Monday in 1987. Meta's cash flow decreased dramatically because of all the capex they're spending on new data centers, dropping from $8.5 billion in free cash flow last year to under a billion now.

This is what happens toward the final phases of a speculative bubble, and it's not a great sign. Investors don't know what to make of the current state of things. They're reading tea leaves and swinging wildly between buying and selling. That's when you know something's wrong.

Why the AI Bubble Popping Matters for Enterprise Security

The Register's analysis makes a sharp counterpoint to the AGI meme: "I've seen a lot of memes on the AI forums I follow, many in the AI community say 'AGI is already here, we just don't realize it yet.' I would counter that 'the AI bubble pop is already here, we just don't realize it yet.'" That's the framing that matters for your work.

When Amazon posted $220 billion in capex commitments, investors who dug into the numbers through analyst Corey Quinn's reporting found something troubling. AWS margins were boosted by hedging on energy prices—not core business performance. Amazon's $53.4 billion in deals with Anthropic got counted across AI business revenue, chips business, and AWS segment revenue. One Anthropic dollar gets counted three times.

This kind of financial engineering isn't fraud, but it tells you something important: companies are desperate to justify spending that doesn't yet have clear ROI. For security & compliance teams managing 365 environments, this means vendor lock-in risks, unpredictable pricing, and the possibility that AI capabilities you're building compliance frameworks around might not exist—or might cost ten times more—by next quarter.

The Capex Trap: Why Companies Can't Back Out

Here's the thing that keeps security & compliance analysts up at night: big tech companies are too deep in to climb out. It's the sunk cost fallacy on a scale you've never seen. Amazon, Microsoft, Meta, Google—they've all committed hundreds of billions in capital expenditures. If Amazon stopped next quarter and said, "We're not spending any more money on AI capex," imagine how the market would react. Not well. That's the point.

The demand underwriting $220 billion in capex is concentrated today in a handful of AI labs, one of which Amazon happens to own a meaningful piece of. But the broader enterprise adoption wave remains a forecast. OpenAI and Anthropic are massively valued companies generating real revenue on the order of twenty billion a year. That's not nothing. They're real companies with real demand. But the size of their commitments is predicated on the idea that at some point AI can replace a lot of economic value residing today in all kinds of other industries, not just IT.

If you believe that, then these numbers make sense. If you're a skeptic, a lot of this is "someday, maybe," and we don't actually see it yet.

The Demand Side: AI Isn't Replacing Economic Value (Yet)

This is where the rubber meets the road for your compliance work. I remain unconvinced that LLMs and what we call "AI" will replace most economic activity. Are you going to have them write all your production code? No. Are they great for prototyping? Yes. Can they help an experienced coder do more with less? Yes. It's a mixed bag.

Are they going to replace all medical professionals with medical advice? No. There was an article in the Wall Street Journal recently talking about companies starting to hire again. People who were laid off ostensibly because of AI are being brought back because companies realized they actually need them after all. Tech companies are hiring again.

Many folks who thought AI could replace customer service are finding that even a smart chatbot is subpar compared with an actual human on the phone who can resolve a question. You've got this massively overstated ease of supply—"We'll figure this out, we'll keep plowing capex into these data centers and they'll get built"—but then you have the demand side and the claim that it's going to replace all economic value. Will it? I don't know.

For two or three years, we've been writing stories about the fact that ROI isn't there, that people can't find a use for this, and they're just trying to plug it in to find something to give it a purpose.

What This Means for Your Security Posture

So what does all this mean for you, the security & compliance analyst who's trying to build a defensible posture in 2026? Here's the advice from The Register's analysis, boiled down to what actually matters for your daily work:

Don't jump in with both feet. This is not something that's done and ready to go. The product sets and functions you see today from these big frontier LLM makers may not be what you see a year or five years from now. These are still speculative businesses. This is not an Oracle database, Office 365, Google Search, or AWS. We don't know what they're going to cost or what will be available. Who knows what's going to be built around them?

Hedge your bets. If you're moving into this space, do so in a deliberate fashion and be aware of the uncertainties. The climate is perfect for a squeeze on customers to see just how sticky the products have become. When you have supply chain constraints and investors looking for evidence of a return on investment and ability to deliver a profit, there is incredible pressure to raise prices.

Check your expenses before you move all your workflows over to agentic AI. We're still in the "test and watch your expenses" phase, unless you are a huge tech company like Google that can afford to have employees tokenmax for six months. Most businesses are not in that state.

