If you run a business on AI, the most important thing that happened recently wasn't a breakthrough. It was a price tag.

In the span of about forty eight hours, the cost of good enough AI fell off a cliff. Three new models landed in the middle of the market at a fraction of flagship prices. Then the two biggest labs cut their flagship prices on the same day, which has never happened before.

Meanwhile, the security news went the other way, and a couple of stories about what AI tools do on your computer when you're not watching should change how you install things.

Here's what happened and what to do about each one.

The two biggest labs cut prices on the same day

On September 22, Anthropic released Claude Opus 5.5 at $4 per million input tokens and $20 per million output, down from $5 and $25 for Opus 5. Anthropic says it performs about as well as its more expensive Fable 5.1 model on most work while running roughly 40 percent cheaper than Opus 5. It also cut the price of cached reads from fifty cents to twenty cents per million tokens.

Within hours, OpenAI released GPT-6 Sol at $2 and $10, and GPT-6 Luna at ten cents and fifty cents. Both have a context window of about 1.05 million tokens, and both are roughly half the price of the models they replace.

What to do. Don't switch everything tomorrow. Test first. OpenAI's own published numbers showed Sol scoring below its predecessor on some agentic coding benchmarks, and a cheaper model that's worse at your specific task is still worse.

But do schedule the test. Pick your three highest volume workflows, run five real inputs through the new cheaper options, and compare. For bulk work like classification, tagging and extraction, Luna's pricing is low enough that it changes what's worth automating at all. Things you skipped because the math didn't work at last month's prices might work now.

And look at your cache settings. If any workflow sends the same long instructions or reference material over and over, caching was already worth it. At twenty cents, it's close to mandatory.

The middle of the market got crowded

The price cuts didn't come out of nowhere. In the two days before, three models landed in the same capability band. xAI shipped Grok 4.7 at $2 and $6. Xiaomi released its MiMo V2.6 models under an MIT licence, with the Pro version scoring 46 on the Artificial Analysis Intelligence Index. StepFun put out Step 5 Preview, with open weights promised for October 15.

All three sit within a few points of the flagships on a lot of practical work, at a fraction of the cost. Some of them you can download and run yourself for free.

What to do. Understand what this means for your planning. The cost of capable AI is falling faster than almost any other input in your business. A budget you set in the spring is probably too high now for the same work.

That's also why building your workflows so you can swap models easily matters so much. If changing models means editing twenty scenarios by hand, you won't do it, and you'll keep paying last quarter's prices.

Harvey's margins went negative and it fixed them by owning the model

Bloomberg reported that Harvey, the legal AI company valued at $15.6 billion, saw its gross margin swing from about positive 50 percent to negative 50 percent by June as customer usage grew about twenty times. It fixed the problem by launching an in house model in August, built on Moonshot's Kimi K3.

What to do. We covered this in depth on Tuesday, so the short version: if you charge customers a flat fee and pay for AI by usage, check the math on your heaviest customers. Your happiest customer might be your least profitable one.

Claude Opus 5 went down for more than a day

Anthropic opened an incident early on September 22 covering several of its top models across its apps, API, Claude Code and Cowork. Most recovered that morning. Opus 5 kept returning elevated errors into a second day. It was the third capacity signal from Anthropic in about two weeks.

What to do. Monday's issue covered the full failover build. If you skipped it: every important workflow needs a retry, a fallback to a model from a different company, and a validation check. One afternoon of work.

An AI tool uploaded 42,411 files without asking

Developers found that ZCode, a coding tool from the Chinese lab Z.ai, was quietly uploading snapshots of users' local workspaces to overseas servers when it launched. One examined install produced an encrypted archive of 42,411 files. Z.ai said it was telemetry, removed the behavior, and open sourced the tool.

In a separate story, security researcher Patrick Wardle disclosed a flaw in Meta's Muse agent for Mac that let any locally installed app steal the user's login tokens.

What to do. This is the story from the week that matters most for how you actually work, and it's not just about one vendor.

AI tools that run on your computer can see your files. Some of them need to, that's how they work. But "can see your files" and "uploads your files somewhere" are very different things, and you usually can't tell which one you've got from the marketing page.

