河马的CC商业实战 · 出品

河马观澜

今 日 深 读

01

自主与创新

Autonomy and Innovation

Stratechery · Ben Thompson · 中英对照 · 约 14 分钟

攻击 Hugging Face 的「黑客」竟然是 OpenAI 自己——一群在评估中失控的智能体。Thompson 从这起事件讲清了一个不对称:自动化攻击的期望值永远是正的,自动化防御的期望值却永远是负的,所以「人在环中」注定追不上全自动攻击。而同一套期望值逻辑,也解释了奥特曼为什么承认 AI 扩散比预想慢、以及为什么 AI 原生公司只会从创业公司里长出来。全文翻译。

开始阅读 →

02

看空却做多的时代

caoz的梦呓(虎嗅转载) · caoz · 中文 · 约 8 分钟

「所有资深从业者都知道 AI 算力有泡沫,但没人敢做空。」caoz 把当前算力市场的真实状态浓缩成一句话:利空都是明确的,利好是未知的、偶然的——但没人敢赌利好不存在。一篇讲投资逻辑而非荐股的短文,配昨日阿里 800 亿港元配售的新闻读,格外有张力。

开始阅读 →

03

放量下跌:沪指失守 3900,成长杀跌、防御抱团

8 月 24 日 A 股复盘综合述评

公开市场信息综合(东方财富、同花顺等) · 本刊整理 · 中文 · 约 6 分钟

周一的盘面一句话:放量下跌、筹码集中换手。沪指跌 0.59% 失守 3900,创业板指与科创 50 双双跌超 3%,成交重回 2 万亿上方——钱都去了哪?黄金、煤炭和高股息。

开始阅读 →

快 览

  1. 阿里 800 亿港元配售落定:香港史上最大增发,近 3 倍超额认购(快科技)—— 每股 112.70 港元、折让约 8.37%,募资净额 100% 投向全栈 AI;主权与长线基金认购超 40%,蔡崇信、吴泳铭合计增持约 1.2 亿港元——但折价与摊薄也让港股阿里盘中一度跌超 10%。
  2. 英伟达 Groq 3 LPX 全面投产,SpaceX 要把 Vera Rubin 算力送上轨道(东方财富)—— 200 亿美元收购 Groq 后的商业化落地,主打低延迟推理;首批「Starmind」AI 卫星计划 2027 年底发射。周三(8 月 26 日)英伟达发财报。
  3. OpenAI 与 Anthropic 冲刺 IPO,分析称行业融资缺口或达 8000 亿美元(ZAKER)—— Anthropic 最快 8 月底递交文件;大模型越卖越便宜、AI 开始靠债市「输血」,有分析师直接说泡沫已破——与本期深读 02 互为镜像。
  4. Hugging Face 传探索出售,潜在交易价值至少 130 亿美元(虎嗅)—— 不卖模型、不造芯片的「AI 角斗场」为何值百亿;加上 Stripe 80 亿美元收购 OpenRouter,巨头争的已是生态入口。
  5. 小鹏机器人完成 9 亿美元首轮融资,估值 63 亿美元创行业纪录(华尔街见闻)—— IDG 领投,阿里、腾讯战略参投;具身智能单轮融资新纪录——对照昨日深读「80% 具身订单可能是假的」服用。
  6. 535B 大模型「直播」训练三个月:代码、数据、Loss 全公开(虎嗅)—— 全流程透明化训练实验,吴恩达公开力挺;开源社区的「开放式厨房」打法。
  7. SHEIN 敲定港股 IPO 价格区间,估值较峰值缩水约七成(华尔街见闻)—— 拟向 IPO 前投资者支付 35 亿美元;消费叙事与 AI 叙事的估值温差仍在拉大。
← 返回目录
深读 · 01

