My earlier argument was that the cost of agentic AI does not stop at the model.
A secure AI outcome also requires identity, access controls, monitoring, logging, isolation, testing, incident response, and human oversight.
That surrounding control layer is becoming a distinct and permanent part of AI operating cost.
OpenAI and Anthropic are now investing directly in it.
OpenAI has committed $1 billion in subsidized access to Daybreak for frontline cyber defenders. Anthropic has moved in parallel through Project Glasswing, Claude Security, and restricted access to its Mythos cyber models.
Anthropic committed $100 million in model-usage credits to Project Glasswing. It also donated $4 million to open-source foundations to help maintainers respond to the vulnerabilities these models uncover.
These are not conventional cash-grant programs.
Approved organizations receive some combination of free or discounted model access, usage credits, training, technical assistance, security tools, and partner services. OpenAI intends its Daybreak commitment to be consumed over six months. Anthropic has already published post-preview pricing for Mythos access.
That distinction matters.
A water utility, local government, community bank, enterprise security team, or open-source project may gain access to powerful AI capabilities without paying the full initial technology cost.
But subsidized AI is not a subsidized outcome.
The organization must still define an authorized use case, integrate the tools, restrict access, validate findings, review proposed patches, monitor activity, preserve audit evidence, manage production changes, train staff, and investigate false positives.
Finding a vulnerability is not the same as fixing it.
A secure outcome exists only when the finding is validated, prioritized, remediated, deployed, and verified without creating another operational failure.
Both vendors' access models reflect this burden.
OpenAI divides Daybreak into Blue for common defensive work and Red for more sensitive activities requiring stronger verification, monitoring, and human oversight.
Anthropic provides broader vulnerability-scanning capabilities through Claude Security while keeping its most capable Mythos models behind vetted-access programs and additional safeguards.
The more consequential the capability, the more expensive the surrounding control system becomes.
Palo Alto Networks CEO Nikesh Arora described the scale of the shift in a September 1 CNBC interview:
"You're going to see $5 trillion of capex spend in the next five years with people building AI data centers and having tons and tons of agents running around."
"You also have to build a net new security stack for that."
The implication is straightforward.
Organizations cannot simply attach traditional cybersecurity controls to a large population of autonomous AI agents and assume the existing cost model will hold.
A new security layer means a new operating-cost layer.
In Why AI Security Is Becoming a New FinOps Cost Layer, I proposed measuring:
Cost per secure successful outcome
= (AI service costs + allocated security-control costs)
÷ Validated secure outcomes
Subsidies can temporarily reduce the AI-service portion of the numerator.
They do not eliminate integration, governance, monitoring, remediation, or human-review costs. They also do not guarantee validated outcomes.
There is an ordinary explanation for these programs. Better tools can help under-resourced defenders find and fix vulnerabilities sooner.
There is also a strategic one. Subsidies introduce organizations to the provider's models, access controls, partner network, and operating environment. If the tools become embedded in security workflows, the provider is well positioned to sell the service that follows.
The two explanations can both be true. The current evidence supports a genuine defensive investment and the early formation of a commercial control layer.
The credits will eventually expire. The security layer will remain.
For FinOps practitioners, the important signal is not only that model providers are funding cyber defense today. It is that they are building the products, access systems, partner networks, and pricing structures through which this control layer may be delivered commercially tomorrow.
Our job is to make that cost visible before it lands in the budget — not after.
References
- Daybreak for Frontline Defenders: $1B to protect essential services — OpenAI
- OpenAI Daybreak: Trusted Access for Cyber overview — OpenAI
- Project Glasswing — Anthropic
- Expanding Project Glasswing — Anthropic
- Claude Mythos availability, pricing, and safeguards — Anthropic
- Palo Alto Networks fiscal fourth-quarter and fiscal-year 2026 results
