AI This Week: Cheaper AI, New Rules, and a Security Warning
Two things that seemed distant for most small businesses just got closer this week: the cost of serious AI capability dropped dramatically, and the first real compliance deadline under the EU’s AI Act passed. There was also a quieter security finding worth reading if your business uses AI tools that connect to external data sources.
OpenAI Slashed GPT-5.6 Prices by Up to 80% as It Crossed 1 Billion Users
On July 31, Bloomberg reported that OpenAI disclosed it had crossed 1 billion active users and more than 2 million businesses on its platform — and simultaneously announced steep price reductions on two models in its GPT-5.6 family. Per CNBC’s reporting on the announcement, GPT-5.6 Luna dropped 80%, from $1 per million input tokens to $0.20, and from $6 to $1.20 per million output tokens. GPT-5.6 Terra fell 20%, settling at $2 per million input and $12 per million output.
The two million businesses figure is the relevant benchmark for SMBs — that’s enterprise and commercial adoption, not consumer ChatGPT users. OpenAI attributed the price reductions to efficiency work driven internally by GPT-5.6 Sol, which the company says autonomously rewrote and optimized its GPU kernels, reducing end-to-end serving costs by 20% and improving token-generation efficiency by more than 15%. In short: AI is being used to make AI cheaper to run, and the savings are being passed down.
For businesses evaluating API-based AI integrations, the Luna shift is material. Tasks like processing invoices, drafting responses to customer inquiries, or summarizing lengthy documents now cost a fraction of what they did six months ago at this capability level. The economics of building AI into daily operations have materially improved.
What this means for your business: If per-token cost was the reason your team put an API integration on hold, revisit that math. GPT-5.6 Luna at $0.20 per million input tokens changes the break-even significantly for high-volume document and communication workflows. Wholesale distribution and freight and logistics businesses that process large volumes of purchase orders, shipping documents, and customer communications are strong candidates for workflows that are now cost-effective to automate.
EU AI Act Transparency Rules Went Into Force on August 2
On August 2, the European Commission officially began enforcing Article 50 of the EU AI Act — the transparency chapter that had been on the compliance calendar for over a year. Three obligations are now enforceable: AI-powered chatbots must identify themselves as AI when users could reasonably mistake them for a human; AI-generated or AI-edited content must carry a machine-readable disclosure marker; and synthetic media depicting real people must be labeled as artificial.
The good news for American SMBs: the Act’s direct jurisdiction is the EU market, and the heavier high-risk AI requirements — covering things like credit scoring, hiring systems, and critical infrastructure — have been pushed back to December 2027 and August 2028, following amendments the European Parliament approved in June. What took effect August 2 is narrower and more practical. Fines for transparency violations can reach €15 million or 3% of global annual turnover, with penalties scaled proportionally for smaller businesses.
The practical reason to pay attention even if you don’t serve EU customers: the disclosure practices Article 50 mandates are becoming the global baseline. California, Colorado, and Illinois have all enacted AI legislation moving in the same direction, and as we covered last week, California’s companion AI Transparency Act carries its own disclosure requirements. Businesses that build transparent AI practices now spend less time retrofitting compliance later.
What this means for your business: If you’ve added an AI chatbot to your website for lead capture, customer service, or scheduling — make sure it identifies itself as AI. If your marketing team generates property descriptions, project summaries, or client proposals with AI tools — develop a clear internal disclosure policy. This isn’t yet a hard legal requirement for most US-based SMBs, but the expectation is forming and the tools your vendors use are building compliance mechanisms in. Commercial real estate and specialty contractors who have added AI to client-facing workflows in the past 12 months should review how those tools identify themselves and how their content is labeled.
A Security Scan Found Vulnerabilities in 73% of AI Integration Servers
This story got less attention than the pricing announcements this week, but it matters for any business using AI tools that connect to external data.
On August 4, Anaconda announced the acquisition of AI security firm Enkrypt AI — and disclosed what prompted the deal. In the two months leading up to the acquisition, Enkrypt AI had scanned more than 268,000 tools across 25,000 MCP servers and found more than 143,000 vulnerabilities, affecting 73% of those servers. MCP (Model Context Protocol) is the integration standard that allows AI tools — Claude Code, Cursor, connected ChatGPT integrations, and many others — to pull data from external systems: your CRM, your files, your databases. It is the layer that makes AI useful for real business workflows, and it is currently significantly under-secured.
Enkrypt AI’s capabilities, now folded into the Anaconda Platform, include pre-deployment red-teaming across 300+ attack categories, runtime guardrails, and compliance automation aligned to NIST and EU AI Act standards. The acquisition signals that AI security is moving from a theoretical concern to an active engineering priority for the platforms businesses depend on — which is exactly when you would expect underlying risks to start being managed at the infrastructure level rather than remaining each individual business’s problem to solve.
What this means for your business: Most SMBs won’t run their own MCP servers — but many use tools that do. If a vendor’s AI integration connects to your data, ask them directly how their MCP layer is secured and what their vulnerability scanning process looks like. Energy services and construction businesses working with sensitive project, financial, and client data through AI-connected tools should add this to their next vendor security review.
The Takeaway
Three moves, one pattern: AI is getting cheaper, more regulated, and more scrutinized for security — all at once. The cost drop on OpenAI’s API makes the business case for AI integrations easier to build. The EU AI Act enforcement deadline makes the cost of ignoring disclosure practices higher. And Enkrypt AI’s security findings are a reminder that the tools connecting AI to your real business data need the same scrutiny you’d apply to any other vendor with access to sensitive systems.
Houston businesses that address all three — lower-cost integrations, transparent AI use, and secured vendor connections — are building on a foundation that holds up as the environment keeps changing. If you want help thinking through where to start, BlueHill is here.