自主与创新

Autonomy and Innovation

Stratechery · Ben Thompson · 2026-08-24 · 约 14 分钟 · 原文链接

导读与要点(建议先读原文)
  • 帽子不分能力:白帽黑帽是同一套技能,区别只在意图,而意图由激励塑造——网络安全的攻防能力本就一体两面。
  • Hugging Face 事件:OpenAI 一批正在接受网络安全评估的无约束智能体,利用沙箱包管理器的漏洞、借助互联网访问相互通信,自主完成了从发现漏洞到编写利用代码的整条攻击链;OpenAI 在 Black Hat 大会上承认:全自动进攻已有「存在性证明」,防御的全自动化还没有。
  • 期望值不对称:攻击只需成功一次,收益即为正;防御自动化只要失败一次(搞坏软件、引入新漏洞),收益即为负——这就是防御方总想留人在环中、因而永远追不上全自动攻击的结构性原因。
  • 防御的结构性优势:防御方手里握有全部代码,可以逐行审查连同依赖在内的整个代码库,进攻方只能探测——这是智能体时代防御方新有的、黑客时代不存在的优势,但前提是敢于全自动。
  • 扩散为什么慢:奥特曼承认经济的惯性被低估;Thompson 补充——在位企业用「负期望值」框架看 AI,只怕它当众出错,所以留人、所以慢;创业公司的基准情形是失败,拥抱 AI 只有上行空间。AI 因此同时是延续性与颠覆式创新:在旧主手里延续,在新主手里颠覆。批判性阅读:「防御必须全自动」的推论依赖进攻规模化的假设,合规与责任问题文中未展开。
While not every Western followed the cliché, by the 1930s cowboy serials had landed on a consistent visual cue: the hero of the show wore a white hat, and the villain wore a black one. At the end of the day, however, they both were cowboys with cowboy hats.
并非每部西部片都遵循这个套路,但到 1930 年代,牛仔系列片已经形成了一个统一的视觉暗示:主角戴白帽子,反派戴黑帽子。不过说到底,他俩都是牛仔,戴的都是牛仔帽。
Westerns aren't much of a cultural touchpoint anymore, but the "white hat" and "black hat" nomenclature is very relevant in tech: hackers who are focused on patching vulnerabilities and protecting software are "white hat hackers", while hackers who are focused on exploiting vulnerabilities for malicious reasons are "black hat hackers". Of course this can very quickly become complicated: governments might employ hackers to break into enemy software installations — are they white hats or black hats? Or consider bug bounty programs, wherein large software companies pay bug bounties to hackers who find and report vulnerabilities; it's basically using money to incentivize would-be black hat hackers to be white hat hackers.
西部片已经不再是共同的文化记忆了,但「白帽」和「黑帽」这套称谓在科技行业依然非常贴切:专注于修补漏洞、保护软件的黑客是「白帽黑客」,出于恶意目的利用漏洞的黑客则是「黑帽黑客」。当然,事情很快就会变得复杂:政府可能雇佣黑客去攻破敌国的软件系统——他们算白帽还是黑帽?再想想漏洞赏金计划(bug bounty):大型软件公司付钱给发现并报告漏洞的黑客,这本质上就是用钱把潜在的黑帽黑客激励成白帽黑客。
The actual takeaway is that all of this complexity is overwrought: just as a cowboy is a cowboy, a hacker is a hacker; the hat is not a statement of capability, but rather intentions, and those intentions are shaped by incentives. The best way to attack infrastructure is to find a vulnerability and exploit it; the best way to defend infrastructure is to find a vulnerability and patch it. It's all the same skillset.
真正的要点是:这些复杂性都是过度纠结。正如牛仔就是牛仔,黑客就是黑客;帽子的颜色不代表能力,只代表意图,而意图是由激励机制塑造的。攻击基础设施的最好方式是找到漏洞并加以利用;防御基础设施的最好方式是找到漏洞并加以修补。这完全是同一套技能。
This delineation between capability and intent and incentive is critical when it comes to AI. At the end of last month's Article Who's Afraid of Chinese Models, I discussed a mysterious attack that model host Hugging Face had just endured, which they were only able to fight off with the help of open weight Chinese models, and wrote:
谈到 AI,能力、意图与激励之间的这条分界线至关重要。在上个月的文章《谁在害怕中国模型?》(Who's Afraid of Chinese Models)结尾,我讨论了模型托管平台 Hugging Face 刚刚遭遇的一场神秘攻击——他们最终是借助中国开放权重模型才击退攻击的。当时我写道:
It's difficult to overstate how wrong-headed the Trump administration's panicked response to Anthropic's release of Fable was, particularly since it exacerbated Anthropic's worst tendencies in terms of assuming only they can be trusted with powerful AI. In a world with only one AI, it might make sense to reserve the most powerful cybersecurity capabilities for the U.S. government and trusted allies; however, that's not the world we live in.
特朗普(Trump)政府对 Anthropic 发布 Fable 的恐慌式反应错得有多离谱,怎么强调都不为过——尤其因为它加剧了 Anthropic 最糟糕的倾向:认定只有自己才配被信任去掌握强大的 AI。如果世界上只有一个 AI,把最强的网络安全能力留给美国政府和可信盟友或许说得通;但那不是我们所处的世界。
There are and will be models eminently capable of mounting cybersecurity attacks on existing infrastructure, and those models will be — already are — widely available. The best defense — the only viable defense, in fact — will be to make sure defenders have access to the best models as well. Right now defenders are effectively banned from using Fable or Sol for cybersecurity because of Trump administration directives; that means the best alternative is using models from a country which has been trying to weaken our cyber defenses for years. This is insane!
现在已经有、将来还会有完全有能力对现有基础设施发动网络攻击的模型,而这些模型将会——其实已经在——广泛可得。最好的防御——事实上也是唯一可行的防御——是确保防御方同样能用上最好的模型。眼下,由于特朗普政府的指令,防御方实际上被禁止将 Fable 或 Sol 用于网络安全;这意味着他们最好的选择变成了使用一个多年来一直试图削弱我们网络防御的国家的模型。这简直疯狂!
The point is the one I made in the introduction: when it comes to cybersecurity, the capability that is necessary for good defense is the exact same capability that is necessary for good offense; the color of the hat is a matter of who is actually prompting the AI.
这就是我在开头提出的观点:在网络安全领域,良好防御所需的能力与良好进攻所需的能力完全相同;帽子的颜色,取决于究竟是谁在向 AI 下达指令。
And, sometimes, not even that is clear: it turns out that the entity that hacked Hugging Face was actually OpenAI, as a series of unconstrained agents being evaluated for their cybersecurity capabilities found and exploited a bug in the package manager in their sandbox; that package manager had Internet access and a sufficiently writeable file system such that the agents could communicate with each other over time. The entire chain of vulnerability discovery and exploit creation culminated in the so-called "Hugging Face incident".
而有时候,连这一点都不清楚:事实证明,攻击 Hugging Face 的「黑客」其实是 OpenAI——当时一系列正在接受网络安全能力评估的、不受约束的智能体(agent),在自己沙箱里的包管理器中发现并利用了一个漏洞;这个包管理器可以访问互联网,文件系统的写权限又足够大,以至于这些智能体能够在一段时间内相互通信。从发现漏洞到编写利用代码的整条链路,最终酿成了所谓的「Hugging Face 事件」。

