Two numbers, from two different reports, published two months apart.
Mandiant's M-Trends 2026, drawn from over 500,000 hours of incident investigations in 2025, measured the median time between an initial access event and the hand-off to a secondary threat group. In 2022 that window was more than eight hours. In 2025 it was 22 seconds.
Verizon's 2026 Data Breach Investigations Report, drawn from more than 22,000 confirmed breaches across 145 countries, measured how long organisations take to fully remediate a critical vulnerability in CISA's known-exploited catalogue. The median rose to 43 days, up from 32 the year before. Only 26% of those vulnerabilities were fully remediated at all, down from 38%.
Twenty-two seconds on one side. Forty-three days on the other. That gap is the entire argument for putting machines in the loop, and it is a far better argument than anything a vendor will show you on a slide, because the slower of the two comes from Verizon, which sells no competing endpoint product, and the faster comes from Google's own incident response arm declining to make the claim that would sell more of its products.
Everything below is organised around one principle: AI earns its place where the defender's problem is speed and volume. It does not earn its place where the problem is a decision. I have gone layer by layer, named the products, printed the published prices, and said plainly where no price is published, which turns out to be most of the market.
The cost argument is the weak one, and it is the one you will be shown
IBM's Cost of a Data Breach Report 2026 says the global average breach cost hit a record USD 4.99 million, a 12% rise. It says organisations using AI and automation extensively in security operations saved an average of USD 1.93 million per breach compared with organisations using none. That second figure is the one that ends up in every sales deck.
Read the methodology before you spend against it. That report is a survey of 602 organisations that experienced breaches between March 2025 and February 2026, conducted by Ponemon Institute and sponsored and analysed by IBM. It asks organisations what happened to them. It is not a controlled measurement of an effect size, and IBM sells AI security products on the same page that carries the stat tile. Directional, not decisive.
The sample problem gets worse when writers put these reports side by side, so let me do it deliberately: IBM's $4.99 million average rests on 602 organisations. Verizon's dataset rests on more than 22,000 confirmed breaches out of more than 31,000 incidents. Those are not comparable instruments, and a factor of thirty-plus in sample size does not disappear because both documents are called annual reports.
Two more traps in the same family, because they are everywhere in secondary coverage:
The $6 million collision. IBM's press release says AI-enabled breaches averaged USD 6 million, roughly USD 1 million above the global average. IBM's own analysis separately gives USD 6.07 million as the average loss from a model inversion attack, and USD 5.89 million for prompt injection. Those are two different findings that round to the same headline number, and they get conflated constantly. When I say $6 million in this piece, I mean the AI-enabled breach average.
The shadow AI number you have read is a year old. The heavily quoted "one in five organisations breached via shadow AI, adding as much as USD 670,000 to breach cost" is from IBM's 2025 edition, dated November 2025. Secondary coverage of the 2026 edition reports a much higher figure, but I could not confirm it on any IBM-owned page, so I am not printing it. If you see 20% quoted as current, the person quoting it is a year behind.
One IBM finding I will use without hesitation, because it is uncomfortable rather than flattering: 85% of organisations said they plan to increase security spending after becoming aware of advanced frontier AI cyber capabilities, compared with just 64% who said so after actually experiencing a breach. Fear of a capability moves budgets harder than being robbed does. Keep that in mind while reading the rest of this.
And one that maps directly onto the clock: among breached organisations, 50% had deployed AI agents in threat hunting, response and containment, while only 18% had applied them to vulnerability scanning and management. The 43-day number is precisely the place almost nobody is pointing the automation.
Identity: where the intrusions start, and the cheapest layer to improve
The threat data disagrees about the exact ranking, and the disagreement is more useful than any single figure.
- IBM X-Force put exploitation of public-facing applications at 40% of incidents observed in 2025, up 44% year over year.
- Verizon put exploitation of vulnerabilities at 31% of breaches, with credential abuse falling to 13%.
- Mandiant put exploits at 32% of intrusions, the top vector for the sixth consecutive year.
Three vendors, three numbers, because they count incidents, confirmed breaches and investigation engagements respectively. All three independently put vulnerability exploitation above credentials. That convergence is worth more than any of the individual percentages.
Against that, CrowdStrike reports 82% of its detections were malware-free, with adversaries using valid credentials, trusted identity flows and approved SaaS integrations to move between domains. Note the alignment: that is real telemetry, but it is telemetry from CrowdStrike-monitored endpoints, and CrowdStrike sells identity protection. The metric and the product line move together. It is still a serious finding, and the honest version is that whatever gets an attacker in, identity is how they travel once inside.
X-Force also found infostealer malware exposed over 300,000 ChatGPT credential sets in 2025, which is the single tidiest illustration that AI platforms now carry the same credential risk as any other core business SaaS account.
What the AI actually does here. Behavioural risk scoring on sessions and sign-ins, and continuous re-evaluation after login rather than a single gate at the door. Okta's Identity Threat Protection with Okta AI is the clearest statement of that model: continuous monitoring of user behaviour, device health and contextual signals throughout a session, with Universal Logout as the automated response that terminates sessions across supported apps. I could not find a published price for it.
What is published:
| Product | Published price (observed 21 August 2026) |
|---|---|
| Microsoft Entra ID P1 | $7.00 per user/month, annual commitment |
| Microsoft Entra ID P2 | $10.00 per user/month, annual commitment |
| Microsoft Entra Suite | $12.00 per user/month, annual commitment |
| Microsoft Entra Workload ID | $3.00 per workload identity/month |
| Push Security | $5 per employee/month annual, $6 monthly, self-serve to 500 employees |
| Huntress Managed ITDR | $4.80 per licensed identity/month, 50 to 99 unit band |
| Okta Identity Threat Protection | No published price I could find |
Two things about that table. First, most articles still quote Entra P1 and P2 at $6 and $9. Those are stale. The prices above came off Microsoft's live pricing page on 21 August 2026.
Second, and this is the detail that decides whether you get anything: Entra ID Protection's machine-learning risk detections are gated behind P2. Without a P2 licence you get an event titled "Additional risk detected" with no detail. The named premium detections include Anomalous Token, Atypical travel, Impossible travel, Password spray, Suspicious browser and Suspicious inbox forwarding. If you are buying Entra for the risk detection specifically, P1 does not give it to you.
Endpoint and the SOC: triage, natural language, and the billing unit that surprises people
This is the layer with the most AI marketing and the widest gap between what is claimed and what is metered.
CrowdStrike Charlotte AI Detection Triage makes the strongest autonomy claim on the market: triage of security detections with over 98% accuracy, eliminating more than 40 hours of manual work per week on average, a claim CrowdStrike first published in February 2025. Read CrowdStrike's own footnote, because it changes the meaning entirely. Accuracy is defined as the share of Charlotte AI triage decisions that match the expert decisions of CrowdStrike's Falcon Complete managed detection and response team. That is a measure of how well the model imitates CrowdStrike's analysts. It is not a measure of ground-truth correctness. Both are useful. They are not the same claim.
