Quick Hits — September 1, 2026

Share
Quick Hits — September 1, 2026

Six things worth knowing from Tuesday's quieter corner of AI: a security vendor claiming frontier models of its own, a cheaper way to make Gemini watch video, and a token price index that keeps sliding.

CrowdStrike opened a Cyber Superintelligence Lab and shipped SafeMind, its own security models built with Nvidia. Announced at Fal.Con 2026, SafeMind pairs Nvidia's open Nemotron models with CrowdStrike's Falcon telemetry — an offensive model that finds an attack path and a defensive model that closes it, running in the same loop — and ships alongside more than 50 task-specific agents, a Charlotte AI AgentWorks toolkit for customers who want to build their own, and a new endpoint product called Falcon Guardian. CrowdStrike's own figures claim investigations run up to five times faster and triage accuracy improves more than threefold, and an accompanying Nvidia technical write-up found its tuned open-model pipeline produced the only detections that passed a full "gold" review. Take: the interesting claim isn't the lab's name, it's that a security vendor now argues its telemetry — not model size — is the moat.


Google DeepMind gave Gemini an agentic mode for video that cuts token use by up to 88%. Available from today on Gemini 3.7 Flash, 3.6 Flash and 3.5 Flash-Lite, the feature lets the model scan through a video and decide which segments actually matter instead of processing it end to end, which Google says also lowers cost by up to 66% and lifts accuracy by up to 7%. The gains are biggest on long recordings — how-to guides, lectures, multi-hour uploads — where the old choice was between an expensive full pass and cheap sampling that loses detail. Take: video is the last major input where cost, not capability, has been the blocker, and this is the first credible move on that number.


The going rate for a million LLM tokens hit 97 cents, an all-time low for Silicon Data's index. The LLM Token Expenditure Index fell to 97 cents on Monday, less than half its late-May high of $2.07, with CNBC attributing the slide partly to cheap open-weight Chinese models like Moonshot's Kimi K3 and to price cuts from the frontier labs themselves. Cheap tokens are good news for anyone building on an API and awkward for the labs: Syz Group's Charles-Henry Monchau argues that token deflation compresses revenue while compute commitments stay fixed, pushing the moat toward distribution, memory and context rather than raw model quality. Take: both OpenAI and Anthropic have IPO paperwork on file — investors will be reading this chart.


Empirik spun out of Sequoia with $21 million to stop outages before they start. The startup sells what it calls an autonomous infrastructure engineer: it watches system changes and reasons about their downstream effects so reliability teams can offload routine troubleshooting, and it already counts S&P Global and Guardant Health among its customers from startups to the Fortune 500. The pitch, per co-founder Kartik Chandrayana, is Cursor-for-infrastructure — and Sequoia's Bogomil Balkansky argues Empirik complements rather than replaces AI SRE platforms like Resolve and Traversal. Take: AI wrote the code faster than the ops layer could absorb it, and that gap is now a funding category.


OpenAI's enterprise data says the gap between heavy AI users and everyone else is widening fast. Its latest Enterprise Signals numbers put frontier firms — the top 10% by usage — at 8.3 times as many output tokens per active user as typical firms, up from 2.6 times in January, and the accompanying write-up argues the difference is structural: leaders connect agents to company context and tools and delegate whole workflows rather than one-off questions. The post walks through three customer patterns, including a sales team that gives every account a persistent subagent and saves about an hour of nightly inbox triage. Take: the metric that matters has quietly shifted from "are people using it" to "how much work are they handing over."


A security executive says frontier models are surfacing vulnerabilities that sat hidden for decades. "All these dormant vulnerabilities are becoming visible at scale," said CrowdStrike's Vishal Salvi, describing an unusual problem: the same capability that helps defenders find old bugs hands attackers the same leverage. His prescription is unglamorous — simplify the tool stack, because more tools mean more risk, and apply the policy discipline companies already use for humans to non-human identities: "if you don't, then they will go berserk." Take: the AI security conversation is moving from model jailbreaks to the boring, expensive work of inventory and identity.

Sources: CrowdStrike · Nvidia Technical Blog · Google DeepMind · Google AI Studio docs · CNBC · Silicon Data · TechCrunch · OpenAI · SiliconANGLE