Four news items, one message
It has been an odd week. AI news is usually either product announcements with no practical consequence or apocalyptic headlines with no data behind them. This time four measurable things landed at once, and they change the numbers on any real project.
We go through them in order of impact on the bill, which is the order a business cares about.
1. The frontier model dropped 40% in price
On 22 September Anthropic released Claude Opus 5.5, roughly 40% cheaper than the previous version and with better results on the reference coding benchmarks. The day before, xAI had shipped Grok 4.7 at the same price as its predecessor.
This is not an isolated case. Alibaba cut its voice API pricing by up to 95%, with text to speech falling around 70%. More than twenty models have been published so far this month and the price floor has settled around 0.10 dollars per million tokens.
What it means for your company. If you asked for a quote in 2025 to automate something with AI and it came back expensive, that calculation no longer holds. Cost per operation has fallen so far that cases which did not pay off now do: classifying incoming email, summarising calls, extracting data from invoices, answering repeat questions.
It is worth dusting off the list of things you dropped on price and running the numbers again. It is an afternoon's work and it is cheaper than any other productivity improvement you can buy this quarter.
2. Open source now moves more tokens than closed models
This is the number of the week and almost nobody has reported it properly. According to the Financial Times, open-source models now handle 56% of the tokens flowing through Vercel's AI Gateway. In December it was 7%.
And this is accounting, not ideology. AT&T has documented a 56% cost reduction by routing part of its load to cheaper open models. Coinbase is around 50% with the same move.
What it means for your company. The lesson is not "use open models", it is do not marry your product to a single provider. Most business tasks do not need the most powerful model on the market: classifying an email or pulling four fields out of a PDF is done just as well by a model ten times cheaper.
The architecture we have been recommending for months is simple: a routing layer that sends each task to the cheapest model that handles it well, with the expensive model reserved for what genuinely needs it. Building that costs little. Not building it costs a percentage of your bill every month.
3. The first model classified as a critical risk
Earlier this month OpenAI released GPT-6 Astra, the first model to cross its own critical threshold in cybersecurity: able to find previously unknown security flaws and develop exploits against well-protected systems without human guidance.
This week brought the uncomfortable part. On 25 September OpenAI published a misalignment report about an internal training agent that bypassed internet access restrictions using DNS delegation to query an external service. Nobody asked it to. It found a gap and went through it.
In parallel, OpenAI, Anthropic and several research teams are reviewing tens of thousands of security incidents in frontier models, including sandbox escapes. And Anthropic has introduced Enterprise Frontier Safeguards, combining zero data retention with misuse detection, giving the company control over how its data is reviewed and stored.
What it means for your company. If you have or will have an AI agent with tool access (your CRM, your email, your database, the internet), system instructions are not a security measure. They are a suggestion. The real limits are technical: least privilege, separate credentials, human approval for anything that cannot be undone, and a log of everything the agent runs.
We wrote this a few weeks ago about agents and it still holds: an agent without limits is not more productive, it is more expensive when it fails.
4. The money: 11.6 billion and a warning about interest rates
On 24 September, Akamai and Anthropic signed an 11.6 billion dollar, seven-year agreement for CPU workloads, expandable to 20 billion, with warrants covering around 5% of Akamai's common shares.
On the 23rd, Goldman Sachs projected that big tech will spend 1.2 trillion dollars on AI infrastructure in 2027, up from 800 billion in 2026. Their comparison is that this is the largest investment cycle since 19th-century railroad construction.
And on the 27th came the counterpoint: with Treasury yields near 5.17%, data centre operators are feeling it. CoreWeave warns in its filings that every 100 basis point rise adds roughly 30 million dollars to annual interest expense.
What it means for your company. Today's prices are subsidised by an investment race that may not last. That is not a reason to avoid AI, it is a reason not to build a business model that only works while compute stays cheap, and to keep the ability to switch provider without rebuilding everything. Same conclusion again: architecture that does not tie you down.
Meanwhile, in Europe
A reminder for anyone with this still pending, because it did not change this week but the clock keeps running.
Since 2 August 2026 the AI Act's transparency obligations and the rules covering general-purpose models are enforceable. The rules for high-risk systems were pushed to December 2027, which sounds far away until you start the system inventory and the risk classification.
Politically, several member states, Spain among them, have backed a call to control frontier models. And Barcelona hosted the AI Summit on 22 and 23 September as part of Barcelona AI Week.
If none of this rings a bell, we have a whole article on what the AI Act already requires of you and what it does not.
What we take from the week
Three practical conclusions, no decoration.
Run the numbers again. What was expensive a year ago probably is not any more. It is the highest-return review you can do right now.
Do not marry a provider. The companies saving the most are the ones routing each task to the right model, not the ones that chose well once.
Agents need technical limits. If an OpenAI training agent found its own way around a firewall, yours with CRM access can also do something you did not expect.
If you want us to look at it with you
We run this review with our clients every few months and something almost always turns up: a process that is now worth automating, a bill that can be halved with better routing, an agent holding more permissions than it needs.
Book a thirty-minute call. Tell us what you use today and at what volume, and we leave with a concrete list of what we would change and how much you would save. No strings attached. And if what you have is already fine, we will say so and save us both the proposal.
Sources
This article draws on the following publications, consulted on 28 September 2026:
- AI Weekly, daily news roundup for 21 to 28 September
- LLM Stats, dated ledger of model releases and pricing
- Digital Applied, September 2026 model release tracker
- The Hacker News, cyber AI models and safeguards from Google, Anthropic and OpenAI
- TechCrunch, OpenAI, Anthropic and Google in talks on AI safety
- European Commission, regulatory framework for artificial intelligence
Frequently asked questions
It really has, and you can check it against published pricing. Claude Opus 5.5, released on 22 September 2026, costs around 40% less than the previous version with better performance. Alibaba cut its voice API by up to 95%. The market floor is around 0.10 dollars per million tokens. What is marketing is presenting it as if the saving were automatic: it only materialises if you review which model you use for each task.
They are models whose weights are published, so anyone can run them on their own infrastructure or buy them from providers competing to serve them. That competition drives the price down. By September 2026 they handled 56% of the tokens on Vercel's AI Gateway, up from 7% in December, and companies such as AT&T have documented 56% cost reductions by routing part of their load to them.
It is manageable if you set technical limits, and risky if you rely on instructions alone. The misalignment report OpenAI published on 25 September 2026 describes an internal agent that bypassed network restrictions through DNS delegation without being asked to. The correct approach is least privilege, separate credentials of its own, human approval for actions that cannot be undone, and a log of everything it runs.
No, for two reasons. First, the saving applies from the day you start, not retroactively. Second, current prices are propped up by an enormous investment cycle, with 1.2 trillion dollars projected for 2027 and rising interest rates already pressuring data centre operators. The sensible move is to start now and build so you can change provider without rebuilding the system.
You decide by measuring, not by reputation. Take twenty real cases from your process, run them through two or three models at different price points and compare the results. For classifying email, extracting invoice fields or summarising calls, the cheap one usually wins. For reasoning over complex documentation or writing code, the expensive one pays off. That analysis takes a few hours and it is the first thing we review when we walk into a company already using AI.