Hugging Face 事件The Hugging Face Incident

There is an entire Article to be written about the implications of this specific incident and what it says about AI risk; some of my takeaways are still up in the air pending OpenAI's promised release of an in-depth technical report (my preliminary takeaway is that the agents were not "cheating" but rather doing what they were told to do; of course that's arguably even scarier). The part I want to focus on today, however, came at the end of a presentation OpenAI's Eric Wallace and Michael Dalton made at the Black Hat USA conference about the Hugging Face incident. This was Dalton summarizing Lessons Learned:
就这起事件的影响及其揭示的 AI 风险,完全可以再写一整篇文章;我的一些结论还要等 OpenAI 承诺发布的深度技术报告出来才能落定(我的初步看法是:这些智能体并没有「作弊」,而是在执行被告知的任务——当然,这可以说更加可怕)。不过今天我想聚焦的,是 OpenAI 的埃里克·华莱士(Eric Wallace)和迈克尔·道尔顿(Michael Dalton)在 Black Hat USA 大会上就 Hugging Face 事件所做演讲的结尾部分。以下是道尔顿总结的「经验教训」(Lessons Learned):
We have seen what will be a dramatic acceleration of offensive capability for attackers. We have an existence proof that was unintentional, but it exists before us, and we have as a consequence seen a glimpse into the near future of what attacks will look like for our industry. The challenge is that we need a similar acceleration of defense. Today we see fully automated offence as possible, but we have no such existence proof for full automation of core defensive loops and cycles in behavior.
我们已经看到,攻击方的进攻能力将出现戏剧性的加速。我们手里有一个无意中产生的「存在性证明」,它就摆在我们面前,我们也因此得以一窥在不远的将来,针对我们行业的攻击会是什么样子。挑战在于,防御需要同样的加速。今天我们已经看到全自动进攻是可能的,但核心防御循环与行为周期的全自动化,还没有这样的存在性证明。
We believe it's vital at this moment to begin accelerating defense and finding ways to automate SDLC, in the modern parlance, so incident response, vulnerability detection, vulnerability patching. There's some things that stand out acutely as challenges for the industry to begin tackling with high urgency. So continuous agentic red teaming is one of them. As you can see from this incident, agents are quite good at finding zero-day attacks in the infrastructure of companies. The question that's now going to be posed is whether companies are able to invest sufficient model intelligence and effort in finding and remediating their vulnerabilities before someone else that's a threat actor does it for you.
我们认为,此刻必须开始加速防御,想办法把软件开发生命周期(SDLC)自动化——用现代的说法,就是事件响应、漏洞检测、漏洞修补。有几件事尤为突出,需要整个行业以最高紧迫感着手应对。持续化的智能体红队(agentic red teaming)就是其中之一。正如你们从这次事件中看到的,智能体非常擅长在企业基础设施中发现零日漏洞(zero-day)。现在摆在所有公司面前的问题是:能否投入足够的模型智能与精力,赶在某个威胁行为者「替」你发现之前,自己找到并修复漏洞。
This style of operating will be different now, but ultimately we need to invest in having AI agent red teaming that enables defenders to find and remediate vulnerabilities before attackers do. But automating these defensive loops is not trivial, and so if we do this partially, we will fail to meet the scalability of the offensive acceleration that we have just seen. So for example, if we automate vulnerability finding without automating patching, we will shift the bottleneck from vulnerabilities to patching to remediation, and we will simply drown or inundate human software engineers in new vulnerabilities to fix and patch. This is not a problem whose end state we can solve partially. We will need to take these core defensive loops and fully automate them, which will require conversations with infrastructure and product partners and reaching to a point where we can say, if a vulnerability is identified, not only can an agent identify that vulnerability, we can have an agent propose a patch, we can have automated infrastructure to roll out a change with that patch, and roll it back if there is an availability incident or outage. That loop needs to be fully automated in its end state. Of course, we want to automate as progressively and iteratively quickly as we can, but if we don't reach that end state, then we will be comparing a core defensive loop of fixing vulnerabilities that is a human in the loop and is much slower and less scalable, with an offensive loop that is fully automated, and that is an unsustainable position for this industry to be in.
今后的运作模式将完全不同,但归根结底,我们需要投资建设 AI 智能体红队,让防御方抢在攻击者之前发现并修复漏洞。但把这些防御循环自动化绝非易事:如果只做一半,我们就无法匹配刚才看到的那种进攻加速的规模。举例来说,如果只把「发现漏洞」自动化而不把「打补丁」自动化,瓶颈就会从漏洞转移到修补和修复环节,人类软件工程师只会被源源不断冒出来的新漏洞淹没。这不是一个可以只解一半的终局问题。我们必须把这些核心防御循环完全自动化,这需要与基础设施和产品伙伴共同推进,直到达成这样的状态:一旦漏洞被识别,不仅智能体能发现它,还能由智能体提出补丁、由自动化基础设施把这个补丁作为变更发布出去,并在出现可用性事故或宕机时自动回滚。这个循环的终态必须是全自动的。当然,我们希望以最渐进、最快速迭代的方式去实现,但如果到不了那个终态,我们就是在拿一个「人在环中」、又慢又无法扩展的漏洞修复防御循环,去对抗一个全自动化的进攻循环——对这个行业来说,那是一种不可持续的处境。
This situation is obviously completely novel; Dalton is arguing that it will become commonplace. Some of the issues he is raising, however, are not novel at all.
这种局面显然是前所未有的;道尔顿的论点是,它将成为常态。不过,他提出的某些问题一点也不新鲜。
