Can AI Pay for Its Infrastructure? Plus 3 Stories
AI is getting very good at producing text, images, code, and increasingly eye-watering capital-expenditure numbers. The less glamorous question is whether the technology can create enough economic value, fast enough, to pay for all of the infrastructure being built around it.
AI’s infrastructure bill is measured in trillions
PwC now projects $31.6 trillion in global data-center capital spending through 2050 under its baseline scenario. Annual spending would rise from roughly $800 billion this year to $1.8 trillion by 2050. And unlike a railroad or a bridge, much of this infrastructure does not get built once and then sit there for decades. GPUs, servers and related equipment need to be replaced every few years, so the spending cycle keeps coming back.
Reuters put the financial problem into sharper focus Saturday. Bain estimates that the hyperscalers and other companies building this infrastructure need more than $4.2 trillion in new revenue over the next five years to fund it. Anthropic, by itself, plans hundreds of billions of dollars in spending in the coming years. At the same time, JPMorgan says broad U.S. productivity gains from AI remain hard to see.
That doesn’t mean AI is useless, and I wouldn’t turn it into the equally lazy conclusion that the entire boom has to collapse. General-purpose technologies have a habit of taking longer to reorganize the economy than investors would prefer. Cambridge economist Diane Coyle told Reuters that the productivity effects from previous technological revolutions typically took 10 to 50 years to work through the economy.
The awkward part is that loans, leases and hardware refresh cycles don’t operate on historical patience.
For ordinary businesses, this matters even if you never plan to buy a rack of GPUs. We’ve already seen AI demand push up memory prices across everyday electronics. Power infrastructure, cloud pricing, software subscriptions and the cost of ordinary computing all sit somewhere downstream from this buildout. A company deciding whether to replace 20 laptops, move a workload into the cloud or sign a multi-year software contract is not operating in a separate economy from the AI boom.
So the question I’m watching is not whether AI can do useful things. Obviously it can. The question is whether useful applications and new markets arrive quickly enough to support infrastructure spending that is already happening at extraordinary scale.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Microsoft says AI is speeding up attacks, not replacing old ones
Microsoft’s 2026 Digital Defense Report contains plenty of AI, but the part I find most useful is how stubbornly familiar the successful attacks still look.
Nearly 40,000 CVEs were published in the first half of 2026. Microsoft says the median time between a vulnerability being discovered in the wild and attackers weaponizing it has fallen to well under 24 hours. Enterprise remediation of critical internet-facing vulnerabilities, meanwhile, can still take 30 to 60 days.
There’s your problem.
AI can help discover weaknesses, automate reconnaissance, customize phishing and move through parts of an attack chain faster. But Microsoft says most complex real-world intrusions still involve meaningful human direction. And the doors attackers walk through are often old ones: user execution accounted for 30% of observed initial access, while valid accounts made up another 20%.
One particularly ugly example is ClickFix, where a fake error message or verification screen convinces a user to copy and run an attacker-supplied command. Microsoft Defender saw those commands executed on more than 1.1 million unique devices between February and early May, about eight times the earlier rate.
The new threat model, apparently, still includes a human being clicking Paste.
That’s not a reason to shrug at AI-enabled attacks. It’s a reason to understand what changed. The attacker can move faster, repeat the process more cheaply and scale a campaign more easily. Defense therefore has to shorten its own timeline: protect identities with strong MFA, remove unnecessary privilege, know what is exposed to the internet, patch the exposed stuff quickly, and teach people that a website telling them to paste a command into PowerShell or Terminal is not normal troubleshooting.
Microsoft also found that 58% of detections tied to the five leading CVEs it analyzed came from CVE-2020-1472, a vulnerability disclosed six years ago. AI may be changing the speed of cybersecurity. It has not repealed the consequences of leaving old doors unlocked.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
GitLab’s AI Gateway needs an urgent patch
If you run GitLab’s Self-Hosted AI Gateway, this one is considerably simpler: check the version and patch it.
GitLab released AI Gateway versions 19.2.4, 19.3.2 and 19.4.1 to fix CVE-2026-90970, a CVSS 9.9 vulnerability in custom flow prompt templates. Under the right conditions, an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox using a specially crafted flow configuration and execute arbitrary commands on the AI Gateway.
There are two scope details worth keeping straight. This is not an unauthenticated drive-by flaw, despite some breathless summaries making it sound that way. The attacker needs an authenticated account with Duo Agent Platform access. And it affects self-hosted AI Gateways; GitLab says its hosted gateways have already been fixed.
Affected releases include versions from 18.1.6 up to the fixed 19.2.4 branch, 19.3 before 19.3.2, and 19.4 before 19.4.1. GitLab is recommending immediate upgrades.
The mechanism is also a useful reminder about AI features becoming part of the application security boundary. A prompt template sounds like text. In this case, the template system sits close enough to executable behavior that escaping its sandbox can become operating-system command execution. “It’s just the AI part” is not a useful security category when the AI part can touch the host.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Europol took KillSec’s leak site — and secured 110 TB of data
European law enforcement took control of the KillSec ransomware group’s leak site on September 30 and says it secured at least 110 terabytes of data against further unauthorized access.
Europol says Operation KillSwitch is examining roughly 1,000 suspected attacks worldwide. Three suspects were provisionally arrested and eight properties were searched across Greece, Romania, Spain and the United Kingdom. Investigators identified a 16-year-old as the suspected main operator.
That last detail is striking, but it shouldn’t turn this into a story about a clever teenager. The important part is how much infrastructure and harm can now sit behind a ransomware operation that law enforcement says may have involved about a thousand attacks.
KillSec allegedly used the familiar double-extortion model: steal data, threaten to publish it, then use the leak site as leverage for payment. Taking control of that site and securing its stored data can prevent additional exposure from that infrastructure. It does not magically pull back every copy of stolen information, undo compromises at victim organizations, or guarantee that the operation cannot re-form somewhere else.
Ransomware has become a service business because repeatable tools, payment systems, affiliates and leak infrastructure let a relatively small number of people operate at a scale that used to require a much larger organization. That’s exactly why boring defenses still matter: MFA, tested backups, limited privileges, patching exposed systems and an incident plan that exists before the ransom note arrives.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: AI’s race to transform the world before the money runs out
- PwC: Global Data Centre Outlook 2026–50
- Microsoft: 2026 Digital Defense Report
- GitLab: AI Gateway critical patch release
- Europol: Operation KillSwitch and the KillSec disruption
Photo by Christina Morillo on Pexels.