Charlotte AI is licensed in monthly credits banded on endpoint count, starting at 40 credits per month for 1 to 149 endpoints and running up to 77,500 credits per month at a million or more. A simple prompt consumes up to one credit; multi-step agentic tasks consume 1, 3 or 6. Extra credits sell in packs of 350 and unused credits do not carry over. At the bottom band, a small shop can burn its month in an afternoon of asking questions.
The saving grace is buried in the licensing FAQ and nobody markets it: automatic triage of endpoint detections consumes no customer credits at all. The genuinely autonomous function is free and the chat is metered. That is the opposite of what the pricing page's shape implies.
Microsoft Security Copilot is the consumption model buyers get caught by, so it gets its own paragraph. It is $4 per provisioned Security Compute Unit per hour, and $6 per overage SCU per hour, confirmed both on Microsoft's pricing page and in Azure's retail price feed across every listed region. The flexible option is 50% more expensive than the committed one. Billing is by whole hourly block with a minimum of one hour, not by the minute, so provisioning at 9:05, deprovisioning at 9:35 and provisioning again at 9:45 charges you twice inside the same hour. And the number that matters: one single SCU left running around the clock is 730 hours at $4, roughly $2,920 a month. "Four dollars an hour" sounds like nothing. Two thousand nine hundred and twenty dollars a month does not.
If you already hold Microsoft 365 E5 or E7, eligible customers get 400 SCUs per month for every 1,000 user licences, capped at 10,000 SCUs per month. Security Copilot agents also run inside Defender, Entra, Intune and Purview and draw on the same pool, and Microsoft's own worked example puts one Defender incident summarisation at 0.5 SCU.
Microsoft Sentinel meters data and AI compute separately, and the spread is enormous. Analytics-tier pay-as-you-go ingestion is $4.30 per GB in East US. The data lake tier is $0.05 per GB ingested, $0.026 per GB per month stored and $0.005 per GB analysed by query. Commitment tiers in the same region run from $161.25 per day for the 50 GB promotional tier and $296 per day at 100 GB up to $102,600 per day at 50,000 GB; Microsoft says they save up to 52% against pay-as-you-go and cannot be downgraded for 31 days. The AI and graph compute sits outside all of that: Advanced Data Insights at $0.15 per hour and Sentinel Graph at $3 per hour. Graph left running continuously is roughly $2,190 a month.
Microsoft Defender XDR carries no separate licence fee and is included with several existing SKUs, but automatic attack disruption specifically requires Defender for Endpoint Plan 2. The autonomous bit is the bit behind the higher tier, which is the pattern across this entire layer.
Elastic does something different and worth understanding, because it is not a SKU at all. The Elastic Security AI Assistant requires an Enterprise subscription, or the Complete feature tier on Serverless. On Serverless, moving from Security Analytics Essentials to Complete raises the published ingest rate from as low as $0.09 to as low as $0.11 per GB. You pay a 22% premium on every gigabyte you ingest whether or not a human ever opens the assistant. At 100 GB a day that is about $730 a month extra. Elastic's own documentation tells you to cross-verify the assistant's advice for accuracy, which is more candour than most of this market offers.
The vendors who publish nothing. Google Security Operations sells three packages and all three say contact sales; pricing is ingestion-based with a year of retention included. Gemini in Google SecOps is not an add-on, it is a tier gate: absent from Standard, present from Enterprise upward. Palo Alto publishes no price for Cortex XSIAM at all, while claiming a 98% reduction in mean time to resolve, more than 10,000 detections, more than 2,600 analytics models, 100% MITRE ATT&CK detection coverage and 300% return on investment. XSIAM endpoint licensing is 1:1 per active device, and its "credits" are a cloud-workload quota mechanic rather than an AI meter, which is a genuinely confusing overload of the word. Splunk publishes no price for any security product. SentinelOne's Singularity Enterprise, the only tier that lists an agentic AI SOC analyst for automated triage, is quote-only, and SentinelOne's own page says the prices it does publish are not final because everything goes through an authorised partner whose pricing controls.
That last point deserves generalising, because it is the shape of the whole market and it runs opposite to intuition: the SMB-priced vendors publish real numbers and the enterprise AI-SOC platforms publish nothing. Splunk is the sharpest illustration. On one page it lists Observability from $15 per host per month, AppDynamics from $6 per vCPU per month and On-Call from $5 per user per month, and every single security product says get a quote.
Where the AI is a natural-language front end and nothing more
You asked, implicitly, by reading this far. Here is the honest sorting.
Blumira's "AI-powered SOC Auto-Focus" is described by Blumira as plain-language explanations of complex security findings. That is a summariser sitting on top of detections that already fired. It appears only in the top Automate edition at $21 per employee per month, against $12 for Detect and $16 for Respond. You are paying $9 per employee per month more than the base tier for prose, and the detection engine underneath is unchanged.
Gemini in Google Threat Intelligence is described by Google as distilling Mandiant's existing intel corpus into natural-language summaries. Same corpus, friendlier writing.
Wazuh's AI Analyst is the most honest and the least ambitious: it produces periodic PDF reports, it runs on AWS Bedrock using Anthropic's Claude, and it is Cloud-only. Self-hosted Wazuh gets none of it. It is a reporting layer, not triage.
SentinelOne markets Purple AI directly against this pattern, saying that unlike chat-based assistants that only answer questions, it reasons across normalised security data, advances investigations and documents decisions. Whether that survives contact with your environment is a separate question, but the positioning is deliberate and it tells you the vendors know the criticism.
And Huntress has gone the other way entirely, marketing "go beyond AI in the fight against today's hackers" and putting its 24/7 human SOC forward as the differentiator. An SMB security vendor now selling "not AI" as the feature is a data point about where this market's credibility actually sits.
Email and social engineering: real losses, almost no published prices
The human element was present in 62% of breaches in Verizon's dataset, up from 60%. The channel is moving off the inbox: median successful click rates on mobile-centric vectors such as voice and text are 40% higher than email in phishing simulations, and Mandiant recorded highly interactive voice phishing surging to 11% of intrusions, the second most common initial vector.
Now the deepfake question, handled carefully, because this is where the writing usually gets loose.
What the evidence supports. The Arup case is documented and specific: the firm lost $25 million after an employee was tricked on a video call where the other participants were synthetic. Arup's CIO, speaking afterward, said he built a real-time deepfake video of himself in about 45 minutes using open-source software. That is the whole asymmetry in one sentence: the loss side is eight figures and the attack side is an afternoon.
One conflict to flag rather than smooth over. The same incident appears as $25 million in the Arup and World Economic Forum framing and as HK$200 million in Hong Kong press reporting, paid out across 15 transfers to five accounts. Those are the same money reported in different currencies, not two incidents, and the Hong Kong figures come from local press rather than from Arup. Do not add them together.
