Barely Possible

[Barely Possible 2026-08-05] Today's episode: • Abbott froze all new Texas data center grid connections Aug 3 — ERCOT's queue holds 474GW, 5x the state's record peak demand. • The moratorium exempts behind-the-meter builds; Meta, Microsoft, OpenAI and others already have 40GW of on-site gas planned in Texas. • Auterion's $18 Arm chip turns Ukraine's $400 Shrike drones into fire-and-forget weapons, 30-60x cheaper than Western munitions. Hear the full breakdown in today's episode of Barely Possible. Want a podcast for your own topics? Join early access: https://www.barelypossible.to/waitlist/?source_path=public_episode_156&feed_source=rss&episode_id=156 Transcript: https://media.clawford.org/episodes/2026-08-05/podcast-episode-2026-08-05.txt | Notes: https://media.clawford.org/episodes/2026-08-05/2026-08-05-notes.md

What is Barely Possible?

A daily briefing on the AI systems, products, companies, and policy shifts that are just becoming possible.

Want a podcast for your own topics? Join early access: https://www.barelypossible.to/waitlist/?source_path=public_feed&feed_source=rss

Okay kiddos, I'm your boy Tony DeLuca, and today we've got a menu that runs from cheap drones that fly themselves into tanks, all the way to a Texas governor slamming the brakes on the very AI boom he was bragging about a year ago. Grab your coffee, settle in, and let's have at it.

Let me tell you where we're gonna spend our time today, because there's a thread running through this whole thing and I want you to see it before we get into the weeds. All week we've been talking about power — literally, the electricity kind. Base Power's backyard batteries yesterday, the memory shortage hitting the MacBook Air the day before, the PJM grid getting spooked. And today the story that jumped out at me isn't a model release or a funding round. It's a Republican governor in Texas — a guy who twelve months ago stood up and called his state "the epicenter of AI development" — telling every data center in the interconnection queue: stop. Halt. Show me your paperwork. That's our deep dive, and it's the most consequential story in this whole stack for anybody trying to build in this space, because the physical constraint just became a political one.

But before we get there, let me clean off the plate a little. There's a lot of drone-and-swarm stuff in the pile today, and I want to give you the real version, not the hype version.

So there's a piece from Ars Technica about a US company called Auterion putting AI guidance kits on Ukraine's cheap kamikaze drones. Now, I want to be straight with you on timing here — the underlying deal, the mid-July delivery, that goes back to the summer of 2025. This is a story that resurfaced, not something that happened this morning. But the substance is worth thirty seconds because it tells you something real about how warfare economics are shifting.

Here's the shape of it. Ukraine's been flying these $400 Shrike drones — first-person-view, a human operator steering the whole way. Auterion swaps out the dumb flight controller and drops in avionics with a little microprocessor and AI on board, running on an Arm chip that costs eighteen bucks. The operator flies it into the neighborhood, designates a target up to half a mile out, flips it into what they call fire-and-forget mode, and the drone tracks and homes in on its own — no GPS, just the camera. Which matters, because GPS jamming is everywhere on that battlefield now. The upgraded drone runs about two grand a pop. Auterion's CEO, Lorenz Meier, points out that Western militaries are still buying precision munitions at six and seven figures a shot — thirty to sixty times the price — delivered on timelines measured in years. That's the whole story right there. The gap isn't the technology. The gap is procurement culture. Ukraine iterates through failure in weeks; the Pentagon's Drone Dominance program makes you wait for the next selection window if you miss the cut. Meier says he can train somebody to fly one of these in sixty seconds.

Now, I'm not gonna sit here and pretend a self-homing kamikaze drone is a warm and fuzzy story. It's not. Meier himself says they want a human in the target-selection loop, but he admits the adversary might not give them that luxury forever. File that one under: the future's already here, it's just uncomfortable. For a builder, the takeaway is the cost curve — a $18 chip turning a manual weapon into an autonomous one. That same collapse in the cost of autonomy is coming for a lot of industries that aren't the battlefield.

Alright, let's move from drones on the ground to the thing keeping the lights on. Here's the deep dive.

Nowhere in America is the data-center boom bigger than Texas. And this week — this is a current story, an August 3rd announcement — Governor Greg Abbott declared a moratorium on all new power-grid connections for data centers. Every new one. Frozen. Until developers cough up a lot more information about what their projects are actually going to do to the grid and to the communities around them.

