The GPU Collateral Question: Financing the AI Build-Out Without Breaking the Balance Sheet
Lenders are writing nine-figure facilities against racks of GPUs, and founders are being offered 'cheap' compute debt with covenants that would make a restructuring advisor wince. Here is how to underwrite silicon as collateral before it underwrites you.
Overview
Two years ago, a growth-stage company that needed serious compute had two options: pay a hyperscaler's list price out of operating cash, or raise equity and watch a third of the round flow straight into a cloud bill. A third option has since matured into a real market. Specialist lenders, credit funds and the financing arms of the chip ecosystem now write facilities secured directly against GPU clusters, and the 'neocloud' providers that emerged to rent that capacity have layered their own debt on top. The result is that a founder can, for the first time, finance the physical layer of an AI business the way a logistics company finances trucks.
That is genuinely useful, and genuinely dangerous, for the same reason: the collateral is a depreciating technology asset whose value is set by a product roadmap the borrower does not control. A truck loses value on a curve that has been observed for a century. A top-tier accelerator loses value when a keynote announces its successor. The lenders know this, which is why the headline interest rate on compute debt often looks reasonable while the structure around it — amortization speed, residual value guarantees, utilization covenants, refresh obligations — transfers the technology risk back to the borrower in ways that only become visible in a downside case.
This article is a field guide for the CFO or founder staring at a term sheet for GPU-backed debt, a take-or-pay compute contract, or a vendor-financed cluster. The goal is not to talk you out of it. Used correctly, compute financing preserves equity for the risks equity is actually good at bearing. The goal is to make sure that when you sign, you know precisely which risks you have kept, which you have sold, and what the answer implies for your runway model, your next fundraise, and your eventual diligence file.
Overview, indexed
Indexed performance across six rolling quarters; capital cohort, n ≈ 143.
Why lenders will underwrite silicon at all
The lender's logic is straightforward. Demand for training and inference capacity has outrun supply for long enough that a financed cluster, placed with a credible operator, generates contracted revenue from day one. The lender is not really underwriting the chips; it is underwriting the offtake contracts attached to them, with the hardware as a recovery asset of last resort. This is project finance logic imported into venture-scale companies, and it explains both the availability of the product and its limits. Where your revenue is contracted, diversified and longer-dated than the debt, the facility is cheap and the covenants are soft. Where it is not, the lender prices the gap and takes security over everything it can reach.
The second driver is the secondary market. A liquid resale channel for used accelerators — brokered, auctioned and increasingly standardized — gives lenders a recovery assumption they can defend to their own investment committees. But liquidity in a rising market is not liquidity in a falling one. The same dynamic that makes a used three-year-old card worth 60% of list today can make it worth 25% the quarter a new architecture ships with a step-change in performance per watt. Recovery assumptions set in a supply-constrained market should be treated as marketing, not analysis.
The third driver is strategic. Some of the most aggressive compute financing comes from parties with an interest in the demand side of the chip market itself: vendors financing purchases of their own hardware, and clouds financing capacity that locks in consumption of their platform. Vendor financing is not inherently bad — it is how aircraft and telecom networks have been built for decades — but it deserves the same skepticism as any situation where the party setting the price of the asset is also setting the terms of the loan against it. When your lender is also your supplier, every negotiation is two negotiations.
“Where it is not, the lender prices the gap and takes security over everything it can reach.
The residual value problem
Every compute financing model contains a number that decides whether the deal works: what the hardware is worth at the end of the facility. Lenders typically amortize the loan faster than they expect the collateral to depreciate, which protects them and quietly concentrates the risk at the borrower's exit from the arrangement. If the facility amortizes to 40% of original cost over three years and the true market value of the cluster at that point is 25%, the borrower is either refinancing into a hole, extending on worse terms, or handing back hardware and writing off the difference. The time to discover which of those you have agreed to is before signature.
The honest way to set the assumption is to ignore the lender's curve and build your own from three inputs. First, the announced cadence of successor architectures, which now runs on a roughly annual rhythm and resets the price-performance frontier each cycle. Second, the observed resale discount of the previous generation once its successor ships, which historically has been severe in the first two quarters and then stabilizes. Third, the utilization economics of older silicon: a card that is obsolete for frontier training may still earn acceptable returns on inference for years, which puts a floor under value that pure obsolescence models miss. A residual value case that survives a 40 to 60% write-down against the lender's base case is one you can sign; one that requires the base case to be right is a bet, and should be sized and disclosed as one.
Watch, too, for the residual value guarantee dressed up as a feature. Some structures offer the borrower a 'guaranteed buyback' or a 'refresh option' that caps downside — in exchange for pricing the guarantee into the rate, the term, or a commitment to purchase the next generation from the same vendor. There is nothing wrong with buying that insurance knowingly. The failure mode is discovering in diligence for your Series C that the refresh obligation is, in substance, a multi-year purchase commitment that an acquirer will treat as debt. Every option in the term sheet has a price; the job is to find it before your investors do.
Where the hours go, the residual value problem
- AI-handled volume38%
- Advisor judgment31%
- Client decisioning21%
- Buffer10%
Distribution observed across CapMaven engagements · seed 760
Structuring the facility: tenor, covenants and the utilization trap
The first structural rule is tenor matching. Compute debt should be repaid by the revenue the compute generates, which means the facility's life should sit comfortably inside the life of the contracts that service it. Three-year amortizing debt against annual contracts with committed customers is financeable. The same debt against month-to-month API revenue is a refinancing machine: you are betting that capital markets, your growth rate and your lender's appetite all remain friendly at the moment the balloon comes due. If the revenue is short-dated, either the debt must be smaller, the equity cushion larger, or the amortization slower — pick at least one, because the market will eventually pick for you.