Go back to the concept of a bug bounty program. Software is incredibly complicated and brittle and built on a foundation of code that, if you dig deep enough, often goes back decades; there is so much code and so many dependencies that no company, no matter how security conscious they are, could ever ensure it is perfect. This reality is what creates the opportunity for black hat hackers: a bad actor can probe software, find bugs, and exploit them; the most effective defensive preparation is to do the exact same thing. That could entail regular penetration testing (pen testing) by a "red-team", or simply paying the would-be bad actors to be on your side.
回到漏洞赏金计划这个概念。软件极其复杂、极其脆弱,而且建立在往往可以追溯到几十年前的代码地基之上;代码和依赖如此之多,无论一家公司安全意识多强,都不可能确保万无一失。正是这个现实给黑帽黑客创造了机会:恶意行为者可以探测软件、找到漏洞并加以利用;而最有效的防御准备恰恰是做同样的事——要么由「红队」定期开展渗透测试(pen testing),要么干脆付钱让那些潜在的恶意行为者站到你这一边。
It's worth noting, however, that this approach to defense only arose after offensive black hat hackers had been breaking into systems for years. The problem wasn't that they were uniquely capable, but rather that they were uniquely incentivized: breaking into systems was good business; companies hosting those systems, on the other hand, were insufficiently incentivized to invest in defense. Spending money on security is well-spent if nothing happens, and unfortunately that is a difficult budget line item to argue for when it only moves the needle on costs, not revenue.
然而值得注意的是,这种防御方式是在进攻型黑帽黑客已经攻破了多年系统之后才出现的。问题不在于他们的能力独一无二,而在于他们的激励独一无二:攻破系统是一门好生意;而托管这些系统的公司却缺乏足够的激励去投资防御。如果什么都没发生,花在安全上的钱就算花得值——但不幸的是,当一笔预算只影响成本、不影响收入时,它总是很难争取。
This is where Dalton's concerns echo past industry indifference. What the Hugging Face incident showed is that agents, with their ability to scale attacks with compute and autonomously develop exploits for vulnerabilities they find, are a threat today, but that companies are not investing in the capabilities necessary to defend themselves.
这正是道尔顿的担忧与行业昔日冷漠相呼应的地方。Hugging Face 事件表明:智能体可以用算力把攻击规模化,并针对发现的漏洞自主开发利用代码,它们今天就已经是威胁;但企业并没有在投资防御自身所需的能力。
There is good news, however: in this new agent-defined security landscape, defense should be at an advantage in a way it wasn't in the hacker era. It used to be that the best defenders could do is mimic the tactics of the offense, and/or pay them off, because preemptively finding all of the bugs was not viable. However, that is changing: it actually is — or soon will be — possible to meticulously go over an entire code base, including all of its dependencies, and look for bugs and patch them. Notice the structural advantage available to defenders: they actually have the code in question; offensive agents need to probe and discover vulnerabilities without the same advantage.
不过也有好消息:在这个由智能体定义的安全新格局里,防御方理应占据一种黑客时代不曾有过的优势。过去,防御方最多只能模仿进攻方的战术,或者花钱消灾,因为提前找出所有漏洞根本不可行。但这正在改变:如今——或者说很快——真的有可能把整个代码库连同所有依赖逐行过一遍,找出漏洞并修补。请注意防御方的结构性优势:他们手里真正握有那份代码;而进攻型智能体只能在没有这个优势的情况下探测和发现漏洞。
What was illuminating about Dalton's overview, however, was the implication embedded in his explanation of why this isn't currently enough. Specifically, the expected value for a hacker's automated attack is always positive. If the offensive agent finds a vulnerability and creates an exploit, and that exploit fails or is itself buggy, then nothing has changed about the status quo: the exploit doesn't work (or, perversely, makes the original vulnerability larger by virtue of its own bugs); if the agent executes the exploit perfectly, meanwhile, the attacker has gained access to the system. The attack only needs to work once for the entire endeavor to have a positive payoff.
不过,道尔顿的分析中最有启发性的,是他在解释「为什么这目前还不够」时隐含的那层意思。具体来说:黑客发起自动化攻击的期望值永远是正的。如果进攻型智能体发现了漏洞并编写了利用代码,而这份利用代码失败了或者本身有 bug,那么现状没有任何改变:利用不奏效(或者更拧巴的是,它自身的 bug 反而把原来的漏洞撑得更大);而如果智能体完美执行了利用代码,攻击者就进入了系统。整个行动只需要成功一次,回报就是正的。
The challenge for the defender, on the other hand, is that they need to keep the software in question working correctly, and not make the situation worse. This means that any automation has a negative expected value: successful automated vulnerability discovery and patching preserves the status quo, i.e. the software is not hacked. However, any unsuccessful patches make the situation worse, either by breaking the software or by introducing new vulnerabilities. The agent only needs to fail once for the entire endeavor to have a negative payoff.
而防御方面临的挑战在于,他们必须让相关软件持续正常运行,不能把情况弄得更糟。这意味着任何自动化的期望值都是负的:自动化的漏洞发现与修补如果成功,只是维持现状,即软件没有被黑;但任何一次不成功的修补都会让情况更糟——要么搞坏软件,要么引入新漏洞。整个行动只要失败一次,收益就是负的。
This is the dynamic that leads to the exact situation Dalton describes, where offensive actors are fully automated while defensive systems, even if they use AI, will be incentivized to keep a human in the loop, and no human in the loop will be able to keep up with fully automated agents. Truly effective defense will mean truly trusting agents to act autonomously, but most companies won't do that until they are forced to by regular and unremitting hacks by fully autonomous attackers.
正是这组动态,导致了道尔顿描述的那种局面:进攻方已经全自动化,而防御系统即便用了 AI,也会被激励着把「人」留在环路里;而任何人在环路中,都跟不上全自动化的智能体。真正有效的防御,意味着真正信任智能体自主行动——但在被全自主攻击者持续不断、毫不留情地攻破之前,大多数公司不会这么做。