What the evidence does not support is that AI is now driving the fraud wave. The FBI's IC3 gave us the first US government dataset sizing this. In 2025 IC3 received 1,008,597 complaints reporting USD 20.877 billion in losses, up 26%. Of those, 22,364 complaints were AI-related, with adjusted losses of USD 893,346,472. That is roughly 2% of complaints and about 4% of losses. Business email compromise cost USD 3,046,598,558 in total, and the AI-involved share of that was just over USD 30 million. AI-nexus investment scam losses passed USD 632 million against more than USD 8 billion in total investment scam losses.
The FBI itself adds the caveat that makes this a floor rather than a share: many victims never realise AI was involved. But a floor of 2% of complaints is a long way from the framing you will see in vendor webinars.
What exists to buy. Abnormal AI's stated mechanism is behavioural baselining over an API-ingested signal set rather than gateway rules, claiming ten times more behavioural signals than legacy tools and deployment in 60 seconds against Microsoft 365 and Google Workspace. Its AWS Marketplace listing publishes nine pricing dimensions, every one of them at exactly $1,000,000.00 per 12 months. That is a private-offer ceiling placeholder, not a price, and the listing tells buyers to request a private offer. If you research this market by reading marketplace pages, you will produce nonsense.
Sublime Security's platform is genuinely open source under an MIT licence, but the free self-hosted Docker deployment is capped at 100 active mailboxes and the project labels it for testing purposes only. Microsoft's Defender for Office 365 Plan 1 and Plan 2 are commonly cited at $2 and $5 per user per month, but Microsoft's own pricing page would not show me those figures and I am not going to state a price I could not read at source; Microsoft's documentation describes the packaging change without a price: Plan 1 is included in Microsoft 365 Business Premium and, effective 1 July 2026, in Office 365 E3 and Microsoft 365 E3. Cloudflare Zero Trust is widely documented as free to 50 users and $7 per user per month above that, and Cloudflare's plans page would not show me those numbers, so treat that one as unconfirmed too.
Deepfake detection has no priced market at all. Reality Defender, the best-known vendor in the category, runs a contact form where its pricing page should be. So: a documented $25 million loss, a 45-minute attack build, and not one published price on the defence side. Your control here is not a product. It is a callback rule, and I will come back to that.
Network detection: the most honest AI claim I found, and the least
Cisco's Encrypted Visibility Engine is the clearest description of a working machine-learning security feature I came across in this whole exercise. It identifies client applications and processes inside TLS and QUIC encrypted traffic by fingerprinting the ClientHello message, without ever decrypting the connection, against a database of over 10,000 known client process fingerprints and 35 billion connections for destination context. And Cisco writes, in its own blog post, that the models are probabilistic by nature and may produce false positives, false negatives or misclassifications. A vendor volunteering the error modes of its own classifier is rare enough to note.
Darktrace is the opposite end. Its own description of what its AI models is "patterns of life" learned per customer in real time rather than signatures, and at the time Thoma Bravo took it private in October 2024 it claimed over 200 patent applications, more than 2,400 employees and nearly 10,000 customers. That take-private was an all-cash deal valuing Darktrace at approximately $5.3 billion, at $7.75 per share, and it is one of the few hard numbers in this entire market. Darktrace publishes no pricing anywhere I could find, and its current product pages did not give me a substantive technical description to quote.
Vectra AI quantifies its estate on its own product page: more than 170 AI models and 36 AI patents behind Attack Signal Intelligence, covering lateral movement, account compromise and command-and-control. No published price. Corelight positions itself as evidence-first and open-core, built on Zeek-style network evidence, and markets explainability as the deliberate contrast to black-box detection. No published price. ExtraHop states figures for RevealX in the range of a million-plus predictive models and thousands of behavioural attributes, but its product pages were not reachable for me during this work, so I am reporting that as unconfirmed vendor marketing rather than as a fact.
Cisco Hypershield deserves a line for the announced-versus-shipping gap. It arrived in 2024 with enormous fanfare as an AI-native distributed security fabric. As of today Cisco's own page says it is available on the N9300 Series Smart Switches. One hardware line.
The free tier here is genuinely good and contains no AI. Suricata is GPL-2.0 licensed and is a mature intrusion detection, prevention and network monitoring engine. Zeek is free, open source and production-ready. Neither ships any AI analysis, and both give you the network evidence that every commercial product in this category is built on top of.
One correction, because CrowdSec regularly gets listed as a free SMB option alongside those two. The agent is free. The commercial data products are not SMB-priced in any normal sense: the Live Exploit Tracker starts at $2,000 a month for SMB and Platinum Blocklists at $1,900 a month for SMB. The only entry point in small-business range is IP Reputation API access from $49 a month for 5,000 queries.
Cloud and workload: where the AI itself gets breached
The most useful cloud finding this year is not about defending cloud with AI. It is about defending the AI you put in the cloud.
More than 20% of organisations in IBM's study reported a breach targeting their own AI models or applications. The most common causes were not exotic: compromised APIs, applications or plug-ins at 27%, and cloud misconfigurations affecting AI workloads at 27%. Of the organisations that suffered an AI-related breach, 92% lacked proper AI access controls. Only 40% of organisations reported using access controls on AI models and data at all.
That is a plumbing problem wearing an AI costume, and it is the single most actionable thing in the IBM report.
Around it: CrowdStrike measured cloud-conscious intrusions rising 37% overall, with a 266% increase from state-nexus actors, and 42% of vulnerabilities exploited before public disclosure. Mandiant's mean time to exploit dropped to an estimated minus seven days, meaning exploitation routinely happens before a patch exists. X-Force found large supply chain and third-party compromises nearly quadrupled since 2020, driven by attacks on trust relationships and CI/CD automation, and Verizon found breaches with third-party involvement up 60% year over year to 48% of all breaches.
Products and prices. Google completed its acquisition of Wiz on 11 March 2026 and is keeping the Wiz brand inside Google Cloud. Note what Google's own completion post does not say: it never states the $32 billion figure that every news outlet attaches to the deal. That number comes from press coverage and law-firm deal announcements, not from Google. Wiz publishes no pricing; its pricing page is a three-step lead-capture form. It does disclose the licensing structure, which is modular and scales with workloads, active developers, log ingestion or sensors, across Wiz Cloud, Wiz Code, Wiz Defend, Wiz Sensor and a Wiz Go Bundle for SMBs.
The AI application layer: newest, most consolidated, and the one nobody covers properly
If you run anything with a model in it, a chatbot, a document assistant, an agent that touches your systems, this is your layer. It is also the layer where the market restructured itself in about eighteen months while most people were arguing about whether prompt injection was real.