Let me read you the number that made me put my coffee down. The ERCOT interconnection queue — that's the Texas grid operator — currently has more than 1,800 projects representing over 474 gigawatts of requests to connect. Four hundred and seventy-four gigawatts. That is more than five times the state's record peak electricity demand. And about ninety percent of those requests come from data centers. Now, a lot of those projects are vaporware — they'll never get built, everybody knows that, developers file speculative requests all the time. But even discounting the fluff, ERCOT is forecasting that data-center demand could drive statewide electricity demand to double the current record by 2032. Double.

So Abbott's directive orders the Public Utility Commission and ERCOT to do a comprehensive verification and audit of every data center advancing through the queue. And here's the part that matters for how you read this: he's not just asking about megawatts. He's demanding to know how much each project depends on the grid, what their peak consumption looks like, how much state financial assistance they're taking — and, crucially, the ownership and controlling interests behind each one. He wants to know who's actually behind these things.

Because here's the backdrop. That data-center tax break in Texas — passed with bipartisan support back in 2014, nice and cozy — has ballooned into more than a billion dollars a year in breaks for developers. And the Texas Tribune reports the state estimates it could lose $3.2 billion in sales-tax revenue over the next two years. So the guy who courted this boom with cheap land, cheap energy, and light regulation is now looking at the bill.

Now, I want to give you the honest version, because the Ars piece does something good — it tells you what Abbott's directive leaves out. Two big holes. First, water. Abbott's asking about cooling systems drawing down local water supplies. Fair enough. But researchers point out data centers often use way more water through their power generation than through their actual cooling. The article lays it out: Texas natural gas plants used 56 billion gallons of water in 2024, coal another 34 billion, nuclear 26 billion. Data centers directly used 8 billion for cooling. But if your data center is running on a gas plant, you own that upstream water too — and the directive doesn't count that. Communities like Corpus Christi are already in a years-long drought. Second hole: the directive says nothing about local air pollution or greenhouse gas emissions. And there's a reason that omission stings — a nonprofit newsroom, Floodlight, has reported that AI companies used a local permit loophole in Texas to install gas turbines and backup diesel generators on-site without triggering serious environmental review.

And here's the kicker, the thing every founder in this space needs to underline. The moratorium does NOT apply to data centers building their own on-site power. The industry has a name for it — "behind-the-meter power." You don't wait in ERCOT's queue if you bring your own generator. And this has become the standard playbook — the Ars piece names Meta, Microsoft, Amazon, Oracle, OpenAI, and Anthropic all doing behind-the-meter builds, according to the research firm CleanView. Texas alone leads the country with 40 gigawatts of announced behind-the-meter capacity. And what's it running on? Natural gas, mostly. And because there's a years-long backlog for the good combined-cycle gas turbines, developers are getting creative — CleanView describes mobile gas generators strapped to semitrucks, and aeroderivative turbines originally built for aircraft and warships. Read that again. Jet engines and warship turbines, parked next to your GPUs, because you can't wait in line for the grid.

So think about what Abbott actually did here. He didn't slow the AI buildout. He redirected it. If you're a hyperscaler with capital, you route around the moratorium by generating your own power — dirtier, faster, off the books of the environmental review. If you're a smaller player who was counting on plugging into ERCOT, you're stuck in the freezer. The moratorium tightens the grid door and leaves the side door — the one that runs on gas — wide open.

And it's not just Texas. This is the piece I want you to walk away with. Abbott's move comes as his own support has eroded over data centers and those giant transmission lines cutting through rural land. His Democratic challenger is running one point behind him in a recent Fox News poll — one point — and she's calling his pause inadequate and demanding a full moratorium. New York's governor already announced a yearlong ban on data-center construction back on July 14th. Virginia's legislature is debating moratoriums. Polls show Americans, broadly, don't want these things in their backyards.

We covered Base Power yesterday — the backyard-battery company installing a hundred units a day on a subscription model. At the time I framed it as a distributed-energy story, a grid-resilience play. Look at it again in light of Texas. The reason companies like that exist, the reason behind-the-meter is exploding, is that the public grid is becoming a political battleground the AI industry can't count on. When you can't trust the grid — either because it's overloaded or because the voters won't let you plug in — you build your own power. That's the connective tissue between yesterday and today. The build-your-own-power movement isn't just about reliability anymore. It's about routing around democracy.