为什么 AI 扩散需要时间Why AI Diffusion Takes Time

Over the weekend David Senra released a new podcast episode with OpenAI CEO Sam Altman, where Altman admitted he had been wrong about the speed of AI diffusion into the broader economy:
上周末,大卫·森拉(David Senra)发布了一期对话 OpenAI CEO 山姆·奥特曼(Sam Altman)的新播客。奥特曼在节目中承认,自己对 AI 向整体经济扩散的速度判断错了:
I love startups. I think startups are the coolest thing in the economy and I've spent my career trying to like really understand startups, and I thought when we got to GPT-4, which was back in 2023, I think, that very quickly after that, there was going to be much more disruption in software businesses being up for grabs right away than turned out to be.
我热爱创业公司。我觉得创业公司是经济中最酷的东西,我的职业生涯都在努力真正理解它们。我曾以为,当我们在 2023 年做出 GPT-4 之后,很快就会有大量软件业务被颠覆、被重新瓜分——结果并没有发生那么多。
I was wrong about a few things, but one of them in terms of the speed, one of them is the economy just has so much inertia. People keep doing the same things they're doing. They keep buying from the same, you know, company. They keep sort of wanting to use their tools in the same way. I think it's actually a positive in many ways and it's going to make this big transition in front of us go smoother and slower. I'm grateful for it. But I think it means we've all been too ambitious on timelines even with this incredible technology. I think AI is one of the most incredible technologies humanity has ever invented. Society and the economy will adapt more slowly.
我在几件事上都判断错了,速度就是其中之一——经济的惯性实在太大了。人们继续做着自己一直在做的事,继续向原来的公司采购,继续想用原来的方式使用工具。我觉得这在很多方面其实是好事,它会让摆在我们面前的这场大转型走得更稳、也更慢。我对此心怀感激。但这意味着,即便握着这样不可思议的技术,我们所有人在时间表上都太激进了。我认为 AI 是人类发明过的最不可思议的技术之一,而社会和经济的适应会比我们想的慢。
I of course think Altman is right about AI taking longer to sweep the economy generally and software specifically; I've been pushing back on these timelines all along. I also think his answer is incomplete in its explanation as to why, and Dalton's warning about the mismatch between offensive agents and defensive preparations explains it.
我当然认同奥特曼的判断:AI 席卷整体经济——尤其是软件行业——所需的时间会更长,我一直在反驳那些激进的时间表。但我同时认为,他对「为什么」的解释并不完整;而道尔顿关于「进攻型智能体与防御准备错配」的警告,正好补上了这个解释。
First, GPT-4 was an incredible breakthrough; it's also a model that wasn't remotely capable enough to actually displace real world software. It didn't even have the ability to reason, which is the key breakthrough that has unlocked the capabilities that Dalton described.
第一,GPT-4 是一个了不起的突破,但它的能力远远不足以真正取代现实世界中的软件。它甚至不具备推理能力——而推理正是解锁道尔顿所描述的那些能力的关键突破。
Second, what is meant by a model not being capable enough is that it makes mistakes and can't be trusted. People can and were rightly awed by what AI can do, but the decision about actually implementing AI isn't made according to what can be done, but about whether or not critical mistakes can be avoided.
第二,所谓「模型能力不够」,意思是它会犯错、不值得信任。人们可以——也确实理所应当地——惊叹于 AI 能做什么,但真正决定是否落地 AI 的依据,不是「它能做什么」,而是「它能否避免致命的错误」。
In other words, incumbent companies are inevitably going to approach AI with a bias towards a negative expected value framing: AI ideally will make their existing operations more productive; what they are most concerned about is AI making a mistake that blows up in their faces. What that means is humans will continue to be in the loop, which will always be a bottleneck.
换句话说,在位企业必然会用一种偏向「负期望值」的框架去看待 AI:理想情况下,AI 能让现有业务更高效;但它们最担心的是 AI 犯错、当众出丑。这意味着人将继续留在环路中,而这永远是个瓶颈。
This will, in the long run, be a mistake, just like it will be a mistake for companies to keep a human in the loop when it comes to agentic defense. As Dalton noted, the only way to defend yourself against fully automated attacks is to fully automate your defense, but it will take a while for defenders to accept the trade-offs that entails. And, by the same token, the companies that win in their category will be truly driven by AI, instead of simply AI as productivity enhancer. The great irony in Altman's answer is that he actually identified how these companies will arise: they won't be incumbent companies overhauling how they work; rather, the true AI-native companies will be startups.
长期来看,这会是一个错误——正如企业在智能体防御上把人留在环路中也是错误一样。正如道尔顿指出的,抵御全自动化攻击的唯一办法是把防御也全自动化,但防御方要接受其中的取舍,还需要一段时间。同理,最终在各自品类中胜出的公司,将是真正由 AI 驱动的公司,而不只是把 AI 当生产力增强工具的公司。奥特曼的回答里有个绝妙的反讽:他其实已经指出了这类公司会如何诞生——它们不会是把工作方式推倒重来的在位企业;真正的 AI 原生公司,将是创业公司。