The acquisition wave, with what the buyers actually disclosed. This matters because almost none of the circulating dollar figures come from the companies involved.
| Deal | Date | Value in the buyer's own release |
|---|---|---|
| Robust Intelligence to Cisco | 2024 | The 2024 opener; press-reported only |
| Protect AI to Palo Alto Networks | Completed 22 July 2025 | No price disclosed |
| Prompt Security to SentinelOne | Announced 5 August 2025 | Cash and stock, no value disclosed |
| Aim Security to Cato Networks | 3 September 2025 | No value disclosed; Cato's first acquisition |
| CalypsoAI to F5 | September 2025 | Reported at $180 million by trade press |
| Lakera to Check Point | 16 September 2025 | No value disclosed |
| CyberArk to Palo Alto Networks | Completed February 2026 | $45.00 cash plus 2.2005 PANW shares per CyberArk share |
Four of those closed or were announced inside a nine-week window in July to September 2025. Every major platform vendor now owns a prompt-injection and red-teaming capability, and in every case it was bought rather than built. That is the clearest available signal of where large firms think the risk is going, and it is more informative than any of their marketing.
The dollar figures you have read for those deals, roughly $700 million for Protect AI, $250 million for Prompt Security, and the various numbers for Lakera and Aim, are trade-press estimates. Say "reported" when you repeat them. Even Palo Alto's CyberArk completion release gives per-share consideration and never uses the $25 billion headline number, and Google's Wiz post never says $32 billion.
What survived independent: HiddenLayer, Noma, WitnessAI and Zenity, which announced a $125 million raise. Capital is still arriving at this layer even after the consolidation.
What these products actually do, and here the low end is deflationary in a way worth knowing before you buy the high end.
Cloudflare AI Gateway's core features, dashboard analytics, caching and rate limiting, are free on every plan including the free Workers plan, and DLP scanning is free on all plans with two predefined profiles for accounts without a Zero Trust subscription. Its Guardrails feature is not a proprietary classifier: it runs Meta's Llama Guard 3 8B on Workers AI and bills as ordinary token inference, so cost scales with prompt and response length. Log storage is 100,000 logs total across all gateways on Workers Free and 10 million logs per gateway on Workers Paid, and Unified Billing adds a 5% fee on purchased credits while passing provider inference rates through with no markup.
Read that again. At the low end of this market, the "AI guardrail" is an open-weights Meta model with a billing wrapper. NVIDIA's NeMo Guardrails is Apache 2.0 licensed and genuinely open source. Microsoft's Prompt Shields is a single API inside Azure AI Content Safety covering both direct jailbreaks and document-embedded indirect injection, and Azure's own content safety pricing page does not display a figure for it.
Portkey publishes real gateway prices: a Developer tier free forever with 10,000 recorded logs a month and deterministic guardrails, and a Production tier at $49 a month with 100,000 logs and $9 per additional 100,000.
At the high end, Palo Alto's Prisma AIRS spans nine named products: AI Security Platform, AI Gateway, AI Model Security, AI Red Teaming, AI Runtime Security, Agent Security, AI Posture Management, Secure GenAI Tools and Prisma Browser. It is bring-your-own-licence, funded out of the same Software NGFW credit pool as Palo Alto's software firewalls rather than sold per seat, and the AI Runtime API bills in tokens defined as four characters each, metered in billions of tokens per month with a quota that resets monthly. MCP tool calls and agent-to-agent requests convert at the same rate. No dollar price is published.
The only public list-price anchor for AI runtime security in the entire market is federal. GSA's OneGov agreement with Palo Alto gives agencies 60% off government list price on designated bundles including Prisma AIRS Runtime Security, and 35% off CNAPP, locked through 31 January 2028. A 60% discount implies a commercial list price exists. Palo Alto simply will not publish it.
Cisco AI Defense is packaged in three tiers, Validation Essentials, Runtime Essentials and Advantage, differentiated by model and application validation, runtime protection, and supply-chain scanning of models and MCP servers. Cisco publishes the feature matrix and no prices, and its AWS Marketplace listing says outright that pricing is based on your requirements and to request a private offer.
But Cisco did one genuinely useful thing. AI Defense Explorer Edition gives away the same algorithmic red-teaming engine as the enterprise edition at no upfront cost, running a full model or agent assessment in as little as twenty minutes across more than 200 risk subcategories. That is the only free-at-any-scale AI red teaming from a major vendor I found. If you have shipped anything with a model in it, that is a free afternoon well spent.
One incident worth knowing by name, because it is the proof that this layer is not theoretical: Aim Security's research team found EchoLeak, CVE-2025-32711, described in Cato's acquisition release as the first reported CVE for a zero-click AI vulnerability, in Microsoft 365 Copilot. Zero-click means the user did not have to do anything wrong.
And on the attack side, CrowdStrike reported adversaries injecting malicious prompts into legitimate generative AI tools at more than 90 organisations to generate commands for stealing credentials and cryptocurrency. This is not a lab finding.
The frameworks, kept to what you would actually use
Standards bodies have produced a lot of paper here. Most owners need four of these and can ignore the rest.
NIST AI Risk Management Framework 1.0, released 26 January 2023, organised around four functions: Govern, Map, Measure and Manage. Important caveat that most articles skip: NIST states the AI RMF 1.0 is currently being revised as part of the White House AI Action Plan, so it is not settled doctrine. NIST released a concept note for a critical-infrastructure profile on 7 April 2026. Take from it: the four-function shape, and the word Govern first.
NIST AI 600-1, the Generative AI Profile companion, July 2024. It enumerates exactly twelve risks unique to or exacerbated by generative AI, including confabulation, information integrity, data privacy, information security and value chain and component integration. Take from it: the twelve-item list as a checklist for any AI feature you ship.
NIST Cybersecurity Framework 2.0, published 26 February 2024 as NIST CSWP 29. Six core functions, GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER, with GOVERN newly added in version 2.0 to tie security into enterprise risk management. Take from it: CSF 2.0 explicitly went after small organisations with its Quick Start Guides. Those guides are the fastest useful thing on this list for a twelve-person company.
NIST SP 800-53 Revision 5, September 2020, with a minor release 5.2.0 on 27 August 2025 adding controls SA-15(13), SA-24 and SI-02(07). Take from it: almost nothing, unless a customer contract references it.
MITRE ATLAS, the Adversarial Threat Landscape for AI Systems, is the catalogue of how AI systems actually get attacked, structured like ATT&CK. Current release 2026.07, modified 27 May 2026: 16 tactics and 178 techniques, of which 101 are top-level and 77 are sub-techniques, alongside 37 mitigations and 68 real-world case studies. The relationship to ATT&CK is concrete rather than decorative: 14 of the 16 tactics carry an explicit ATT&CK Enterprise tactic reference and 37 individual techniques do too. Only two tactics are AI-native with no ATT&CK equivalent, AI Model Access and AI Attack Staging. Take from it: the 68 case studies. They are the cheapest threat modelling you will ever do.
