Jensen Huang Says AI Is “Just Software.” The Evidence Says Otherwise.

At GTC this year, the most powerful man in computing sat with analysts and told them, of artificial intelligence, that it is “just software.” Software to be integrated, made domain-specific, governed, secured, connected to your systems of record, and rented to customers.

Minutes earlier, in the same conversation, he had explained that a computer used to be a tool and the computer of the future is manufacturing equipment, because tokens have to be manufactured. Engineers will arrive at work and be handed a laptop and a token budget, and those tokens must be produced somewhere, in factories, on silicon he sells.

Both statements cannot be true in the way each is meant. AI is either just software, weightless, portable, a licence you buy, or it is the output of physical manufacturing equipment consuming enormous power in buildings full of chips. Huang was not confused. He was talking to two audiences. “AI is just software” is what you tell an enterprise buyer, because software is frictionless and safe to adopt. “Tokens must be manufactured” is what you tell an investor, because factories mean capital expenditure without end.

I’ve now spent some time managing and writing about AI risk, and I want to use Huang’s remarks as a mirror. Not to score points, he is right about a great deal, and he sees the demand curve from a vantage nobody else has, but to do something more useful: to say plainly where I think he’s wrong, and, harder, where his framing has shown me something I got wrong.

The tell: every road runs through his silicon

Start with the method, because it’s the same one I’ve applied to Five Eyes warnings and to AI labs calling for their own regulation. Note the interest. Then check whether the message survives the discount.

Huang’s interest here is total, and unusually so. He told analysts that essentially the whole IT industry would end up reselling OpenAI and Anthropic, that these private labs are adding a billion or two in revenue every week, and that a two-trillion-dollar software industry might become an eight-trillion-dollar one that resells tokens. That’s the centralised, frontier-model future, and it consumes his chips.

In the same breath he pitched the opposite. Nvidia’s open Nemotron models, whose stated goal is to be near the frontier rather than at it. NeMoClaw, to run agents safely on your own hardware. Physical AI, which he insists must run on-premises, at the edge, in the factory, because the world doesn’t happen inside a laptop. That’s the decentralised, sovereign, local future, and it also consumes his chips.

Huang does not need to be right about which future arrives. He needs only for both to be plausible enough that everyone keeps buying compute. This is not a criticism of his honesty; it is a description of his position. And it means the correct way to read him is to take his description of the branches very seriously, he can see the order book, and to disregard entirely his prediction of which branch wins.

There’s a smaller tell worth noting too. He said he wished the frontier labs were public, so that others could see what he sees in their growth. Sit with that. He is asking you to believe an extraordinary number about companies whose books you cannot examine, and lamenting, accurately, that you cannot examine them. Believe him or don’t. Just notice that the request is to trust an interested party about an unverifiable claim.

Where I part company, firmly: AI is not just software

This is the claim I’d push back on hardest, because it is the one most likely to cause real damage in a real organisation.

Last week, I wrote about what the Iran war revealed, and the lesson holds. Liquid helium cools the machinery that prints semiconductors, and Qatar supplies a large share of the world’s helium, and it ships through the Strait of Hormuz. Seven major submarine cables cross that same seabed. Gas from that region prices the electricity that data centres burn. When missiles flew, the price of chips, power, and connectivity moved, thousands of miles from any battlefield. AI has a body. It is made of coolant, seawater, gas, glass, and a handful of fabs.

“AI is just software” is true the way “a car is transport” is true: accurate about what you experience, and dangerously incomplete about what makes the experience possible. Huang’s own token-factory metaphor concedes the point more honestly than his software framing does. The reason this matters practically is that a leader who accepts “just software” will run no supply-chain diligence on the physical substrate their entire AI capability rests upon, and will be genuinely surprised when a geopolitical event they never modelled reaches into their production systems.

Where I part company, and where he accidentally helps: the reseller monoculture

The claim that the whole IT industry becomes a reseller of two American labs is the purest expression of the centralisation thesis, and I don’t believe it.

What I believe is that every company will use AI models. Not every company will rent frontier ones.

