Morning Watchlist

    OpenAI just delayed its own model.

    Behind the Markets
    Tuesday, August 18, 2026
    OpenAI just delayed its own model.

    Morning Watchlist: Tuesday Edition             

    A quick note from Behind the Markets

    Wall Street keeps treating AI, defense, pharmaceuticals, China, and energy as separate trades. The signals from the past ten days point at the same change: capital is moving toward businesses that control a necessary operating layer.

    AI needs containment. Militaries need capability they can deploy this year, not in 2032. Drugmakers need cheaper biologics as patents expire. Alibaba needs to sell yesterday's growth to fund tomorrow's. Even cooking gas has become a matter of national planning.

    On August 7, the company under more commercial pressure to ship a product than almost any on earth announced it was slowing down — because its next model might be too good at breaking into computers.

    When the accelerator taps the brakes, somebody gets paid to build the brakes. Let's find them.


    1) AI's Next Liability Is Cybersecurity

    OpenAI disclosed on August 7 that it "cannot rule out" that its upcoming model, Astra, has reached the "Critical" cybersecurity threshold under its own Preparedness Framework.

    A model hits Critical if it can independently identify and develop functional zero-day exploits against many hardened real-world systems without human intervention, or devise and execute end-to-end novel cyberattacks against hardened targets given only a high-level goal. OpenAI has been careful to say this is a preliminary assessment — Astra has not been formally classified, and evaluations continue. But the company is treating the possibility as credible enough to trigger the most demanding part of its own rulebook.

    What it actually did is the investable part. Astra's release has been delayed — the language suggests months rather than weeks. Development now runs in isolated testing environments with restricted network and tool access. Model weights carry stronger encryption. There's additional monitoring and detection, sandboxed execution, and automated review of the model's reasoning traces to catch risky actions early. External auditors, including government agencies and the UK AI Security Institute, are conducting independent testing — and OpenAI is imposing security requirements on those partners' own infrastructure. One OpenAI staffer put it plainly: the company is "consciously slowing down research to enhance security."

    If the most sophisticated AI developer in the world concludes that a model with agentic coding ability requires isolation, permissioning, monitoring, and third-party audit before deployment — what exactly is your bank, hospital, or logistics company going to need before it hands an AI agent credentials to its production systems?

    That's the spending. Not model licenses. The layer around the model: identity for machines, permissioning, sandboxing, activity logging, and — critically — proof after the fact that an agent did not cross a boundary it wasn't supposed to cross. An auditor will eventually ask for that evidence. Somebody has to sell the system that produces it.

    The Stock: SailPoint (NASDAQ: SAIL)

    SailPoint sells identity governance — the software that decides who and what is allowed to access which systems, enforces least-privilege rules, and produces the audit trail proving it. For twenty years that meant employees. The company's entire current strategy is that it now means machines and AI agents, which is exactly the problem OpenAI just illustrated at the frontier.

    The numbers show the shift is real. In its most recent quarter, annual recurring revenue reached $1.163 billion, up 26%, with SaaS ARR up 36% to $781 million and revenue up 22%. The relevant detail: non-human identities accounted for 40% of identity growth in the quarter and now represent 14% of all identities managed in its cloud platform. SaaS made up 92% of net new ARR. The company launched Agentic Fabric to discover AI agents, map ownership, enforce authorization, and monitor behavior; completed its acquisition of Entro Security in June specifically for agentic identities; shipped a connector in July to secure AI-driven software development in Cursor; and in August announced unified protection across human, non-human, and AI agent identities. Management raised full-year guidance and targets $800 million-plus of AI-driven ARR by fiscal 2029, against roughly $200 million of free cash flow this year.

    However, this is not a stock the market has been kind to.

    The last earnings report was a disaster for the shares. SailPoint fell more than 15% pre-market and as much as 21% intraday after its June report, despite raised guidance. Investors focused on decelerating ARR growth — 28% in fiscal 2026, 26% last quarter, guided to 24% next quarter — plus foreign-exchange headwinds, margin pressure, and a pickup in insider selling. Earnings per share came in below some estimates and management guided cautiously on Q2 profitability.

    The agentic opportunity is also earlier than the narrative implies. Management said roughly 10% of customers have adopted AI capabilities, that the agentic pipeline has been doubling but from a small base, and repeatedly noted it is not yet a meaningful contributor to reported results. This is a company selling the right story ahead of the revenue. Add a diluted share count near 571 million, competition from Okta, Microsoft, and Cisco, and a post-IPO shareholder base still forming, and you have a genuinely two-sided setup.

    One event to note: SailPoint reports fiscal Q2 on September 9 — about three weeks out. Given what happened to the stock in June, that print matters more than usual.

    Bottom line: AI adoption creates a security bill before it delivers a productivity dividend. Follow the companies that control access, evidence, and containment — and respect that the market has already punished this one once for growing into the story too slowly.

    📢 Sponsor Slot — rotating content will appear here

    2) The Defense Trade Is Becoming Capability-as-a-Service

    Two transactions from the same day tell the story. German drone maker Helsing enlisted Japan's Rakuten to help finalize a sale of unmanned systems to Japan's army. And India signed a 30-month lease for two General Atomics MQ-9B Sea Guardian drones for maritime surveillance — a roughly $203 million deal.

    Note the second one carefully: India didn't buy the aircraft. It leased them, for a defined term.

    The structural change is worth understanding. Allied governments want capability in the field faster than a traditional buy-and-build cycle allows. Leasing, local brokers, software updates, training, maintenance, and data services compress the path from contract to usable coverage. Hardware gets the press release; availability gets the renewal. It also changes what a defense contract is as a financial asset — a lease with service obligations behaves far more like a subscription than a delivery.