OWASP, and there are now three current lists that people constantly conflate. The Top 10 for LLM Applications 2025, version 2.0, released 18 November 2024. The Top 10 for Agentic Applications, released 9 December 2025, built from input by over 100 security researchers and practitioners. And the current edition, the Top 10 for LLM Applications 2026, dated 3 August 2026 on OWASP's own resource page, though the PDF cover carries 4 August, so cite the month if you want to be safe.
The 2026 order is: LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Excessive Agency, LLM04 Supply Chain, LLM05 Data and Model Poisoning, LLM06 Unbounded Consumption, LLM07 Misinformation, LLM08 Hidden Context Exposure, LLM09 Vector and Embedding Weaknesses, LLM10 Improper Output Handling. The reshuffle from 2025 is informative on its own: Excessive Agency climbed from sixth to third, Unbounded Consumption from tenth to sixth, Improper Output Handling fell from fifth to tenth, and System Prompt Leakage was broadened and renamed Hidden Context Exposure. The 2026 edition maps its risks to NIST, MITRE ATLAS, CWE and the OWASP Agentic Top 10. Take from it: if you ship one AI feature, read LLM01 and LLM03 and stop there for now.
Government guidance, and the arc is the point. CISA and the UK NCSC published Guidelines for Secure AI System Development on 26 November 2023, co-sealed by 23 organisations. NSA's AI Security Center published Deploying AI Systems Securely with six partners on 15 April 2024. CISA published the AI Cybersecurity Collaboration Playbook on 14 January 2025 and the AI Data Security information sheet with NSA, FBI and international partners on 22 May 2025. Principles for the Secure Integration of AI in Operational Technology followed on 3 December 2025, a 25-page TLP:CLEAR document from nine agencies. Careful Adoption of Agentic AI Services arrived on 1 May 2026, naming expanded attack surface, privilege creep, behavioural misalignment and obscure event records as the core agentic risks. The Five Eyes cyber security agency heads issued a joint statement, "The AI shift in cyber risk: why leaders must act now", on 22 June 2026.
The guidance moved from how to build AI securely, to how to deploy someone else's AI securely, to how to secure the data, to how to adopt agents. That progression tracks what businesses actually did over the same three years.
ISO and SOC 2, with a warning. ISO/IEC 42001:2023, the AI management system standard, was published December 2023 as Edition 1 and ISO sells the document for CHF 225. ISO/IEC 27001:2022 is Edition 3, published October 2022, at CHF 155 plus CHF 44 for its amendment. SOC 2 reports are performed against the AICPA's 2017 Trust Services Criteria with revised points of focus from 2022, covering five categories: security, availability, processing integrity, confidentiality and privacy.
The warning: there is no authoritative published cost for ISO 42001 certification. ISO publishes the price of the document and nothing else. Every estimate in circulation comes from firms selling readiness consulting or audit preparation, and they disagree by roughly an order of magnitude. What is defensible to say is that certification requires Stage 1 and Stage 2 audits by an accredited body plus annual surveillance, and that no independent published pricing exists. For a young standard, that is a fair criticism.
Law, briefly, and mostly to correct two things you have probably read.
The EU AI Act timeline most articles still cite is wrong. The Act entered into force 1 August 2024 and became generally applicable 2 August 2026. But the AI Omnibus simplification regulation, proposed 19 November 2025, agreed 7 May 2026 and in force 27 July 2026, moved the high-risk obligations: Annex III high-risk use cases now apply from 2 December 2027, and high-risk AI embedded in regulated products from 2 August 2028. What did not slip: general applicability, the Article 50 transparency duties on disclosing chatbots and labelling AI-generated content, and the AI Office's enforcement powers, all live from 2 August 2026. A new prohibition on AI generating non-consensual sexually explicit content takes effect December 2026.
Penalty ceilings run to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, EUR 15,000,000 or 3% for most other operator obligations including the transparency duties, and EUR 7,500,000 or 1% for supplying misleading information to authorities. Here is the detail routinely reported backwards: for larger undertakings the fine is the higher of the euro figure or the percentage. For SMEs and start-ups it is the lower.
And Colorado. Almost every article from 2025 says the Colorado AI Act was delayed to June 2026. True and obsolete. SB 24-205 never took effect; it was repealed and reenacted by SB 26-189, signed 14 May 2026, replacing the algorithmic-discrimination duty of care with an automated decision-making technology disclosure regime that begins 1 January 2027. The Attorney General must give 60 days' notice and opportunity to cure before any enforcement action initiated before 1 January 2030, and the law creates no private right of action. For context on the federal weather around that: Executive Order 14365, signed 11 December 2025, directed the Attorney General to stand up an AI Litigation Task Force within 30 days specifically to challenge state AI laws, and directed Commerce to publish an evaluation of onerous state laws within 90 days. Executive Order 14179 of 23 January 2025 had already replaced the previous administration's posture, and the most recent, EO 14409 of 2 June 2026, is security-focused.
Elsewhere: Texas HB 149 took effect 1 January 2026, Illinois Public Act 103-0804 covering AI in employment decisions took effect the same day, New York City's Local Law 144 bias-audit requirement has been enforced since 5 July 2023, and California's SB 53 was chaptered 29 September 2025 as Chapter 138.
Insurance, where the story is exclusions rather than premiums. Verisk's ISO division has put three optional generative-AI exclusion endorsements into circulation for commercial general liability: CG 40 47, CG 40 48 and CG 35 08. W.R. Berkley introduced an absolute AI exclusion for directors and officers, errors and omissions, and fiduciary liability lines, excluding an insured's policies and procedures relating to AI and breach of any duty regarding AI use. An insurance attorney quoted in the same trade coverage makes the point that matters to an owner: traditional liability policies may currently provide silent AI coverage precisely because AI is not explicitly excluded, and that window closes at renewal. The same piece cites a Gallagher study finding a 978% increase in AI-related lawsuits from 2021 to 2025 and 137% from 2024 to 2025; that is trade-press reporting of a broker's study, not a primary dataset.
Carrier claims data is more grounded. Coalition's 2026 Cyber Claims Report, drawn from more than 100,000 global policyholders, found businesses are now twice as likely to experience a cyber incident as they were five years ago, despite record security spending. Dual-extortion ransomware, both exfiltration and encryption, made up 70% of 2025 ransomware claims and cost twice as much as encryption alone, averaging $302,000. Initial ransom demands jumped 47% to more than $1 million, and a record 86% of affected policyholders refused to pay. On fraud: 39% of funds transfer fraud events occurred without any confirmed email compromise, and 20% were driven by fraudulent instructions sent directly to banks, bypassing employees entirely. Coalition recovered $21.8 million in stolen funds for policyholders in 2025, averaging $202,000 per incident.
That "twice as likely despite record spending" line is from an insurer with no product to sell you at the endpoint, and it should temper the entire shopping list above.
