Simon Willison, in his September sponsor newsletter, summarizes this month's LLM (large language model) industry with two jarring keywords: "price war" and "vulnapocalypse" (vulnerability apocalypse). Our judgment: the former is a short-term positive; the latter is far more concerning.
What this is
Simon Willison is a UK-based independent developer who has tracked the AI industry long-term; his monthly sponsor newsletter is treated as high-quality independent commentary in the English-language AI world. This issue's table of contents covers: the rise of Fable small models (small-parameter but high-capability models), price wars, 3D graphics generation, LLMs entering mathematics, a surge in unexpectedly triggered cyberattacks, and "vulnapocalypse" — the explosion of security vulnerabilities in LLM-related tools.
Because it is a paid newsletter, full content requires a subscription. But the table of contents alone reveals the two defining features of the September 2026 LLM industry: on one side, things are getting cheaper; on the other, things are getting less secure.
Industry view
On the "price war": most vendors and investors view it as positive — falling API costs enable more AI applications. The dissent: price wars typically come at the expense of R&D investment and stability, and they squeeze the survival space for small-model companies. The rise of Fable small models is itself a product of this price compression.
On the "vulnapocalypse": this is the first time Willison has used such severe language to describe a security risk; even his own tool Datasette was not spared. Optimists argue that "every new technology has a shakedown period"; pessimists counter that a large number of enterprises are plugging insufficiently tested AI tools into production systems — and when things go wrong, the cost far exceeds the few dollars saved on subscriptions.
We lean toward the latter: the total cost of ownership (TCO) of AI tools needs to be recalculated. A cheap subscription price does not equal a cheap total cost of ownership.
Impact on regular people
For enterprise IT: selecting AI services cannot be based on price alone; you must ask explicitly about security audit and vulnerability response capabilities.
For working professionals: when using AI tools to handle sensitive data, risk is notably higher than six months ago — don't throw everything at the AI.
For the consumer market: AI applications will get cheaper over the next few months, but some low-priced or free products may be using your inputs to train the next generation of models.