---
title: "OkamiOps Insights - AI, AppSec and compliance with data"
description: "Technical notes on AI, AppSec, compliance and markets with public data, cited sources and auditable charts."
url: https://okamiops.com/insights/
lang: en
alternates:
  en: https://okamiops.com/insights/
  pt-BR: https://okamiops.com/pt/insights/
  de: https://okamiops.com/de/insights/
  x-default: https://okamiops.com/insights/
lastmod: 2026-09-10
---

# The numbers most SMBs find out too late.

Insights · AI, AppSec and compliance without guesswork

How much AI really costs, how much extra you pay per token, how long it takes to reach mature security, and by when EU law sets the deadline. Every article answers a question a client asked us, with the source right next to it.

- **Output token price**: 106×
- **Cost per automated task**: US$ 0,02 /ticket
- **The price of the leak**: US$ 5
- **High risk (Annex III)**: dez/2027

## LLM output prices vary 106× between vendors. Your SMB pays the ceiling.

In September 2026, output from the priciest model in the public catalog (Claude Fable 5.1, $50 per 1M tokens) costs 106 times the cheapest one that still handles production work (Qwen3.8-Flash, $0.47). No SMB needs the top of that list to triage a support ticket or pull a field off an invoice. Run everything on one vendor and you pay the top price on 100% of requests.

> **What to do tomorrow**: Break last month's invoice down by task type, not by model: around 70% of volume is usually light work paying frontier prices. Then put the gateway in front — with it, swapping models is configuration, not migration.

- [Read the full article](https://okamiops.com/insights/llm-cost-spread-2026/)

Output per 1M tokens (USD, Sep 2026) · 10 models

| Item | Value |
| --- | --- |
| anthropic · fable 5.1 | $50.00 |
| anthropic · opus 5 | $25.00 |
| openai · gpt-5.6 sol | $20.00 |
| google · gemini 3.1 pro | $12.00 |
| mistral · medium 3.5 | $7.50 |
| zhipu · glm-5.3 | $4.40 |
| google · gemini 3.8 flash | $3.75 |
| mistral · large 3 | $1.50 |
| openai · gpt-5.6 luna | $1.20 |
| alibaba · qwen3.8-flash | $0.47 −99% |

■ cheapest that still does the job · bars in US$ per 1M output tokens

## All articles

CONSULTORIA · AGO · 2026 · 6 min

### [What AI really costs in 2026: three bands, with the arithmetic shown](https://okamiops.com/insights/quanto-custa-implementar-ia-2026/)

Ten people on ready-made subscriptions cost $317 a month. The API automation that handles 4,000 tickets in that same month costs $90 — $0.02 per ticket, with routing and caching. The expensive band is not the one you expect, and the number that decides the project is not on the vendor invoice.

**Monthly vendor bill per band (USD/month, 10-person company)**

- faixa 1 · 10 assentos padrão: 317
- faixa 1 · 10 assentos premium: 1117
- faixa 3 · IA no produto (tokens + operação): 920
- faixa 2 · mesma carga, modelo de topo: 400

source: Claude · Pricing

APPSEC · ABR · 2026 · 8 min

### [OWASP LLM Top 10 (2025): five risks already in the incident record — and how to cover each](https://okamiops.com/insights/owasp-llm-top-10-2025/)

The 2025 OWASP list for LLM applications was rewritten after two years of real incidents. It does not replace the web Top 10 — it adds to it. For a team of five or ten engineers with an AI feature in production, the question is not knowing all ten items: it is knowing which five to close first, what each costs in engineering days, and what to check before the release.

**OWASP LLM Top 10 · 2025**

- LLM01 · Prompt Injection — high
- LLM02 · Sensitive Information Disclosure — high
- LLM03 · Supply Chain — high
- LLM04 · Data and Model Poisoning — med

source: OWASP Gen AI Security Project · Top 10 for LLM Applications 2025

COMPLIANCE · MAR · 2026 · 7 min

### [The EU AI Act after the Digital Omnibus: the real calendar and a 90-day plan](https://okamiops.com/insights/eu-ai-act-timeline/)

On 2 August 2026 the EU AI Act became generally applicable and enforcement began. The Digital Omnibus, in force since 27 July 2026, pushed the high-risk rules to 2 December 2027 — and left everything else in place. If your company sells into the EU or processes EU residents' data, the comfortable window has already closed.

**EU AI Act applicability**

- AGO · 2026 — General applicability: transparency (Art. 50) and enforcement
- SET · 2026 — Today
- DEZ · 2026 — Marking of legacy synthetic content and new prohibitions
- DEZ · 2027 — Annex III high risk (deferred by the Digital Omnibus)

source: EUR-Lex · Regulation (EU) 2024/1689 (Artificial Intelligence Act)

APPSEC · FEV · 2026 · 8 min

### [SAMM 0→3 in an SMB: 12 months, five practices, and the order that matters](https://okamiops.com/insights/appsec-maturity-smb-2026/)

OWASP SAMM has 90 activities and a 0-to-3 scale per practice. In the official benchmark, dominated by multinationals, the average is 1.44 — and Verification sits at 1.12. The bar for mature is lower than the word suggests. With tight scope and the right order, an SMB reaches level 3 on the critical practices in four quarters.

**SAMM on the critical practices · SMB · month 0 vs month 12**

- secure build · M12: 3
- security testing · M12: 2
- threat assessment · M12: 2
- defect management · M12: 2

source: OWASP SAMM · The Model (v2)

## No loose opinions. Every number has a source, every article ends with what to do.

We write what we learn solving the problem for a client. If your situation looks like one of these, the conversation starts here.