The small-business answer: twelve employees, no security staff
Here is the shopping list, published prices only, all observed on 21 August 2026. Everything quote-only has been left off deliberately, because a product you cannot price is a product you cannot compare.
| Layer | Product | Published price |
|---|---|---|
| Endpoint | Microsoft Defender for Business | $3.00 per user/month, paid yearly |
| Endpoint plus office suite | Microsoft 365 Business Premium | $22.00 per user/month yearly ($18.79 without Teams) |
| Endpoint | CrowdStrike Falcon Go | $7.99 per device/month or $59.99 per device/year |
| Endpoint | CrowdStrike Falcon Pro | $14.99/month or $99.99/year per device |
| Endpoint | ThreatDown Core Next-Gen AV | $69 per device/year |
| Endpoint plus EDR | ThreatDown Advanced | $79 per device/year |
| Managed detection | ThreatDown Elite MDR | $99 per device/year |
| Managed detection | Huntress Managed EDR | $8.99 per endpoint/month, 50 to 99 band |
| SIEM | Blumira Detect / Respond / Automate | $12 / $16 / $21 per employee/month |
| Identity | Microsoft Entra ID P1 / P2 | $7.00 / $10.00 per user/month |
| Identity in the browser | Push Security | $5 per employee/month annual |
| Browser | Chrome Enterprise Core / Premium | $0 / $6 per user/month |
| AI gateway | Cloudflare AI Gateway core and DLP | $0 |
| AI gateway | Portkey Developer / Production | $0 (10k logs) / $49 per month (100k logs) |
| AI guardrails | NVIDIA NeMo Guardrails | $0, Apache 2.0 |
| AI red teaming | Cisco AI Defense Explorer Edition | No upfront cost |
| Network monitoring | Suricata, Zeek | $0, open source |
| SIEM, self-hosted | Security Onion, Wazuh | $0 base |
The free tiers on that list are real, not trials. Chrome Enterprise Core at zero, Cloudflare AI Gateway's analytics, caching, rate limiting and DLP scanning at zero, NeMo Guardrails under Apache 2.0, Cisco's Explorer Edition red teaming at no upfront cost, and Suricata and Zeek as production-grade network monitoring. If you did nothing else this quarter but run the Cisco red-team assessment against whatever AI feature you shipped and put Chrome Enterprise Core in place, you would have spent nothing and learned something.
Six things about that table that will save you a phone call.
Defender for Business is the cheapest credible AI-assisted endpoint detection, at $3 per user per month standalone, and it is effectively free at the margin if you are already paying $22 for Business Premium, which bundles it. It covers up to 300 users with up to five devices per user and no minimum device requirement. Microsoft capping the SKU at 300 users is what makes it a genuine small-business product rather than an enterprise product with a friendly label.
Falcon Go is hard-capped at 100 devices, which is fine at twelve people and a wall later.
Charlotte AI does not appear in CrowdStrike's published Go, Pro or Enterprise feature lists. If you buy the SMB tier expecting the AI triage everyone writes about, you are not buying it. It is a separate module.
Huntress has a 50-seat minimum per product when bought through a reseller and no minimum through an MSP. At twelve employees, that means Huntress is an MSP purchase, not a direct one. Worth knowing before you fill in the form.
Wazuh Cloud is not an SMB price. Managed Wazuh starts at $571 a month for up to 100 agents, $923 for up to 250 and $1,467 for up to 500. Self-hosted Wazuh is free and has no AI analysis. Of the open-source options, only Security Onion Pro and Wazuh Cloud ship anything AI-assisted and both put it behind the paid tier. Security Onion's approach is the most interesting for a technical small business: rather than embedding a model, Pro exposes an MCP interface so you point your own model at your own grid, licensed per node with the standard Pro licence covering up to ten. Security Onion publishes no price for Pro.
Blumira prices on headcount, not data volume or endpoints, which is unusual and makes it easy to forecast. Its bundled agent comes one per licence in the Respond and Automate editions, with additional agents at $3 per agent per month. Just be clear-eyed that its only named AI feature is the plain-language explainer gated to the $21 tier.
What the cheap stack does not cover
Be honest about this or you will be surprised at the wrong moment.
- No network detection and response at any published price. Darktrace, Vectra, ExtraHop and Corelight are all quote-only. Your substitute is Suricata or Zeek plus somebody who reads the output, and at twelve people that somebody is you.
- No behavioural email security at a published price. Abnormal is private-offer only, Sublime's free self-hosted deployment caps at 100 mailboxes and is labelled for testing, and I could not verify Microsoft's Defender for Office 365 prices at source.
- No deepfake detection at any price, from anyone, published.
- No AI-application runtime protection from a major platform vendor at a published price. You get gateways and open-source guardrails. Prisma AIRS and Cisco AI Defense are quote-only.
- No 24/7 human eyes unless you buy managed detection, and the managed tiers are where the prices start climbing.
- Nothing on the list patches anything for you. The 43-day median is not a product gap. It is a work gap.
That last point is the one to sit with. Every product above is on the detection and response side of the ledger, which is exactly where the industry has pointed its automation: 50% of breached organisations had AI agents in threat hunting and response, and 18% had them in vulnerability management. The measurable failure is on the side almost nobody automated.
The honest brakes, all of them published by people with every reason not to
Here is the part that should make you slower with your budget. Every organisation with the most to gain from AI-threat panic published a caveat against it. All five are primary.
Mandiant, in M-Trends 2026: they do not consider 2025 to be the year where breaches were the direct result of AI, and from their view on the frontlines the vast majority of successful intrusions still stem from fundamental human and systemic failures. That is Google's incident response arm, in a report built on half a million hours of investigations, declining to claim the thing that would sell more of its products.
Verizon, in the DBIR: the median threat actor researched or used AI assistance across 15 documented techniques, with some using as many as 40 or 50. But less than 2.5% of AI-assisted malware observations involved genuinely uncommon techniques with one or fewer known equivalents. Most AI-built tooling replicates attacks that already existed, with a median of 55 pre-existing malware examples doing the same job. AI is making attackers faster and more numerous. It is not, so far, making them novel.
Google's Threat Intelligence Group, which found the first malware families that query a language model during execution, PROMPTFLUX and PROMPTSTEAL, writes that PROMPTFLUX is in a development or testing phase and in its current state does not demonstrate an ability to compromise a victim network or device. The flagship exhibit in AI malware cannot yet break into anything. PROMPTSTEAL is real and was used by APT28 against Ukraine in June 2025, querying an open model through a public API to generate Windows commands, and that is the first observation of malware querying a model in live operations.
Anthropic, disclosing what it assesses to be the first documented large-scale cyberattack executed without substantial human intervention, in which a state-sponsored group manipulated its coding tool into attempting infiltration of roughly thirty global targets in mid-September 2025 and succeeded in a small number of cases, with the AI performing 80% to 90% of the campaign and humans intervening at perhaps four to six critical decision points. Anthropic then adds the deflating detail: the model occasionally hallucinated credentials or claimed to have extracted secret information that was in fact publicly available, and this remains an obstacle to fully autonomous attacks.