    So look for mission software, secure communications, repair networks, and integration expertise rather than the biggest airframe.

    Bottom line: Defense is shifting from one-time platform sales toward deployable capability. Favor recurring service revenue and local access, not just the biggest airframe.

    3) Biosimilars Are Turning Drug Patents Into a Price War

    Sandoz agreed to pay up to $77 million upfront to Shanghai Henlius Biotech for rights to three biosimilars targeting cholesterol, lupus, and colorectal cancer, plus development and commercial milestones, taking commercialization rights outside China ahead of a major loss-of-exclusivity window.

    The prize here isn't a molecule — it's the infrastructure to manufacture, win approval for, distribute, and price biologics once exclusivity fades. Contract manufacturers, regulatory specialists, and commercial platforms with payer access all collect a toll on that transition regardless of which specific biosimilar wins.

    And apply the discipline we've used on every licensing deal this month: milestones are a confession. When a buyer puts $77 million up front and holds the rest behind development and commercial achievements, it's telling you precisely where it thinks the risk lives and declining to pay for it today. Check clinical stage, interchangeability designation, manufacturing capacity, and cash needs before treating a licensing agreement as validation of anything.

    Bottom line: The next pharmaceutical value transfer may come from the patent cliff, not the laboratory. Favor companies that can deliver lower-cost biologics at scale.

    📢 Sponsor Slot — rotating content will appear here

    4) Alibaba Is Selling Games to Fund the AI Race

    Alibaba has reached a formal agreement to sell its gaming unit, Lingxi Games, to private equity firm Trustar Capital — formerly CITIC Capital — with Reuters reporting expected proceeds of more than $2 billion. Lingxi's management stays in place. It is the largest equity M&A transaction in China's gaming sector this year, and several listed Chinese gaming companies bid before Trustar won.

    Two cautions on the number itself. The $2 billion figure is source-reported, not disclosed — the internal memo confirming the agreement gave no value, no closing date, and no detail on regulatory approvals or conditions. Bloomberg's reporting put the value at at least $1.5 billion, and earlier estimates in June ranged from roughly $1.0 to $1.3 billion. That's a wide band for a deal being described as done.

    A conglomerate can own a valuable asset and still trade as though that asset doesn't exist. Selling a non-core division unlocks cash, simplifies the story, and funds a higher-priority buildout — here, CEO Eddie Wu's redirection of capital toward AI and cloud.

    One analysis notes that $2 billion covers roughly 80% of a single quarter's cash usage at Alibaba's current rate of AI and cloud investment. That reframes the transaction: it is a signal about strategic focus and a test of what the market will pay for a Chinese digital asset — not a solution to the balance sheet. Proceeds can be consumed quickly by AI capital spending, soft Chinese consumer demand, and losses in quick-commerce before cloud profitability scales.

    Alibaba reports June-quarter results on Thursday, August 20 — two days after you read this. Pay attention to that report and you'll see whether cloud growth is outrunning the cash burn. Read the print, then decide if the stock is right for your portfolio.

    Bottom line: In China tech, the contrarian trade may be asset recycling. Watch who is selling yesterday's growth to finance tomorrow's infrastructure — and check whether the proceeds are big enough to matter.

    5) The Next Energy-Security Trade Is Cooking Gas

    India has set targets for its oil companies to increase cooking-gas output as the Middle East conflict disrupts fuel flows. Energy security isn't only crude oil and power generation. For a country where hundreds of millions of households cook with liquefied petroleum gas, reliable LPG is as strategic as jet fuel.

    This is the household end of the same supply chain we've been tracking all month — the one running through a closed Strait of Hormuz, 8.3 million barrels a day of shut-in Gulf supply, and an IEA demand forecast cut because fuel became too expensive. Governments respond to that by managing domestic production and building buffers rather than relying on spot purchases, and that widens the investment map: refiners, storage operators, bottlers, pipeline businesses, and equipment suppliers all participate in resilience.

    But hold the enthusiasm to the same standard as any other policy trade. State-directed targets can compress margins. Subsidies shift. Capacity built for a crisis becomes uneconomic when the crisis passes — and the IEA now expects demand to return to growth in the fourth quarter with Brent averaging near $69 in 2027 as production recovers. Underwrite utilization and contract structure before strategic importance. A company can be essential to national policy and still be a poor investment; those are unrelated questions.

    No name today: the direct beneficiaries here are Indian state-controlled oil marketing companies, which are not practical positions for most readers, and the U.S.-listed propane and midstream names serve a different market with different economics. Don't let a good insight talk you into a bad proxy.

    Bottom line: Energy security is moving down the household supply chain. Watch who stores and delivers essential molecules, then check who captures the margin.

    Before You Go

    The market loves a theme because a theme is easy to sell. The harder work is finding the operating layer that remains after the headline disappears.

    AI needs containment — and the developer closest to the frontier just delayed its own product to build it. Defense needs deployment — and India leased its drones rather than buying them. Biosimilars need manufacturing and market access, which is what the money is actually chasing. Alibaba needs disciplined capital allocation, and a $2 billion sale that covers 80% of one quarter's burn tells you how large the ambition is. India needs fuel resilience down to the cooking stove.

    Four of tonight's five sections have no stock attached, and I want to be plain about that rather than dress it up. Two of the lanes are overbought. One reports earnings in 48 hours. One has no accessible way in. Handing you a name in each of those situations would be easy and would make this a worse letter.

    Identify the unavoidable problem, find the toll collector, then check whether the balance sheet can survive the wait. When there's nothing worth naming, the honest move is to say so and keep looking.

    Found this helpful? Share it with others.

    Written by Behind the Markets