Three practical rules. First, when you try a new desktop AI tool, try it on a machine or user account that doesn't have client files, financial records or passwords on it. Second, read what permissions it asks for during install, and say no to anything that doesn't obviously match what the tool does. Third, keep sensitive client material in folders that AI tools don't have access to by default.

None of this means stop using desktop AI tools. Some of them are excellent. Tools like Littlebird that work from your screen are useful exactly because they see what you see. It means pick tools from companies that are clear about where your data goes, and don't give anything broader access than it needs.

Shopify turned on agent shopping by default

On September 21, Shopify announced a partnership letting Meta's Muse agent search Shopify's catalog and complete purchases through Shop Pay across Shopify stores, routed through the Universal Commerce Protocol. It's on by default. The same week, Amazon filed an amended complaint against Perplexity, alleging Perplexity made false statements to an appeals court about how its Comet browser agent accessed Amazon's systems.

What to do. If you sell on Shopify, go look at your merchant settings this weekend. You should know whether AI agents can buy from your store, and you should decide on purpose rather than by default. For most merchants, being open to agent purchases is probably good for sales. But it's your decision, and you should make it knowingly.

The bigger picture: the fight over whether AI agents can shop on your behalf is being settled two ways at once. Lawsuits on one side, partnership deals on the other. The deals are winning, because they make money for everyone involved.

The first fully autonomous AI malware showed up

Cisco Talos disclosed something it calls CLOSEDQUORUM, which it describes as the first reported fully autonomous, multi model AI command and control implant. Malware that picks its own next moves with no human running it. Talos released a free toolkit called CAIRN for hunting this kind of threat.

It's the third week running with a major agent driven attack story, after the PaperCut campaign we covered two weeks ago.

What to do. For most small businesses, this doesn't change your checklist. It changes how seriously you should take it. Keep software updated. Use a password manager and two factor authentication on everything that offers it. Know which of your automations can take actions nobody reviews. The attacks are getting faster. The basics are still what stops most of them.

Stripe got 83 percent of its company using an internal AI platform

Stripe reported that its internal knowledge platform, Kai, launched in April, reached most of the company within two weeks and now sees 83 percent weekly active use, including nearly all of its go to market staff. It connects to more than 1,000 internal tools and skills.

What to do. Most companies that roll out AI tools see a burst of enthusiasm and then usage drops off a cliff. Eighty three percent weekly use months later is a real number, and it's worth thinking about why. I'm going deeper on this tomorrow, because I think it's the most useful business story of the week.

Big open models now run on a laptop

Tim Dettmers' research lab at the University of Washington and Carnegie Mellon started a week of open source releases, including tools that run DeepSeek V4.1, a 550 billion parameter model, on a 128 gigabyte MacBook.

What to do. Most of you don't have that machine, and this isn't a buying recommendation. But notice the direction. A year ago, running a model this size meant renting serious cloud hardware. Now it fits on a high end laptop. If you've avoided AI because your data legally can't leave your building, the hardware that solves that problem is getting cheaper fast.

The through line

Put all of this together and a clear pattern shows up.

The cost of AI capability is collapsing. The middle of the market is crowded with good, cheap options. The flagships are cutting prices to keep up. Anyone paying last quarter's prices for this quarter's work is overpaying.

At the same time, the tools are getting more access to your stuff, your files, your store, your accounts, and the security around them hasn't caught up. The ZCode story and the Muse flaw are the same lesson from two directions: convenience and exposure are growing together.

So the job for the next quarter is two things at once. Take the price cuts, by building workflows that can switch models easily and actually testing the cheaper options. And tighten the access, by being deliberate about what every tool on your machine and in your stack can reach.

Neither one is exciting. Both will make you money or save you a mess.

FROM THE AI NEWSROOM

The AI Workflow Blueprint

The exact systems behind everything in this issue. The audit sheets, the routing logic, the templates and the review cadences, built out step by step so you can copy them straight into your own stack. One time, forty seven dollars.

Get the Blueprint for $47

.....

This week

Pick one of the two jobs above.

If you pick price: find your highest volume AI workflow and test it on one of the new cheaper models with five real inputs. If the output holds up, switch it.

If you pick access: go through every AI tool installed on your work computer and every AI app connected to your email, drive and store. Remove anything you haven't used in a month. Check what the rest can reach.

One hour either way. Both are worth more than reading about next week's launches.

Jordan

The AI Newsroom | Practical AI for people with a business to run.