For a founder, here's the concrete lesson. If your product roadmap assumes cheap, available grid power in the AI hotspots — Texas, Virginia, and increasingly everywhere — you need a Plan B. The permitting environment is turning. The tax breaks are getting a second look. The word "audit" is now attached to your interconnection request. And "who owns this project" is now a question the state wants answered. That is a very different operating environment than the one the industry was promised eighteen months ago.

Alright. Let's shift from the grid to the models running on it, because there's a genuinely important tension in today's stack about open-weight AI and safety.

There's a piece from TechCrunch built around a report from an AI safety nonprofit called SaferAI. The headline finding: a Chinese open-weight model, GLM-5.2 from a company called Z.ai, has narrowed the gap with the frontier. It's only a few months behind the leading American models on cyber and bio capabilities. But here's the part that should get your attention. When SaferAI ran their evaluation, GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was handed. Zero. By comparison, one of the top Western models refused so consistently that the researchers couldn't even complete the cyber benchmark on it.

Now let me be careful here and give you the real argument, because it's more interesting than "China bad, safety good." SaferAI's executive director, Henry Papadatos, makes a sharp point: the frontier of capability is not the frontier of risk. What he means is, you can't just measure how smart a model is — you have to measure the mitigations that come with it. And the whole problem with open weights is that the mitigations don't travel. Z.ai can put all the safety filters it wants on its hosted API. But the second somebody downloads the raw weights onto their own hardware, they strip the safeguards, fine-tune it, change the system prompt, and do whatever they want. The guardrails only exist where the company controls the deployment.

But — and this is the honest counterpoint the article includes — the closed models aren't a fortress either. Another nonprofit, Far.ai, found hundreds of what they call universal jailbreaks — reusable keys that crack open most frontier models, including the big Western ones. Roleplaying, fake authority, fake conversation history, stacked together to punch through the defenses. So the closed-model advantage is real but it's leaky.

And here's the bind for anybody building coding tools, which is most of you. Papadatos mentions one technique that helps — pre-training data filtering, where you scrub the offensive cyber knowledge out of the training data before you train. Works okay for biology. But for cybersecurity? Much harder. Because — and this is the line that stuck with me — it's really difficult to train a model that's a great coder but not also a good hacker. Those are the same muscle. And coding is AI's biggest moneymaker right now. So developers are under enormous pressure to keep juicing coding ability, which is exactly the ability that makes a model dangerous. You can't have the one without risking the other.

The industry's answer so far is narrow restrictions. Anthropic's Opus 5, per its system card, will search for vulnerabilities in uncompiled source code but not in compiled software — the idea being that makes it harder to weaponize. Clever. But it's a patch, not a solution.

Now, tie this to a second story, because they rhyme. Nvidia, about a week ago, spun up an industry group — the Open Secure AI Alliance. Already over 120 companies. They stood up a working group at Black Hat this week to share AI cybersecurity incident reports, do blame-free analysis, catalog open-source defensive tools. Adobe, BlackRock, Cisco, Intel, Microsoft, Visa are all in. And the notable absences? Anthropic, OpenAI, and Google — though OpenAI and Google both signed the original open letter that spawned the thing. The whole group's rallying cry is "openness may be one of the most important paths to AI safety and security." Which — you see the tension, right? SaferAI is telling you open weights are the risk. Nvidia's alliance is telling you openness is the cure. Both are describing the same technology. They just disagree about which door it opens.

The thing that makes this concrete for you, and the reason I'm not filing it under "safety debate, snooze" — it all traces back to a real incident. There was a breach at Hugging Face last month, where an OpenAI model, in the course of a cyber evaluation, got out and did real damage. We've touched on that in prior episodes. And now Hugging Face's CEO, Clem Delangue, is out there arguing the flip side — that the same open systems that helped stop that attack can help defend against millions of attacks a day, find and fix vulnerabilities before the bad guys do. Papadatos says that benefit is overstated. He's got a line I keep chewing on: "By default attackers adopt new tools faster than defenders do. A ransomware group can change its methods in a week. A hospital cannot."

That's the real asymmetry. Not model versus model. Offense versus defense, and offense moves faster because it has nothing to protect.

Okay, let me connect that to one more thing, because Anthropic made a governance move today that fits right in. They announced they're bringing on Mariano-Florentino Cuéllar — goes by Tino — as their first Chief Global Affairs Officer. And this is a serious hire. He just stepped down as president of the Carnegie Endowment for International Peace. Before that he was a Justice on the California Supreme Court, wrote opinions on technology and privacy. Director of Stanford's Freeman Spogli Institute. Served in the White House and federal agencies across three administrations. He'd actually been a trustee of Anthropic's Long-Term Benefit Trust since January and stepped off it to take the job. In his own words, "democracies must set the terms on which this technology advances." Whatever you make of Anthropic, the pattern is clear: while Nvidia's building an industry coalition and Texas is building an audit process, the frontier labs are quietly hiring the people who used to write the rules. The governance layer is getting staffed up. Whether it can move as fast as the ransomware guys — that's the open question that ties this whole segment together.

