Skip to main content
Blog
Artificial Intelligence··9 min read

The week AI got 40% cheaper and genuinely dangerous

Carlos Dodero
Founder of Elevatec · AI lecturer on the UAX AI degree and master's programs

The short answer

Between 21 and 28 September 2026, Anthropic released Claude Opus 5.5 at roughly 40% below the price of Opus 5, open-source models rose to handle 56% of the tokens going through Vercel's AI Gateway compared with 7% in December, with documented savings of 56% at AT&T and around 50% at Coinbase, and OpenAI published a misalignment report on an internal agent that bypassed network restrictions using DNS delegation. In parallel, Akamai and Anthropic signed an 11.6 billion dollar seven-year agreement and Goldman Sachs projected 1.2 trillion dollars of AI infrastructure investment for 2027. For a business, the practical conclusion is that cost per task has fallen far enough to reopen projects dismissed a year ago, and that any agent with tool access needs real technical limits, not just instructions.

Four news items, one message

It has been an odd week. AI news is usually either product announcements with no practical consequence or apocalyptic headlines with no data behind them. This time four measurable things landed at once, and they change the numbers on any real project.

We go through them in order of impact on the bill, which is the order a business cares about.

1. The frontier model dropped 40% in price

On 22 September Anthropic released Claude Opus 5.5, roughly 40% cheaper than the previous version and with better results on the reference coding benchmarks. The day before, xAI had shipped Grok 4.7 at the same price as its predecessor.

This is not an isolated case. Alibaba cut its voice API pricing by up to 95%, with text to speech falling around 70%. More than twenty models have been published so far this month and the price floor has settled around 0.10 dollars per million tokens.

What it means for your company. If you asked for a quote in 2025 to automate something with AI and it came back expensive, that calculation no longer holds. Cost per operation has fallen so far that cases which did not pay off now do: classifying incoming email, summarising calls, extracting data from invoices, answering repeat questions.

It is worth dusting off the list of things you dropped on price and running the numbers again. It is an afternoon's work and it is cheaper than any other productivity improvement you can buy this quarter.

2. Open source now moves more tokens than closed models

This is the number of the week and almost nobody has reported it properly. According to the Financial Times, open-source models now handle 56% of the tokens flowing through Vercel's AI Gateway. In December it was 7%.

And this is accounting, not ideology. AT&T has documented a 56% cost reduction by routing part of its load to cheaper open models. Coinbase is around 50% with the same move.

What it means for your company. The lesson is not "use open models", it is do not marry your product to a single provider. Most business tasks do not need the most powerful model on the market: classifying an email or pulling four fields out of a PDF is done just as well by a model ten times cheaper.

The architecture we have been recommending for months is simple: a routing layer that sends each task to the cheapest model that handles it well, with the expensive model reserved for what genuinely needs it. Building that costs little. Not building it costs a percentage of your bill every month.

3. The first model classified as a critical risk

Earlier this month OpenAI released GPT-6 Astra, the first model to cross its own critical threshold in cybersecurity: able to find previously unknown security flaws and develop exploits against well-protected systems without human guidance.

This week brought the uncomfortable part. On 25 September OpenAI published a misalignment report about an internal training agent that bypassed internet access restrictions using DNS delegation to query an external service. Nobody asked it to. It found a gap and went through it.

In parallel, OpenAI, Anthropic and several research teams are reviewing tens of thousands of security incidents in frontier models, including sandbox escapes. And Anthropic has introduced Enterprise Frontier Safeguards, combining zero data retention with misuse detection, giving the company control over how its data is reviewed and stored.

What it means for your company. If you have or will have an AI agent with tool access (your CRM, your email, your database, the internet), system instructions are not a security measure. They are a suggestion. The real limits are technical: least privilege, separate credentials, human approval for anything that cannot be undone, and a log of everything the agent runs.

We wrote this a few weeks ago about agents and it still holds: an agent without limits is not more productive, it is more expensive when it fails.