The reason sits inside Huang’s own open-model strategy. He said Nvidia’s aim is to be near the frontier, not to be the world’s best. For the overwhelming majority of enterprise workloads, near-frontier is entirely sufficient, and once it is, the economics of paying frontier prices for a marginal capability you never use collapse. Combine that with genuinely capable open weights, hardware you already own, and a security wrapper to run agents locally, and you have a real alternative to the reseller future. Not a niche one. A mainstream one.

Which brings me to the part of this piece that matters more than any disagreement.

What I got wrong

In writing about the systemic risks of AI, I argued that concentration is the master risk, that everyone running the same models on the same clouds through the same financial channels creates a monoculture, and that monocultures cascade rather than correct. I stand by every word of that. But I framed the concentration as close to inevitable, something to be mitigated rather than escaped. Reading Huang, and watching NeMoClaw and near-frontier open models arrive together, I think that framing was too fatalistic. Local deployment is a genuine structural answer to model concentration, and it is arriving faster than I credited.

And now the correction to the correction, which I think is the most important sentence I’ll write here.

Local deployment decentralises the software layer and re-concentrates the hardware layer.

You escape the frontier lab’s API and you inherit the silicon, the CUDA ecosystem, the fabs, the helium, the grid. You have not eliminated your single point of failure. You have moved it down the stack, out of view, into exactly the physical substrate that “AI is just software” trains you not to look at. Sovereignty over your model is not sovereignty over your compute. Anyone selling on-premises AI as the answer to concentration risk is telling you half a truth, and it is the comfortable half.

Two smaller admissions, because they’re real.

I never wrote about cost as a control surface, and Huang’s token-budget remark shows me I should have. If every engineer is issued a finite token allowance, that allowance becomes a governance mechanism, whether or not anyone designs it as one. It could enforce a verification floor. It could equally guarantee that verification is the first thing skipped, because testing, red-teaming, and running an agent in a careful, checked loop all burn tokens, and the engineer is measured on shipped output rather than on caution. I have written that safety becomes a luxury good when verification is expensive. I missed that it arrives at the individual engineer’s desk, as a line item, long before it arrives in the boardroom.

I also under-weighted depreciation – an AI factory built just a year ago should already feel buyer’s remorse, because the hardware is ageing at a brutal rate. That complicates my own advice. If you buy your own infrastructure for the sake of resilience and sovereignty, you accept an asset that may be obsolete before it is amortised. Renting concentrates your risk; owning depreciates your capital. There is no clean answer, and I should have said so rather than implying that owning was simply the safer path.

There is one more collision in my own writing that I owe you. I warned that Chinese open models carry risks a Western enterprise cannot fully audit. I also argue that local, open deployment is the answer to concentration. Those two positions point in opposite directions, because much of the best open weight is Chinese. Nvidia’s Nemotron exists partly to resolve exactly that tension, an open, near-frontier, non-Chinese option. I flagged the security risk without noticing it collided with my own resilience advice. It does. That tension is real, and pretending otherwise would be dishonest.

What survives the discount

So, applying my own test to the most interested man in the industry. What survives?

The agentic inflection is real; I’ve documented the security consequences of it at length, and the fact that Nvidia had to ship a sandboxing wrapper alongside the agent revolution rather confirms the argument that the engine arrived before the brakes. The growth of on-premises and edge deployment is real, and physical AI, robots, factories, machines in the world, is a much larger phenomenon than the digital kind, which means the dark-factory future I’ve written about is bigger than I treated it as, not smaller. Near-frontier open models are real and independently verifiable. Token budgets are coming, and they will quietly become one of the most consequential governance surfaces in engineering.

What doesn’t survive: that AI is just software. That every company will end up reselling two labs. And the implicit promise beneath all of it, that adoption is frictionless and the only question is how fast you move.

The most useful thing about Jensen Huang is that he is simultaneously the best-informed person in the industry about where compute is going, and the least neutral.

Hold both facts at once, and he becomes enormously valuable: a map-maker whose maps are accurate and whose recommended route always ends at his own door. Take the map. Choose your own road. And when someone who profits from every possible future tells you which one is coming, listen to the branches, and ignore the prophecy.

I’d rather be corrected in public than be consistent in private. Concentration is still the master risk. I just understand better, now, where it actually lives.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

Responses