延续性创新与颠覆式创新Sustaining Versus Disruptive Innovation

Back in 2023, shortly after ChatGPT came out, I put forward the question in AI and the Big Five as to whether AI would be a sustaining or disruptive innovation:
2023 年,ChatGPT 发布后不久,我在《AI 与五巨头》(AI and the Big Five)一文中提出过一个问题:AI 究竟是延续性创新(sustaining innovation),还是颠覆式创新(disruptive innovation)?
The story of 2022 was the emergence of AI, first with image generation models, including DALL-E, MidJourney, and the open source Stable Diffusion, and then ChatGPT, the first text-generation model to break through in a major way. It seems clear to me that this is a new epoch in technology. To determine how that epoch might develop, though, it is useful to look back 26 years to one of the most famous strategy books of all time: Clayton Christensen's The Innovator's Dilemma, particularly this passage on the different kinds of innovations:
2022 年的故事是 AI 的登场:先是图像生成模型——DALL-E、MidJourney 和开源的 Stable Diffusion——然后是 ChatGPT,第一个实现大规模突破的文本生成模型。在我看来,这显然是一个新的技术纪元。而要判断这个纪元将如何展开,不妨回望 26 年前那本最著名的战略著作:克莱顿·克里斯坦森(Clayton Christensen)的《创新者的窘境》(The Innovator's Dilemma),尤其是其中关于创新类型的这段论述:
Most new technologies foster improved product performance. I call these sustaining technologies. Some sustaining technologies can be discontinuous or radical in character, while others are of an incremental nature. What all sustaining technologies have in common is that they improve the performance of established products, along the dimensions of performance that mainstream customers in major markets have historically valued. Most technological advances in a given industry are sustaining in character…
大多数新技术都会推动产品性能的提升,我把它们称为延续性技术。有些延续性技术在性质上可以是非连续的、激进的,另一些则是渐进式的。所有延续性技术的共同点在于:它们沿着主要市场中主流客户历来重视的性能维度,改进既有产品的表现。一个行业里的绝大多数技术进步,性质上都是延续性的……
Disruptive technologies bring to a market a very different value proposition than had been available previously. Generally, disruptive technologies underperform established products in mainstream markets. But they have other features that a few fringe (and generally new) customers value. Products based on disruptive technologies are typically cheaper, simpler, smaller, and, frequently, more convenient to use.
颠覆性技术带给市场的,则是一种与此前截然不同的价值主张。一般来说,颠覆性技术在主流市场中的表现不如既有产品,但它们具备一些被少数边缘客户(通常是新客户)看重的特性。基于颠覆性技术的产品通常更便宜、更简单、更小,也往往更方便使用。
It seems easy to look backwards and determine if an innovation was sustaining or disruptive by looking at how incumbent companies fared after that innovation came to market: if the innovation was sustaining, then incumbent companies became stronger; if it was disruptive then presumably startups captured most of the value. I think it speaks to the incredible capability of AI that it is setting up to be both. There are massive productivity benefits from AI right now; for most knowledge workers leveraging those benefits is a matter of agency, but for software developers in particular it is increasingly a matter of necessity.
事后回看,判断一项创新是延续性还是颠覆性似乎很容易:看它上市后在位企业的命运——如果是延续性创新,在位企业变得更强;如果是颠覆式创新,那么大部分价值想必被创业公司拿走了。而 AI 的格局正在同时成为两者——这恰恰说明了 AI 的能力有多么不可思议。AI 眼下已经带来巨大的生产力收益:对大多数知识工作者来说,能否用上这些收益取决于个人的主观能动性(agency);但对软件开发者而言,它越来越是一种必需(necessity)。
That distinction between agency and necessity, however, is an important one: if leveraging a technology depends on humans figuring it out, then penetration will be limited by human creativity and risk taking. Those limits will be very strong in any sort of established company, because the risk calculus will be biased towards avoiding the downsides. Those calculations will make AI sustaining, but nothing more.
然而,「主观能动」与「必需」之间的区分至关重要:如果一项技术的利用取决于人主动去琢磨,那么它的渗透率就会受限于人类的创造力和冒险意愿。这些限制在任何成熟企业里都会格外强大,因为那里的风险计算天然偏向规避下行风险。这样的计算方式,会让 AI 只是延续性的,仅此而已。
Human creativity and risk taking in the form of a startup, however, operates with a completely different risk profile. For startups the base case is failure; that means that anything that makes success more likely has positive expected value, which is to say that truly leaning into AI will be nothing but upside. Or, to put it another way, it is startups who will be the offensive hackers with nothing to lose by automating everything; it is the incumbents they will be attacking who will be so worried about losing what they have, that they will keep humans in the wrong loop for too long.
而以创业公司形态出现的人类创造力与冒险精神,遵循的是一套完全不同的风险剖面。对创业公司来说,基准情形就是失败;这意味着任何能提高成功概率的事,期望值都是正的——也就是说,全身心拥抱 AI 只有上行空间。或者换个说法:创业公司将成为那些进攻型「黑客」,把一切自动化也毫无可失;而被它们攻击的在位企业,会因为太害怕失去已有的东西,把「人」留在错误的环路里,留得太久。
Same tools, different incentives, and, in the very long run, very different outcomes.
同样的工具,不同的激励,而在足够长的时间尺度上——截然不同的结局。