OpenAI, which has disrupted and reported over 40 networks violating its usage policies since it began public threat reporting in February 2024, measured that its own product is used to identify scams up to three times more often than it is used to run them.
Add the sourcing caution I opened with, because it applies to every number in the shopping sections above. Four of the five headline threat reports come from vendors selling the exact remedy their numbers imply. IBM's $1.93 million saving is a sponsored survey of 602 self-reporting organisations, not a measurement. CrowdStrike's 82% malware-free is genuine telemetry from CrowdStrike-monitored endpoints, and CrowdStrike sells identity protection. The independent instruments in this set are Verizon's DBIR, the FBI's IC3 report, the CISA and NSA advisories, and Coalition's claims data.
None of that means the threat is fake. It means the clock argument stands on its own and the cost argument does not.
What I would actually do, in order
Cheapest and highest value first. Stop when you run out of money or patience; the top of this list does most of the work.
- Fix the things on the known-exploited list. Free, unglamorous, and the measured failure. The median full remediation is 43 days and getting worse, only 26% get fully remediated, 42% of vulnerabilities are exploited before public disclosure, and mean time to exploit is now estimated at minus seven days. Nothing you buy compensates for this.
- Write a callback rule for money movement and rehearse it once. Any change of payment details or unexpected urgent transfer gets verified on a number you already had, never a number in the message and never on the call that requested it. Costs nothing. This is the only control that would have caught Arup's $25 million, and Coalition found 39% of funds transfer fraud happening with no confirmed email compromise at all and 20% going straight to the bank.
- Turn on the identity layer properly. Entra ID P1 at $7 per user per month, or P2 at $10 if you want the machine-learning risk detections, because P1 gives you an undetailed "Additional risk detected" and nothing more. Push Security at $5 per employee per month annual is the browser-side alternative and self-serves up to 500 people.
- Put managed endpoint detection on every machine. Defender for Business at $3 per user per month if you are in the Microsoft world, or Business Premium at $22 if you want the bundle. Falcon Go at $59.99 per device per year to 100 devices if you are not. Do not expect Charlotte AI in the SMB tiers, because it is not there.
- Deploy Chrome Enterprise Core at zero and decide later about Premium at $6 per user per month. The browser is now where identity attacks land.
- Write down which AI tools your staff actually use. Verizon found 67% of users accessing AI services from non-corporate accounts on corporate devices, 45% of employees now regular AI users on corporate devices against 15% the year before, and shadow AI as the third most common non-malicious insider action in its data loss dataset, a fourfold increase, with source code the most common data type sent to external models. This step is a spreadsheet and an hour.
- If you ship anything with a model in it, put a gateway in front of it and run one free red-team pass. Cloudflare AI Gateway core and DLP scanning at zero, or Portkey's free Developer tier at 10,000 logs a month, plus Cisco AI Defense Explorer Edition for a twenty-minute assessment across 200-plus risk subcategories at no upfront cost. Then read OWASP LLM01 Prompt Injection and LLM03 Excessive Agency and fix whatever the pass found.
- Put access controls on your AI models and data. Only 40% of organisations have them, and 92% of organisations that suffered an AI-related breach lacked them. The most common causes were compromised APIs, applications or plug-ins at 27% and cloud misconfigurations affecting AI workloads at 27%. This is ordinary plumbing, and it is the highest-yield AI-specific work available.
- Read your liability renewal before you sign it. Three generative-AI exclusion endorsements are in circulation for general liability and at least one carrier has written an absolute AI exclusion for directors and officers, errors and omissions and fiduciary lines. Whatever silent coverage you have today is being written out at renewal.
- Only now consider a paid AI-SOC product, and make them put a number in writing. Understand the meter before you sign: Security Copilot at $4 per provisioned compute unit per hour is roughly $2,920 a month for one unit running continuously, overage units cost $6, Elastic's assistant is an ingest-rate increase you pay on every gigabyte rather than a SKU, Charlotte AI credits do not roll over, and Sentinel's graph compute at $3 an hour is about $2,190 a month left running. If a vendor will not give you a price at all, that is information too.
The pattern across all ten is the same one the clock implies. Machines are good at the twenty-two-second problem. The forty-three-day problem is a decision about how you spend Tuesday, and no product on this page fixes it.
Fact-check notes and sources
- The 22-second hand-off and dwell time: from M-Trends 2026, Google Cloud, 23 March 2026, grounded in over 500,000 hours of Mandiant incident investigations in 2025. Same source for global median dwell time rising to 14 days from 11, 52% internal detection up from 43%, exploits at 32% of intrusions, voice phishing at 11%, mean time to exploit at an estimated minus seven days, and Mandiant's explicit statement that 2025 was not the year breaches resulted directly from AI.
- The 43-day remediation median, 26% remediation rate, and every other Verizon figure: 2026 DBIR Executive Summary (PDF), covering more than 31,000 incidents and more than 22,000 confirmed breaches in 145 countries. Note one internal inconsistency: the executive summary states a data window of October 2024 through November 2025 while Verizon's own report FAQ says 1 November 2024 through 31 October 2025. The FAQ version matches Verizon's standing methodology and is probably the correct one. This is the largest and most independent of the datasets cited here; Verizon does not sell a competing endpoint product.
- CrowdStrike breakout time of 29 minutes, 27-second record, four-minute exfiltration, 82% malware-free, 89% growth in AI-enabled operations, prompt injection at 90-plus organisations, 42% pre-disclosure exploitation, cloud intrusion growth: 2026 CrowdStrike Global Threat Report press release, 24 February 2026 and the findings blog. CrowdStrike describes 29 minutes as a 65% increase in speed rather than a 65% reduction in duration; if you quote it as "65% faster" alongside the minutes, readers will try to reconcile the two and fail. This is vendor telemetry from CrowdStrike-monitored endpoints and CrowdStrike sells the identity products the findings point toward.
- IBM cost figures: Cost of a Data Breach Report 2026 landing page and the 29 July 2026 newsroom release, with the AI-specific analysis at IBM Think. This is a Ponemon Institute study sponsored and analysed by IBM, based on 602 organisations breached between March 2025 and February 2026. It is a survey of self-reported experience, not a controlled measurement, and IBM sells the products the findings recommend. The widely circulated US average of $11.5 million and the 247-day identify-and-contain figure appear only in secondary coverage of the gated PDF, so they are not stated here. The shadow AI figure of 20% and $670,000 is from IBM's 2025 edition, dated 12 November 2025, not the current one.
- X-Force figures: IBM 2026 X-Force Threat Index, 25 February 2026 and the accompanying Think analysis.
- FBI fraud numbers: 2025 IC3 Annual Report (PDF). All IC3 data is victim-reported, and the FBI states plainly that its ransomware loss total excludes lost business, time, wages, files and equipment, which is why the $32 million ransomware figure should never be used as a market size. The AI share arithmetic (22,364 of 1,008,597 complaints, $893 million of $20.877 billion) is mine, from the report's own totals. Note that the FBI's press-release permalink for its annual internet crime report was still serving the prior year's release when I checked, so go to the IC3 PDF directly.