The second rule is to read the utilization covenant as the real pricing mechanism. Many facilities include minimum utilization or minimum revenue tests measured against the financed cluster, with cash sweeps or margin ratchets when the tests are missed. These clauses convert a demand problem into a liquidity problem at exactly the wrong moment: a soft quarter triggers a sweep, the sweep drains the operating account, and the company is suddenly negotiating with its lender instead of serving its customers. Negotiate the test levels against your downside case, not your plan; negotiate a cure mechanism that uses time before it uses cash; and model the sweep in your 13-week forecast as a standing scenario, not a tail risk.
The third rule is to keep the security perimeter narrow. The natural drift of these facilities is toward an all-assets lien: the lender starts with the cluster, adds the receivables it generates, then asks for the IP 'for comfort.' Each expansion is individually defensible and collectively fatal, because a lender with a lien on everything is a lender who must consent to your next equity round, your next facility and, in a stress case, your sale process. Ring-fence the collateral to the hardware and its direct receivables, accept a higher rate as the price of that ring-fence, and treat any request for the IP as the negotiation's real center of gravity.
Signal
Identify the leading indicator that moves first.
Sample
Build the smallest cohort that proves the thesis.
Scale
Hard-code the cadence into a weekly operating rhythm.
Sunset
Retire metrics that stopped predicting outcomes.
Jurisdiction callouts
In the United States, the market is the deepest and the documentation the most standardized, with most facilities structured as equipment loans or leases under UCC Article 9 filings against the hardware. The practical nuance is tax: the treatment of accelerated depreciation on compute hardware can materially improve the after-tax cost of ownership versus rental, but the benefit depends on the entity's taxable position, which many loss-making AI companies cannot currently use. Sale-leaseback structures that transfer the tax capacity to a lessor who can use it are often the real reason a lease beats a loan, and the comparison should be run on after-tax cash flows, not headline rates.
In the United Kingdom and the European Union, the collateral question gets harder because the hardware frequently sits in a third-party data center in a different jurisdiction from the borrower, the lender and the operating entity. Perfecting security over equipment located in a colocation facility requires the cooperation of the facility operator, and the enforceability of that security in an insolvency varies more than the term sheets suggest. Cross-border structures should assume an extra four to eight weeks of legal work and a real possibility that the lender's recovery in the hardware's home jurisdiction is weaker than the model assumes — which is precisely why some lenders quietly price European compute risk wider than American.
In the United Arab Emirates, the build-out of sovereign-backed AI infrastructure has created a financing environment where the state-adjacent anchor tenant changes the credit equation entirely. A cluster with a government-linked offtake contract is bankable on terms a private customer book could never support, and the free zone regimes in DIFC and ADGM provide a common-law security framework that international lenders will underwrite against. The nuance is concentration: a facility whose economics depend on a single sovereign-adjacent counterparty is exposed to procurement-cycle risk that no covenant can fix, and the diligence question 'what happens if the anchor tenant's strategy rotates' deserves a written answer, not a reassuring call.
- Repetitive tagging and reconciliation
- Multi-source variance detection
- Scenario re-runs at hourly cadence
- Pattern-matching against deal history
- Calling the asymmetric bet
- Reading the room in a diligence call
- Choosing what not to model
- Owning the relationship after close
The CFO's diligence checklist
Before signing any compute financing, run the five tests that separate a capital structure decision from an expensive lesson. First, the write-down test: re-run the model with the collateral worth 50% less at exit and confirm the company still services the debt without a rescue round. Second, the tenor test: lay the debt amortization schedule next to the revenue contract maturities and confirm the debt is always inside the contracts. Third, the sweep test: model the utilization covenant being missed for two consecutive quarters and confirm the resulting cash sweep does not breach your own minimum liquidity floor. Fourth, the perimeter test: list every asset the lender can reach in a default and confirm the IP, the data and the customer contracts are not on it. Fifth, the exit test: ask how the facility is treated in an acquisition — whether it is assumable, prepayable without penalty, or a change-of-control default — because the answer will be discovered in a data room at the worst possible time if you do not ask it now.
Then step back and ask the allocation question that the whole analysis serves. A company's risk budget is finite, and every unit of risk parked in the financing structure is a unit unavailable to the product roadmap. Hardware risk — obsolescence, residual value, refresh cycles — is best borne by parties with portfolios of hardware and the tax capacity to use depreciation, which argues for leasing or vendor financing of the physical layer. Utilization risk is best borne by whoever controls demand, which is usually you, and should be priced consciously rather than discovered in a covenant. Customer risk belongs with equity, because equity is the only capital patient enough to wait for a market to form.
The companies that come through this build-out well will not be the ones that avoided compute debt or the ones that took the most of it. They will be the ones that can produce, on request, a one-page answer to the question every serious investor and acquirer now asks: what do you own, what do you owe, what is it secured against, and what happens to all three if the next architecture cycle is unkind. If your financing lets you answer that calmly, it is doing its job. If the answer requires a spreadsheet and a caveat, the structure — not the market — is the risk you should fix first.
Move from reading,
to a written read on your numbers.
Two weeks. Three scenarios. A senior advisor on the call. The CFO Diagnostic gives you the artifact most founders only see after a fundraise.
