Risky Tuesday #9 · AI Risk, Part III · 29 September 2026
Every Tuesday, we take one risk from somewhere in the world and classify it according to the Five Quadrants methodology.
The Great Compute Bet
Quadrant 3 and 4 – and the industry is underpricing Q4
Dear Reader
In the first two parts of our AI conversation with Professor Theos Evgeniou, we explored what happens if AI works and asked if humans may have started to surrender control. This week we turn to the risk of infrastructure build-out: models, chips, compute, data centres and the extraordinary amount of capital being committed to it.
Given the enormous investments in AI infrastructure, the questions we put to Theos focused on the risk of over-building and concentration of ownership in the hands of a few companies.
Question 1: Where is the concentration risk—in models or in hardware?
Companies increasingly depend on a relatively small number of model providers and cloud platforms. We asked Theos whether this was primarily a technology risk, a geopolitical risk, or simply the same concentration risk viewed from different perspectives.
He challenged the premise. Why assume that companies will continue to depend on a handful of general-purpose models?
“Why do you need a general-purpose model if you have a specific application?”
Theos expects companies to adopt a portfolio of AI solutions: large models for some tasks, smaller specialised models where they are better suited, and conventional code where AI is unnecessary.
“Let’s create a portfolio of AI solutions: a combination of large, small, code, whatever.”
That diversification could reduce concentration at the model level. But all of those solutions ultimately depend on computing infrastructure, and Theos sees the tighter bottleneck further down the technology stack:
“There is potentially more concentration on compute and silicon than on the models.”
The reason is largely economic. Advanced chips, data centres, power and cooling infrastructure require enormous amounts of capital, take years to build at scale, and can be supplied by only a relatively small number of players. “The concentration is driven by the capital requirements,” Theos explained.
So as AI applications proliferate, concentration may actually decline at the model level while increasing further down the stack where all those different applications converge on the same physical infrastructure.
Question 2: Will we really need all those data centres?
We see extraordinary projections for future data centre capacity and major bottlenecks in processors and compute. Is it realistic to project ever-increasing capacity, or will technology find ways to do more with less?
Theos separated the answer into two time horizons and warned of increasing physical constraints:
“There is a short-term story and then a longer-term story. The short-term story is that there are bottlenecks: the chips that you can use today and existing infrastructure. There can also be overinvestments and bubbles; it is hard to get the price of infrastructure for significant tech innovations like AI right. We are not able to assess the options that such infrastructure enables, including second-order effects in the future. So markets can easily get it wrong, but that is a short-term issue.”
Over the longer term, however, Theos was quite clear on one point: demand for compute is not going away. He was less certain about how that demand will be served.
“Compute, or maybe better say ‘intelligence’ needs, will absolutely increase.” Whether that intelligence will be served through today’s infrastructural approach with big data centres or through another way … in the long term, I assume things will shift.”
That creates an interesting investment problem. You can be completely right about the growth of AI and completely right about the growth in demand for compute yet still be wrong about the assets built to serve it.
The real risk may be that the architecture changes, not necessarily the demand forecast.
Question 3: What happens when regulation and geopolitics enter the picture?
We shifted our questions to regulatory fragmentation. AI regulation is developing differently in the US, UK, Middle East, Singapore, China and elsewhere. Does that fragmentation itself create a new category of risk?
At the company level, Theos was not particularly alarmed.
“You face a more complex regulatory risk landscape, but that’s nothing new.”
Companies already operate across different financial, product-safety and other regulatory regimes. AI adds complexity, but regulatory fragmentation by itself is not a new risk species.
Things get more complex when AI applications cross borders and carry consequences well beyond an individual company or jurisdiction. Autonomous weapons are an obvious example. Effective oversight then depends on countries agreeing on minimum standards and creating institutions capable of enforcing them. Easier said than done when engaged in a life-threatening battle.
“What is the lowest common denominator that everybody on the planet has to accept in order to manage some of those risks?”
Theos argues that this common standard needs sufficient substance and institutional backing:
“You need to start from the lowest common denominator, which must be high enough, and then implement through strong institutions.”
That connects the technology back to geopolitics. Chips, compute, infrastructure, regulation, supply chains and national power do not sit neatly in separate boxes.
“Geopolitics, technology, and competition—all those things are all completely linked these days.”
For Theos, institutions are, therefore, part of the competitive landscape itself. But as he highlights, “Whoever designs institutions designs the world, basically.”
So, which quadrant are we in?
A single data centre has both Quadrant 3 and Quadrant 4 risks.
Quadrant 3 covers the engineering component risks: power systems and redundancy, cooling failures, UPS batteries and degradation, fire suppression, structural loading, and most routine cybersecurity.
These systems may be technically complex, but their risks are well understood. Engineers design around them, insurers price them, and established standards provide a framework for managing them. Measurement and mitigation usually work.
Quadrant 4 hosts risks that become correlated and interconnected. Grid-level power availability, which is more macro/policy than engineering, water scarcity, chip supply, shared software failures, geopolitical disruption, regulation, data sovereignty, financing and demand risks. A problem in one can impact several others at the same time.
Too much capital? Enormous amounts of investor capital have been committed on assumptions that make sense today. But these are long-lived physical assets being built into a technology environment that can change rapidly. A different chip architecture might impact power requirements. Greater efficiency could change the demand for capacity. Either could affect financing assumptions and asset values.
The Quadrants question makes us think beyond the immediate and obvious need for more compute and asks what we are really betting on when we build the infrastructure to provide it. The answer is that we are in both quadrants, simultaneously, and the industry is likely underpricing Q4 risks.
Question 4: What should boards do?
We ended the interview by inviting Theos to a hypothetical board meeting. What should directors stop doing, or what should they start doing?
“Definitely start thinking about the ambition and urgency question. That’s the key question.”
He would also stop treating AI as simply another productivity programme.
“Stop treating AI as a purely productivity game, like any other technology.”
And then came the line likely to make a few investment committees uncomfortable.
“Oh yes, stop only calculating and asking for ROI. And support learning through experimentation, for which the ROI is hard to measure but the value is obvious. Like the value of education.”
When asked why, his point was that conventional ROI can become a dangerous gatekeeper when the actual, strategic risk includes disruption, competitive displacement and moving too slowly. For boards, that leaves an awkward balance. Commit too quickly and you may lock capital into today’s answer to a problem that is changing rapidly. Wait for perfect visibility, and the companies or countries moving faster may set the pace, the standards and perhaps even the institutions.
Theos’s prescription was short: “Do set the right ambition and urgency levels.”
Now I need you
Where do you think the bigger AI infrastructure risk sits? In underbuilding compute capacity, or in committing too much capital to an architecture that may change?
And if you sit on a board or investment committee, how are you thinking about that trade-off between urgency and the danger of betting too heavily on today’s technology? We would welcome a call.
This concludes our first three conversations on AI risk with Theos Evgeniou. There is plenty left in the interview, and probably even more left in the risk register.
That's the AI series for now. Forward this to someone who would argue with it, and tell us which risk we should deconstruct next.
Claudia and Dave
https://5quadrants.com/
Not subscribed yet? One risk, one quadrant, every Tuesday. 
Risky Tuesday is written by Claudia Zeisberger and David Munro. |