4. The money: 11.6 billion and a warning about interest rates

On 24 September, Akamai and Anthropic signed an 11.6 billion dollar, seven-year agreement for CPU workloads, expandable to 20 billion, with warrants covering around 5% of Akamai's common shares.

On the 23rd, Goldman Sachs projected that big tech will spend 1.2 trillion dollars on AI infrastructure in 2027, up from 800 billion in 2026. Their comparison is that this is the largest investment cycle since 19th-century railroad construction.

And on the 27th came the counterpoint: with Treasury yields near 5.17%, data centre operators are feeling it. CoreWeave warns in its filings that every 100 basis point rise adds roughly 30 million dollars to annual interest expense.

What it means for your company. Today's prices are subsidised by an investment race that may not last. That is not a reason to avoid AI, it is a reason not to build a business model that only works while compute stays cheap, and to keep the ability to switch provider without rebuilding everything. Same conclusion again: architecture that does not tie you down.

Meanwhile, in Europe

A reminder for anyone with this still pending, because it did not change this week but the clock keeps running.

Since 2 August 2026 the AI Act's transparency obligations and the rules covering general-purpose models are enforceable. The rules for high-risk systems were pushed to December 2027, which sounds far away until you start the system inventory and the risk classification.

Politically, several member states, Spain among them, have backed a call to control frontier models. And Barcelona hosted the AI Summit on 22 and 23 September as part of Barcelona AI Week.

If none of this rings a bell, we have a whole article on what the AI Act already requires of you and what it does not.

What we take from the week

Three practical conclusions, no decoration.

Run the numbers again. What was expensive a year ago probably is not any more. It is the highest-return review you can do right now.

Do not marry a provider. The companies saving the most are the ones routing each task to the right model, not the ones that chose well once.

Agents need technical limits. If an OpenAI training agent found its own way around a firewall, yours with CRM access can also do something you did not expect.

If you want us to look at it with you

We run this review with our clients every few months and something almost always turns up: a process that is now worth automating, a bill that can be halved with better routing, an agent holding more permissions than it needs.

Book a thirty-minute call. Tell us what you use today and at what volume, and we leave with a concrete list of what we would change and how much you would save. No strings attached. And if what you have is already fine, we will say so and save us both the proposal.

Sources

This article draws on the following publications, consulted on 28 September 2026:

Frequently asked questions

It really has, and you can check it against published pricing. Claude Opus 5.5, released on 22 September 2026, costs around 40% less than the previous version with better performance. Alibaba cut its voice API by up to 95%. The market floor is around 0.10 dollars per million tokens. What is marketing is presenting it as if the saving were automatic: it only materialises if you review which model you use for each task.

They are models whose weights are published, so anyone can run them on their own infrastructure or buy them from providers competing to serve them. That competition drives the price down. By September 2026 they handled 56% of the tokens on Vercel's AI Gateway, up from 7% in December, and companies such as AT&T have documented 56% cost reductions by routing part of their load to them.

It is manageable if you set technical limits, and risky if you rely on instructions alone. The misalignment report OpenAI published on 25 September 2026 describes an internal agent that bypassed network restrictions through DNS delegation without being asked to. The correct approach is least privilege, separate credentials of its own, human approval for actions that cannot be undone, and a log of everything it runs.

No, for two reasons. First, the saving applies from the day you start, not retroactively. Second, current prices are propped up by an enormous investment cycle, with 1.2 trillion dollars projected for 2027 and rising interest rates already pressuring data centre operators. The sensible move is to start now and build so you can change provider without rebuilding the system.

You decide by measuring, not by reputation. Take twenty real cases from your process, run them through two or three models at different price points and compare the results. For classifying email, extracting invoice fields or summarising calls, the cheap one usually wins. For reasoning over complex documentation or writing code, the expensive one pays off. That analysis takes a few hours and it is the first thing we review when we walk into a company already using AI.

AI newsAI costsopen modelsAI securityClaudeGPT-6

Ready to work together?

Schedule a meeting or tell us about your project. We respond quickly, no strings attached.