Insights · AI, AppSec and compliance without guesswork

The numbers most SMBs find out too late.

How much AI really costs, how much extra you pay per token, how long it takes to reach mature security, and by when EU law sets the deadline. Every article answers a question a client asked us, with the source right next to it.

  • Output token price
    106×
  • Cost per automated task
    US$ 0,02/ticket
  • The price of the leak
    US$ 5
  • High risk (Annex III)
    dez/2027
§01FeaturedGATEWAY · JUL · 2026 · 6 min · most read

LLM output prices vary 106× between vendors. Your SMB pays the ceiling.

In September 2026, output from the priciest model in the public catalog (Claude Fable 5.1, $50 per 1M tokens) costs 106 times the cheapest one that still handles production work (Qwen3.8-Flash, $0.47). No SMB needs the top of that list to triage a support ticket or pull a field off an invoice. Run everything on one vendor and you pay the top price on 100% of requests.

What to do tomorrowBreak last month's invoice down by task type, not by model: around 70% of volume is usually light work paying frontier prices. Then put the gateway in front — with it, swapping models is configuration, not migration.
Read the full articlesource: OpenAI · API pricing
Output per 1M tokens (USD, Sep 2026)10 models
anthropic · fable 5.1
$50.00
anthropic · opus 5
$25.00
openai · gpt-5.6 sol
$20.00
google · gemini 3.1 pro
$12.00
mistral · medium 3.5
$7.50
zhipu · glm-5.3
$4.40
google · gemini 3.8 flash
$3.75
mistral · large 3
$1.50
openai · gpt-5.6 luna
$1.20
alibaba · qwen3.8-flash
$0.4799%
§02ArticlesGateway · AppSec · Compliance · Consulting

All articles

CONSULTORIA · AGO · 2026 · 6 min

What AI really costs in 2026: three bands, with the arithmetic shown

Ten people on ready-made subscriptions cost $317 a month. The API automation that handles 4,000 tickets in that same month costs $90 — $0.02 per ticket, with routing and caching. The expensive band is not the one you expect, and the number that decides the project is not on the vendor invoice.

Monthly vendor bill per band (USD/month, 10-person company)
faixa 1 · 10 assentos padrão317
faixa 1 · 10 assentos premium1117
faixa 3 · IA no produto (tokens + operação)920
faixa 2 · mesma carga, modelo de topo400
Read articlesource: Claude · Pricing
APPSEC · ABR · 2026 · 8 min

OWASP LLM Top 10 (2025): five risks already in the incident record — and how to cover each

The 2025 OWASP list for LLM applications was rewritten after two years of real incidents. It does not replace the web Top 10 — it adds to it. For a team of five or ten engineers with an AI feature in production, the question is not knowing all ten items: it is knowing which five to close first, what each costs in engineering days, and what to check before the release.

OWASP LLM Top 10 · 2025
LLM01 · Prompt Injectionhigh
LLM02 · Sensitive Information Disclosurehigh
LLM03 · Supply Chainhigh
LLM04 · Data and Model Poisoningmed
Read articlesource: OWASP Gen AI Security Project · Top 10 for LLM Applications 2025
COMPLIANCE · MAR · 2026 · 7 min

The EU AI Act after the Digital Omnibus: the real calendar and a 90-day plan

On 2 August 2026 the EU AI Act became generally applicable and enforcement began. The Digital Omnibus, in force since 27 July 2026, pushed the high-risk rules to 2 December 2027 — and left everything else in place. If your company sells into the EU or processes EU residents' data, the comfortable window has already closed.

EU AI Act applicability
AGO · 2026General applicability: transparency (Art. 50) and enforcement
SET · 2026Today
DEZ · 2026Marking of legacy synthetic content and new prohibitions
DEZ · 2027Annex III high risk (deferred by the Digital Omnibus)
Read articlesource: EUR-Lex · Regulation (EU) 2024/1689 (Artificial Intelligence Act)
APPSEC · FEV · 2026 · 8 min

SAMM 0→3 in an SMB: 12 months, five practices, and the order that matters

OWASP SAMM has 90 activities and a 0-to-3 scale per practice. In the official benchmark, dominated by multinationals, the average is 1.44 — and Verification sits at 1.12. The bar for mature is lower than the word suggests. With tight scope and the right order, an SMB reaches level 3 on the critical practices in four quarters.

SAMM on the critical practices · SMB · month 0 vs month 12
secure build · M123
security testing · M122
threat assessment · M122
defect management · M122
Read articlesource: OWASP SAMM · The Model (v2)
§03How we writeAll insights

No loose opinions. Every number has a source, every article ends with what to do.

We write what we learn solving the problem for a client. If your situation looks like one of these, the conversation starts here.