For Startups Facing the AI Safety Uproar, Cybersecurity Looms Larger than Existential Risk
1. Key Themes
AI Safety Anxiety Is Being Reframed (and Monetized) as a Cybersecurity Opportunity
The article's central argument is that the abstract, existential fears around AI are less useful to operators than the concrete reality that frontier models are powerful cybersecurity tools — and the labs know it.
- "Whatever your level of p(doom), though, for anyone not directly involved in frontier model development or high-level policy, there's a simple way to think about all this: it's a cybersecurity problem."
- "Cyber-defense is thus set to become a major line of business for OpenAI and Anthropic. It's coming at a crucial moment for the model providers, which need to sustain vertiginous revenue growth ahead of their IPOs but are starting to see signs that established categories like coding may not be enough."
- "However you might feel about buying solutions from the people who caused the problem, you might not have much choice."
AI Spending Growth May Be Plateauing as Token Costs Fall
Signs are emerging that the blank-check era of AI spend is giving way to cost discipline, even among heavy users.
- "But at least some of its biggest customers have grown more cost-conscious in recent months, new data from Ramp shows."
- "Ramp's latest AI Index Report shows some signals that the extraordinary growth of AI spending may be starting to ease, though Ramp research head Ara Kharazian is cautious about drawing broad conclusions."
- On Uber specifically: "while its agent usage continued to go up, its cost per 1,000 model requests is down almost 34% from its peak. Essentially, usage was up significantly and spending was still increasing but spending growth has slowed."
Infrastructure Consolidation: Big Players Are Buying, Not Building
A shift in M&A appetite suggests infrastructure startups serving the AI agent stack are becoming acquisition targets rather than being out-built by incumbents.
- "Inference providers are looking for more ways to build out their tools to help run AI agents, a new deal shows."
- "Some investors we've spoken with in the past have hesitated to back many of these kinds of startups, expecting that the companies that needed the technology would build it themselves. But this deal shows at least one well-capitalized startup would rather go shopping."
- "For Blaxel, it's a strong markup — the startup had only raised $7.3 million in seed funding last December... we heard the deal total was roughly $300 million."
European AI Champions Face an Identity Crisis
Mistral's pivot illustrates the difficulty of competing at the frontier without hyperscaler-level capital, forcing a shift toward a services/deployment model that risks commoditization.
- "Mistral's recent moves suggest that it is giving up on being 'Europe's answer to OpenAI' and pivoting to institutional deployments."
- "The ambition has morphed from competing with OpenAI to competing with the Chinese models to implement models as European Palantir. The danger, however, is that you end up as that other French services company, Capgemini."
- "Mistral's 'frontier-class' model, Medium 3.5, is the world's 31st most powerful open-weight model per the capabilities index run by research firm Epoch AI, although it remains first among European firms."
2. Contrarian Perspectives
Cyber-defense revenue may be a temporary bump, not a durable business line. The article floats the idea that AI-driven cybersecurity demand could be a one-time cleanup wave rather than a sustainable growth category, cutting against the labs' bullish framing.
- "Another founder said that many of the vulnerabilities he's seen these tools patching up come from older systems. That raises the possibility that we could see a spike in AI cyber-defense spending as people work to clean up their legacy (human-coded) infrastructure, but once those vulnerabilities are discovered and updated the need for these tools would decline."
Mistral's "European Palantir" pivot could be a demotion, not a strategy. Rather than accepting the narrative that Mistral is cleverly following the Palantir forward-deployed-engineer playbook, the piece surfaces a more skeptical read that it's actually becoming a commoditized IT services shop.
- "one critic cited in Le Monde instead compared them to Capgemini, the far less glamorous IT solutions company."
- "This comparison is apt if customers prefer to use open-source models other than Mistral's while still relying on the firm for AI services."
Individual AI-doom whistleblower narratives are overweighted in the discourse. The author pushes back on the amount of attention given to alarmist safety voices relative to their actual standing/expertise.
- "The fears of an individual young researcher who worked at Anthropic for less than two months have gotten far more airtime than they deserve."
3. Companies Identified
- OpenAI — Frontier AI lab. Mentioned as pivoting toward cybersecurity as a growth line ahead of its IPO. "OpenAI has crossed $40 billion in annual run rate"; held "a separate cybersecurity session led by president Greg Brockman detailing the cyber capabilities of the new model."
- Anthropic — Frontier AI lab. Cited for its threat intelligence report on misuse of Claude and surging revenue. "Anthropic reportedly has crossed $65 billion"; published a "threat intelligence report... detailing bad actors' efforts to use Claude in nefarious ways."
- Modal — AI infrastructure company. Case study for using AI models internally to replace security consultants. "We've been running those models internally; they're very good at finding things," said co-founder Erik Bernhardsson.