- Anthropic's disrupted campaign: Disrupting the first reported AI-orchestrated cyber espionage campaign, 13 November 2025, including Anthropic's own caveat about hallucinated credentials. OpenAI's threat reporting: the October 2025 report (PDF) for the 40-networks and three-times-more-often figures, and the February 2026 update. PROMPTFLUX and PROMPTSTEAL: Google Threat Intelligence Group, 5 November 2025.
- Microsoft prices: Security Copilot pricing and the capacity documentation for the hourly-block billing rule; Sentinel and Security Copilot meter rates independently confirmed through the Azure Retail Prices API; Defender for Business for the $3 and $22 prices; Defender XDR prerequisites for the attack-disruption licensing requirement; Entra pricing and Entra ID Protection risk detections for the P2 gate. All observed 21 August 2026. The $2,920 and $2,190 monthly figures are straightforward arithmetic on the published hourly rates over a 730-hour month.
- CrowdStrike, SentinelOne, Huntress, Blumira, ThreatDown, Wazuh and CrowdSec prices: CrowdStrike pricing, CrowdStrike licensing FAQ for the Charlotte AI credit bands and the zero-credit detection triage, Charlotte AI Detection Triage announcement for the 98% claim and its definition, SentinelOne packages including SentinelOne's own disclaimer that its published prices are not final, Huntress pricing, Blumira pricing, the ThreatDown store bundle pages, Wazuh Cloud, and CrowdSec pricing. All observed 21 August 2026. Secondary aggregator sites claim real-world contract prices well below several of these list figures; I did not verify any of those and have deliberately not printed them.
- Quote-only vendors: Google Security Operations, Google Threat Intelligence, Cortex XSIAM and its licensing documentation, Splunk pricing, Elastic AI Assistant requirements and Elastic Serverless Security pricing, Coro, Guardz, Todyl, Security Onion Pro, Wiz and Reality Defender. The XSIAM performance claims (98% MTTR reduction, 300% ROI) are Palo Alto's own marketing and are reported as such.
- Network detection claims: Cisco's Encrypted Visibility Engine blog including Cisco's own statement that the classifier is probabilistic; Cisco Hypershield for the single supported switch family; Vectra AI Attack Signal Intelligence; Corelight products; Thoma Bravo's completion release for the $5.3 billion Darktrace valuation, $7.75 per share and the company boilerplate. ExtraHop's model-count figures are not cited as fact here because its product pages were not reachable during this work.
- Acquisitions: Palo Alto and Protect AI, SentinelOne and Prompt Security, Cato and Aim Security including the EchoLeak CVE, Check Point and Lakera, Palo Alto and CyberArk, and Google completing Wiz on 11 March 2026. None of the first four discloses a value in the buyer's own release, and neither Google's Wiz post nor Palo Alto's CyberArk post uses the headline figure the press attaches to it. The $180 million for F5 and CalypsoAI comes from SecurityWeek rather than from F5's own release, which I could not reach. Zenity's $125 million raise is stated on its own site.
- AI application layer pricing: Cloudflare AI Gateway pricing docs, 19 May 2026 including the confirmation that Guardrails runs Llama Guard 3 8B billed as ordinary token inference; Portkey pricing; NeMo Guardrails on GitHub; Azure AI Content Safety Prompt Shields; Prisma AI Runtime Security and its licensing documentation; Cisco AI Defense data sheet and the Explorer Edition announcement; and the GSA OneGov agreement with Palo Alto, 4 December 2025 for the 60% and 35% federal discounts through 31 January 2028.
- Abnormal AI's marketplace listing: AWS Marketplace. The nine dimensions listed at exactly $1,000,000.00 per 12 months are a private-offer ceiling placeholder rather than a price, and the listing itself directs buyers to request a private offer. Sublime Security's platform is MIT licensed with the 100-mailbox cap stated in its own README.
- The Arup deepfake: World Economic Forum, February 2025 for the $25 million loss and the CIO's 45-minute rebuild. The HK$200 million figure reported by South China Morning Post describes the same money in local currency, from Hong Kong press rather than from Arup, and the two figures must not be added.
- Frameworks: NIST AI RMF including NIST's own note that version 1.0 is being revised; NIST AI 600-1 (PDF); NIST CSWP 29, CSF 2.0 (PDF); SP 800-53 Rev. 5; MITRE ATLAS with counts taken from the machine-readable ATLAS-2026.07 data release; OWASP GenAI LLM Top 10 2026 alongside the 2025 edition PDF and the Agentic Applications release. The 2026 LLM list is dated 3 August 2026 on OWASP's resource page while the PDF cover carries 4 August, so I have used the month in the body text.
- Government guidance: CISA and NCSC secure AI development guidelines, Deploying AI Systems Securely, AI Cybersecurity Collaboration Playbook, AI Data Security, Principles for Secure Integration of AI in OT, Careful Adoption of Agentic AI Services and the Five Eyes statement of 22 June 2026.
- Standards and law: ISO/IEC 42001:2023 at CHF 225 and ISO/IEC 27001:2022 at CHF 155; AICPA 2017 Trust Services Criteria; the European Commission's AI Act page, which is the correct source for the post-Omnibus timeline rather than the widely linked implementation timelines still stamped August 2024; Article 99 penalties including the inverted SME rule; EO 14365 and EO 14409; Colorado SB 26-189; Texas HB 149; Illinois PA 103-0804; NYC Local Law 144; and California SB 53. No published cost exists for ISO 42001 certification itself; every figure in circulation comes from firms selling readiness services, and they disagree by roughly an order of magnitude, so none is printed here.
- Insurance: Insurance Journal, 22 July 2026 for the Verisk endorsement forms, the Berkley absolute AI exclusion, the silent-coverage point and the Gallagher lawsuit-growth figures. That is trade press, though the endorsement descriptions came from Verisk directly and its executive is quoted by name; the Gallagher percentages are a broker's study reported second-hand. Coalition's 2026 Cyber Claims Report summary, 5 March 2026 is genuine carrier claims data across more than 100,000 policyholders, though the full report is gated and the public summary carries no control-by-control breakdown.
Related reading
- The three trust boundaries every AI system that acts has to draw: the design work that sits underneath everything in the AI application layer section.
- Prompt injection when the data is the attack: what LLM01 actually looks like in a system you built yourself.
- Never let a model pull the trigger: where to draw the line between machine-speed triage and a decision a person has to make.
- Six fraud reflexes small business owners should have already built: the callback rule and its siblings, in more detail than step two here allows.
- Build the guardrail, not the dashboard: what to put in place before your team starts using AI tools you did not choose.
This post is informational and is not legal, security, insurance or financial advice. Product names and prices are as published on the dates cited and change frequently. No affiliation with any vendor mentioned is implied, and mentions are nominative fair use.