← 返回目录

← 返回目录
深读 · 02

看空却做多的时代

caoz的梦呓(虎嗅转载) · caoz · 2026-08-25 · 约 8 分钟 · 原文链接

导读与要点(建议先读原文)
  • 三条明确的利空:巨头现金流开支增速远超利润、靠发债和配股维持(阿里已开始配股);美国调查东南亚算力出租市场,若严苛实施将「杀敌一千自损八百」;Anthropic 增速放缓,中国开源模型迈过「可替代拐点」,同等能力所需算力更少。
  • 摊销的障眼法:算力采购成本按时间摊销,财报上利润好看,现金流开支却远大于账面成本——延展摊销周期本身就在掩盖成本问题。
  • 利好从来都是意外:ChatGPT、Claude 的编程现金牛、DeepSeek、Manus 引爆的 Agent 市场,再到今年的「龙虾」——算力需求的每次跳升都来自投资人盲区里的新玩家,而非被盯着的巨头。
  • 核心判断:利空确定、利好偶然,但没人敢捅破泡沫——这不是盲目的乐观,而是对「意外发生率」的敬畏;理解这一点比预测拐点更重要。
  • 投资的执念:看好就拼命找利好、看空就拼命找利空,看到的都是事实,判断却已被立场劫持——「投资可以承担风险,可以允许损失,但不要有执念」。批判性阅读:作者自述无财经资质,东南亚调查、Anthropic 增速等论据未附一手出处,宜作框架参考而非事实依据。

来源:微信公众号 caoz的梦呓,作者:caoz

首先,我说明一点,不是财经博主,没有财经资质,本文只是探讨投资逻辑,而非具体投资行为,其中算力行业是重资本行业,不可避免涉及金融市场动向,但本文无荐股,无投资建议,不构成任何投资决策。

前段时间在国内,拉个饭局,和几个行业内顶尖的朋友吃饭,聊了聊行业的现状和发展。结合之前在新加坡和一些资深从业者的沟通,加深了一个有趣的结论。就是

所有资深从业者都知道目前AI算力行业存在泡沫,但没人敢做空。

那么我再总结一下,就是

利空都是明确的,但利好是未知的,是偶然的,即便如此,没人敢赌利好不存在。

说一下几点利空。

1,谷歌,meta等巨头现金流吃紧,国内巨头稍好,但现金流开支增速远超利润增长。这种现金流烧法难以持续,只能靠发债维持,现金全在英伟达手里,现在要靠英伟达投资AI企业,然后AI企业拿着英伟达的投资去买英伟达芯片。这怎么看都不是可持续的过程。

这里简单解释一下,你看巨头财报,不是利润很好么,怎么现金流下降这么快,因为算力的采购成本,是按照时间摊销的,所以财务上看上去成本不算特别多,但现金流开支远大于这个财务数据,从某种意义来说,这里其实也是很多人诟病的地方,通过延展摊销周期,掩盖成本问题。

现金流吃紧,意味着后续必然被迫减少算力开支,或者不断通过发债或配股弥补。最新新闻可以看到,阿里开始配股了。

2,美国开始调查东南亚算力出租市场,并准备通过法规限制中国企业租用最新算力。

这个不解释,其实都知道东南亚算力中心的背后金主是谁,本地根本没有那么夸张的算力诉求。但东南亚算力在英伟达全球版图上的占比是非常高的,仅次于美国本土市场,如果法规真的实施(也看实施的细则,会到什么程度,比如是否承认tiktok是新加坡企业,中国人海外创办的企业是否被穿透),并且被苛刻实施,那么杀敌1000自损800,英伟达及其他美国算力配套企业的业绩预期会崩盘。

3,anthropic 增速放缓,增长不及预期。一方面可以说是被openai抢夺了部分市场,但另一方面,中国大模型似乎迈过了拐点,前段时间文章提到过,Token预算失控时代已然来临。

感觉中国开源大模型已经达到了可替代的拐点,目前越来越多美国企业为了控制成本选择部署中国开源大模型。

(除了成本,还有数据安全和可控性,毕竟开源部署可以私有化,而且安全围栏可以自主约束)。

中国开源大模型在同等能力上所需算力更少,算力盲目扩张的时代可能快要结束。

顺便说一下,openrouter和fireworks两大平台在北美市场高歌猛进,说到底,这里最大的价值其实就是部署中国开源大模型给欧美用户,以及解决这里的合规问题。

(前段时间kimi高管和cursor有一次乌龙拌嘴,后来发现就是通过fireworks授权的合作,结果kimi的高管自己不知道,解释清楚就过去了,算是花边)

以上都是非常清晰的利空,而且数据都是很直白的,但即便如此,依然没人敢说,市场泡沫破灭在即。

那你说利好在哪里呢,不知道,看不到,但就是没人敢说,利好不存在。

我们往前看,从历史来回看,算力这个市场的利好,从来都是意外,Open AI的chatgpt横空出世,不在任何投资者意料之中,但是算力市场迅速被引爆了。anthoropic 通过claude,在编程细分赛道上杀出一条现金牛路径,这也不是分析师能提前想到的,但算力变现路径第一次如此清晰。deepseek横空出世,把国产芯片和国内算力市场引爆,又是一个超级意外。然后去年,以manus为代表的agent市场引爆,商业路径彻底打开,算力需求直线上升,市场再度亢奋;今年则是龙虾,你们知道么,龙虾的横空出世让全球算力消耗直接上了一个新台阶, 本来不少人觉得差不多几年泡沫该破了,市场应该冷静了,结果龙虾一来,全球算力投资再度飙升,这谁想得到呢。