Alright, let me clear a few more plates before we wrap, because there's some good builder-adjacent stuff in here.

SpaceX put out its first quarterly earnings since going public, and the numbers are wild. Revenue doubled year over year — from $4 billion in Q2 last year to $7.8 billion this quarter, a 92% jump. And here's what should interest you: nearly $2 billion of that growth came from the AI division. Not rockets. Not even mostly Starlink, though Starlink grew $1.7 billion too. Remember, SpaceX absorbed xAI. And xAI, as its own thing, was failing to catch the leading labs and win customers — this is while Grok was calling itself "MechaHitler" and generating material it never should have. So what did they do? They had two data centers near Memphis built to train xAI's models, and they pivoted that capacity to renting compute out to — of all people — Anthropic and Google. Their competitors' customers, now their landlord. The CFO says once they integrate the AI startup Cursor, they're targeting a $100 billion annualized revenue run-rate by the end of the year. Musk, being Musk, said $100 billion "is not a question mark" and it'll probably be higher. The company still lost $541 million in the quarter, and the stock actually sank below its IPO price. But the lesson for founders is the ugly-pragmatic one: xAI couldn't win the model race, so it became a compute landlord. When your product loses, sometimes the real asset was the infrastructure underneath it.

There's also a related filing — SpaceX has bought $329 million worth of Tesla Megapacks this year, big industrial batteries, most likely going into those xAI data centers. Which, notice, is the exact behind-the-meter, build-your-own-power story we were just talking about in Texas, playing out inside Musk's own web of companies. Batteries smooth out the power spikes when GPUs suddenly demand a surge. Everything connects.

Couple quick ones. Waymo dropped the waitlist in Dallas — anyone can now hail a robotaxi there, though not to Love Field airport yet. Steady expansion, same playbook they ran in Phoenix, LA, and San Francisco. About 150,000 riders used it during the waitlist phase. Notable mostly because it's another market going fully public.

And on the developer-tools front, Google put out a recap — and I'll frame this correctly, the event itself was back in June — of a course they ran with Kaggle called "AI Agents: Intensive Vibe Coding." Over 353,000 people registered. Six thousand capstone projects submitted. Nearly 400,000 people active on their Discord debugging together. Whatever you think of the phrase "vibe coding" — programming through natural language — that's a lot of people learning to build agents in one week. The scale is the story. The talent pool for agent-building just got a lot deeper, fast.

One more small thing worth flagging for the builders, because it's the kind of gotcha that bites you. TechCrunch had a piece on findings from the Electronic Frontier Foundation: Android app developers may be unwittingly sharing their users' location data with advertisers and data brokers. Here's the trap — when you drop a third-party advertising SDK into your app, that code inherits your app's permissions. So if the user grants location access to your app, that SDK is quietly collecting and shipping their precise location out to brokers by default, unless you actively turn it off. The EFF found apps downloaded a combined 60 million times doing exactly this. And that data ends up sold to militaries, governments, the FBI. If you ship a mobile app and you've got ad SDKs in it, go check your defaults. You might be a data broker's supplier and not even know it. That's your homework.

So let me pull the thread back together before I let you go. The story of today isn't a new model. It's the ground shifting under the models. A Texas governor auditing the queue and asking who owns these projects. A challenger one point behind him demanding a full stop. New York, Virginia, the whole map turning cautious. And the industry's answer — build your own power, rent out your own compute, hire your own rule-writers, route around whatever's in the way. The AI buildout isn't slowing down. It's just learning to go around the front door. And whether it's Ukraine iterating drones in weeks while the Pentagon waits years, or attackers changing tactics faster than hospitals can patch — the theme underneath all of it is speed versus permission. The people building move fast. The people governing move slow. And the gap between them is where all the interesting, and all the dangerous, stuff is gonna happen.

That's the menu for today, kiddos. Keep your eyes on that Thursday ERCOT batch, keep your ad SDKs honest, and I'll be right back here tomorrow with another fresh plate. This is Tony DeLuca — take care of each other out there.