- Town — AI assistant startup. Example of AI making continuous security monitoring newly cost-effective. "Before it wasn't worth it — now it is," said co-founder Jean-Denis Greze.
- Uber — Case study in AI cost discipline. "Earlier this year the company revealed that it had blown through its entire AI budget several months into the year"; later showed "cost per 1,000 model requests is down almost 34% from its peak."
- Mistral — French frontier AI lab. Central case study on strategic pivoting and European AI ambition. Raised "a €3 billion Series D at a €21 billion post-money valuation" but faces doubts it can avoid becoming "that other French services company, Capgemini."
- Baseten — Inference provider. Highlighted for aggressive infrastructure M&A. "Baseten announced that it had acquired the startup Blaxel... It's the second acquisition for the inference provider in the last year."
- Blaxel — AI agent sandbox startup, acquired by Baseten. Notable for its valuation markup: "the startup had only raised $7.3 million in seed funding last December... we heard the deal total was roughly $300 million."
- Moonshot AI — Referenced via its model Kimi K3 as a reminder that lab reputations are fragile. "labs are only as good or bad as their last model," referencing "the shock success of Moonshot AI's Kimi K3 in July."
- Nvidia — Mentioned for CEO's comments on cybersecurity as a growth category and its Groq acquihire drawing DOJ scrutiny. Jensen Huang "touted it as the next big AI thing."
- Cognition — Coding assistant startup mentioned in weekly roundup as raising large capital ("rakes in billions").
- Meta — Mentioned for launching "Instinct-competitor Muse."
- Ramp — Fintech providing AI spending data cited as evidence of softening growth trends.
4. People Identified
- Erik Bernhardsson — Co-founder of Modal. Cited as a firsthand source on using frontier models for internal security work. "Where there's a vulnerability in a system you can now hack something in a few hours... We've been running those models internally; they're very good at finding things."
- Jean-Denis Greze — Co-founder of Town. Cited on the changing economics of security monitoring. "Before it wasn't worth it — now it is."
- Sam Altman — CEO of OpenAI. Noted as actively promoting the company's cybersecurity capabilities. "Sam Altman is out selling it."
- Greg Brockman — President of OpenAI. Led a dedicated session on the cyber capabilities of OpenAI's new model.
- Jensen Huang — CEO of Nvidia. Publicly framed cybersecurity as a major AI growth category "at a Goldman Sachs conference in San Francisco."
- Arthur Mensch — CEO of Mistral. Described as "well-respected in the industry," used to temper skepticism about Mistral's strategy.
- Audrey Herblin-Stoop — Mistral's Global Affairs SVP. Explained the rationale for the new raise to Le Monde, framing it as funding compute buildout and customer-hosting capability.
- Zavain Dar — Founder of Dimension. Featured in the Newcomer podcast discussing what Silicon Valley can learn from Chinese AI companies.
- Ara Kharazian — Ramp's research head. Provided cautious framing on the spending data. "Ramp research head Ara Kharazian is cautious about drawing broad conclusions."
- Emmanuel Macron / Marine Le Pen — Referenced regarding political risk to Mistral's status as a national champion given Macron's potential 2027 replacement by "the Eurosceptic Marine Le Pen."
5. Operating Insights
- Use frontier models to replace expensive security consultants now, while enterprise adoption is still catching up. Founders at Modal and Town are already substituting AI models for costly external security work, suggesting an underused, immediately actionable lever for cost-conscious startups: "Before it wasn't worth it — now it is."
- Watch unit economics, not just usage, when evaluating AI spend. Uber's experience — rising usage but falling per-request costs — is a model for how operators should frame AI budget conversations to boards/investors rather than reacting to headline spend increases.
- Infrastructure startups solving narrow agent-tooling problems (sandboxing, post-training, etc.) may be better positioned as acquisition targets than as standalone platform bets — Baseten's back-to-back acquisitions (Parsed, then Blaxel at a reported ~$300M markup on a $7.3M seed) show well-capitalized inference providers would rather buy than build, a potential exit path worth designing toward.
6. Overlooked Insights
- Legacy infrastructure cleanup could be a temporary, not durable, demand driver for AI cybersecurity tools — an important nuance for anyone modeling out the cyber-AI market size, since the piece suggests current vulnerability-patching demand may be a one-time surge tied to outdated (human-coded) systems rather than a recurring revenue stream.
- The DOJ is reportedly scrutinizing Nvidia's acquihire of Groq, a regulatory signal buried in the roundup that could presage tighter antitrust treatment of AI talent/IP acquisitions generally — a risk factor for other large labs pursuing similar acquihire strategies.