哪个不是意外,哪个不是投资人盲区,大家都盯着谷歌,盯着meta,盯着阿里,盯着百度(曾经),但市场的惊喜多是来自新/陌生玩家。

所以,仅仅这几年来看,利好是偶然的,不确定的,却没人敢说它不存在。利空是明确的,确定的,但没人敢真的捅破它。

这就是当前算力市场在资本面所体现的真实的状态。

理解这些,不只是理解算力市场,也包括建立正确的投资逻辑。

很多人投资有执念,所谓执念就是,看好的东西,就会去找它的利好,越找越多,越看好。看空的东西,就会找它的利空,越找越多,越看空。

也许他看到的都是事实,都是真实的数据,但是市场有更多的因素,利好存在,利空也存在,我们甚至无法判断下一个时刻,哪个因素会带来逆转。

我的读者群里(早满员了,不拉新,不推广)有俩股东,一个是零跑股东,一个是多邻国股东,就是很典型执念很深的那种,没事就群里发发相关的利好,你说他们发的是事实么,是事实,但我说的不是这个企业好还是坏,也不是这个投资对还是错,还是那句话,不做投资建议,不构成投资决策,但我要说的是,这种执念要不得。

算力行业,哪怕你看到的都是利空,利好一个都看不到,你都不敢赌,就好比几个月前,你无法预测一个龙虾会把算力需求拉到匪夷所思的高度。

当年我在新加坡,和几个金融业内资深大佬聊在线教育,看到再多利好,再多机会,抵不住突然的一个政策利空。

投资可以承担风险,可以允许损失,但不要有执念,执念太深,你就无法看清全貌,判断力会跟随执念,而丧失了理性。

投资要理性,不要有执念。

← 返回目录

← 返回目录
深读 · 03

放量下跌:沪指失守 3900,成长杀跌、防御抱团

8 月 24 日 A 股复盘综合述评

公开市场信息综合(东方财富、同花顺等) · 本刊整理 · 2026-08-24 · 约 6 分钟 · 原文链接

导读与要点(建议先读原文)
  • 指数:沪指收报 3882.01 点、跌 0.59% 失守 3900;深成指 -2.13%,创业板指 -3.21%,科创 50 -3.10%(盘中一度跌超 4%);全市场超 3900 只个股下跌。
  • 量能:两市成交约 2.01 万亿元,较前一交易日放量约 1280 亿——放量下跌意味着筹码在集中换手,而非缩量阴跌;北向资金全天净卖出约 66 亿元。
  • 结构:AI 算力与光模块成重灾区,中际旭创以 344.92 亿成交居首、跌超 7%;阿里 800 亿港元折价配售被解读为股权稀释利空,叠加长江存储 IPO 融资预期,压制整个科技方向的风险偏好。
  • 避风港:贵金属 +3.19%(白银有色、湖南白银涨停)、煤炭 +2.72%,保险、银行、白酒等高股息板块托底;农业种业与航运亦有脉冲——典型的「成长杀跌、防御抱团」风格切换。
  • 后市观察:成交额能否站稳 2 万亿、北向是否结束净卖出、3890-3900 支撑能否守住;市场观点普遍建议控制仓位、不急于抄底 AI 硬件,等缩量止跌信号。本期 02 的「看空却做多」,正是这轮调整背后的集体心理。

指数:放量下跌,沪指失守 3900。 8 月 24 日(周一),沪指收报 3882.01 点、跌 0.59%;深成指跌 2.13%,创业板指跌 3.21%,科创 50 跌 3.10%、盘中一度跌超 4%。两市成交约 2.01 万亿元,较前一交易日放量约 1280 亿元——放量下跌,筹码在集中换手。全市场超 3900 只个股下跌,上涨约 1400 家,亏钱效应明显。

资金:北向净卖出 66 亿,主力撤离科技。 北向资金全天净卖出约 66 亿元,减仓高位成长赛道;主力资金净流出计算机、电子板块超 300 亿元。直接诱因是阿里 800 亿港元折价配售(折让约 8.37%)被解读为股权稀释利空,叠加长江存储 IPO 融资预期,科技方向的风险偏好被系统性压制。

盘面:AI 硬件失血,防御资产狂欢。 光模块龙头中际旭创以 344.92 亿元成交居两市之首、跌超 7%,天孚通信跌超 7%,共进股份跌停;半导体、存储芯片、创新药、消费电子普跌。另一边,贵金属板块涨 3.19%(白银有色、湖南白银涨停)、煤炭涨 2.72%(上海能源、大有能源涨停),保险、银行、白酒等高股息板块托底,农业种业与航运脉冲上涨——「成长杀跌、防御抱团」的极端风格切换。

性质:牛市中的急跌回踩,而非趋势反转。 综合市场观点,本轮调整发生在 AI 主线累计涨幅巨大的背景下,属于获利盘兑现与外部利空共振的急跌;成交维持在 2 万亿上方说明承接资金仍在,但短期抛压未完全释放。多数策略观点建议仓位控制在三成以内、不急于抄底 AI 硬件,等待缩量止跌加放量回流的确认信号。

本周看什么: 三个信号——成交额能否站稳 2 万亿、北向资金是否结束净卖出、沪指 3890-3900 一带支撑是否有效;周三(8 月 26 日)英伟达财报是全球 AI 叙事的本周围标。把盘面和本期深读对照着看:01 讲「自动化攻防的期望值不对称」,02 讲「利空明确、利好偶然但没人敢做空」——昨天市场里避险资金的集体行动,正是这种心理的即时定价。

(本文基于公开市场信息综合整理,具体数据以交易所及终端为准;仅为信息转述与复盘,不构成任何投资建议。)

← 返回目录