Look at API prices carefully. OpenAI dropped prices on GPT models significantly, saying it was because they maximized their ability to do more with less. But Thomas Claburn had an excellent piece looking at how Anthropic's latest models use a tremendous number of tokens to deliver the result. If the model consumes four times as many tokens to deliver a result, it's not cheaper. That is somewhat dependent on the harness, reasoning effort, and how they're routing the models.

The Supply Chain Squeeze: Data Centers, GPUs, and Uncertainty

Building data centers is easy words to say or to put in a press release. These things are tremendously complicated. You're dealing with multiple buildings, permitting, siting, water, power, local protests, networking. Are the GPUs and CPUs even available? Apple, which has the greatest supply chain expertise in history, is running into constraints on supplies for iPhones and iPads. I can't imagine that companies intending to build these massive data centers are not going to soon face similar constraints.

That doesn't even get into energy costs and oil prices. It's bonkers. Hyperscalers and cloud providers build their own data centers but also lease a lot of capacity as a hedge because it's easier to walk away from a lease than to commit to maintaining your own facilities. Microsoft has had scares going back a couple of years. There was a point where Microsoft was pulling out of leases and everyone was freaking out, thinking it was the canary in the coal mine. In reality, the hardware changed and the facilities they had signed initial contracts for could not support the hardware. So they killed those agreements because they were for facilities that couldn't take the infrastructure they wanted to deploy.

There's also a problem with how co-location has historically been treated like a real estate deal. That's fine for air-cooled data centers because it's predictable, the infrastructure is simple, and power constraints are reasonable. You don't need the same degree of backup generators, and usually those facilities have different uptime requirements. With AI data centers, it's completely different. The scale at which these are being deployed means that before you even break ground, you have to have figured out contracts with utilities to see if they can even give you the power or build the substations to supply it. You have to figure out where you're going to get water because these are such high power consumption facilities that evaporative cooling is the most cost-effective way to do it.

You can't even get the infrastructure until Nvidia and AMD know that it exists. They don't want allocation sitting on pallets for six months. The supply chain has gotten so screwed up where you can do everything right, but now everything is liquid-cooled and the constraints are so bad that you might be on a waitlist for a year to get the plumbing and manifolds just to get everything hooked up.

The Pendulum Swing: Giant Mode

The Register's analysis captures the mood perfectly with a reference to the "Giant Mode" meme—where someone is shown doing something impressive, only for the camera to pull back and reveal they're actually just standing on someone else's shoulders. That's exactly what's happening with AI capex.

The companies posting these numbers aren't generating them from core business performance alone. They're using financial engineering, cross-charging between subsidiaries, and counting the same dollar multiple times across different reporting segments. It's not illegal, but it tells you everything you need to know about how desperate the narrative has become.

For security & compliance analysts, this means the tools and platforms you're evaluating today may not be available tomorrow. The AI infrastructure stack is still being built on speculation, and when the pendulum swings back, the whole thing could look very different.

What Security & Compliance Teams Should Do Now

Here's the practical advice for your daily work:

1. Don't overcommit to AI-dependent security tools. If your incident response playbook relies on AI-powered threat detection that may not exist in six months, you have a gap. Build fallbacks.

2. Audit your 365 environment for AI-related dependencies. Are there AI-powered compliance checks, automated threat response workflows, or vendor integrations that could disappear? Document them.

3. Watch the capex reports. When Amazon, Microsoft, Meta, and Google start cutting AI spending, it won't be gradual. It'll be sudden. Have a contingency plan for when AI-powered tools become too expensive or unavailable.

4. Focus on fundamentals. The AI bubble popping doesn't mean AI is dead. It means the hype cycle is correcting. Your security & compliance center office 365 tenant, your backup encryption, your access controls—these still matter. Don't let the AI narrative distract from core hygiene.

For more on protecting your 365 environment, see our coverage of Hotel Gateway DNS Poisoning Targets Microsoft 365 and Why Your Cloud Security Incident Response Playbook Needs a Battery Upgrade.

The AI bubble popping is real, even if the AGI meme keeps circulating. As a security & compliance analyst, your job isn't to predict when the bubble bursts—it's to make sure your 365 environment, your incident response playbook, and your compliance frameworks can survive the aftermath. Focus on what you can control: fundamentals, fallbacks, and vigilance.

More blogs