Inference Wire
Daily BriefInsights
Subscribe

The Daily Brief for working professionals

A five-minute morning read on the AI developments that could reach your work, explained in plain words.

Free forever · Unsubscribe anytime

Inference Wire

Practical AI intelligence for working professionals.

A product by Hexaa

Explore

  • Home
  • Daily Brief
  • Insights

More

  • Search
  • Saved
  • Privacy Policy

© 2026 Inference Wire. All rights reserved.

HomeDailyInsightsSearchSaved
Stories
THE DAILY BRIEF

Software is becoming a usage bill, and most finance teams cannot see it

Legal AI still fabricates cases, free models run cheap cyberattacks, Gemini Notebook adds data analysis, and Google lets shoppers buy inside its AI answers.

July 20, 2026

6stories
·
6minute read
In This Edition
Stories
1

Software pricing is shifting from flat fees to bills that grow with use

The way businesses pay for software is changing. For years it was a fixed price for each user, easy to forecast a year ahead. AI tools are billed differently, by how much work they do, counted in tokens, the small units of text a model reads and writes. The bill now moves with usage, and usage is climbing fast.

Across the companies the finance platform Ramp tracks, average monthly spending on AI tokens has risen 13-fold since January 2025. Among Ramp customers that pay for AI, the median company now puts nearly 15% of its software budget into these tools. A single prompt change or an agent left running can multiply a bill overnight, and Ramp says most finance teams find out only when the invoice arrives.

Forrester surveyed more than 2,600 business and technology leaders and found 82% expect their budgets to rise in 2027, with AI a main reason. Its warning to them was plain: ordinary cost tracking was not built for usage-based AI, and the teams that already manage cloud spending should take the job on next year.

Software used to be a fixed line a finance chief could set and leave alone. It is becoming a variable cost closer to an electricity bill, one that has to be watched and tied to a team or a project. Ramp released a free tracker on July 16, open to non-customers, that pulls spending from OpenAI, Anthropic and Google's Gemini into one view by team and project.


2

Even purpose-built legal AI invents cases, and judges are sanctioning lawyers

In May, a federal judge in Oregon fined two lawyers $110,000, the largest penalty of its kind in the United States, after they filed a brief with 23 invented case citations and eight made-up quotations. That was one entry in a long list: a lawyer and data scientist, Damien Charlotin, now counts more than 1,300 cases worldwide where a court has flagged AI-generated fabrications in a filing.

The reflex is to blame free chatbots. But Stanford researchers tested the tools built specifically for lawyers, sold by LexisNexis and Thomson Reuters and wired into the same case databases the profession has used for decades. Even those gave incorrect or misgrounded answers more than 17% of the time; one did so a third of the time.

The reason a wrong answer is dangerous is the same in any field: the model states a fabricated citation with the same confidence as a real one, and cannot check its own work. A tool built for the job narrows the error. It does not remove it. What draws the sanction is not the use of AI but the failure to verify it, and courts have not accepted a tool's brand as a defense. In one case, a large firm was fined after eight of the nine cases it cited from its own purpose-built system turned out not to exist.


3

Open AI models now match paid ones at a fraction of the cost

In June, the US government ordered Anthropic to restrict two of its newest models to keep them from foreign nationals. Unable to verify in real time who was on which account, Anthropic switched both off for every customer worldwide, three days after launch, and they stayed dark for about three weeks. Any business that had built work around them lost it overnight, by an order from a government it does not answer to.

That is the risk of renting intelligence rather than owning it. And the case for renting the most expensive versions is weakening. Open models, which anyone can download and run on their own computers, have closed most of the quality gap with paid services and cost roughly 50 times less to run than three years ago. On July 16 the Chinese lab Moonshot released Kimi K3, a free-to-download model it says rivals the strongest closed systems.

A business paying top prices out of habit now has a reason to ask what it is paying for. Even the premium sellers are repricing: on July 20 Anthropic pulled Claude Fable 5, its most capable model, out of the $20-a-month Pro plan and restricted it to plans that start at $100, citing strained capacity and cheaper competition from OpenAI and Chinese labs.


4

Google renames NotebookLM to Gemini Notebook and adds data analysis

Google renamed its research tool NotebookLM to Gemini Notebook on July 16 and added a real capability: every notebook now has a secure cloud computer that writes and runs code against the documents a person uploads, with no outside internet access and a citation behind each claim.

Until now the tool read your files and summarized them. Now it can analyze them. Drop in a stack of vendor contracts, a year of sales reports, or a set of survey responses, and it can clean the data, build the tables, test whether a pattern holds, and show the work, the kind of output that used to need an analyst. What it cannot supply is the judgment to know the method was sound; a convincing chart can hide a bad choice about missing data.

The tool already has more than 30 million users and 600,000 organizations. Code analysis is live now for the top-priced AI Ultra and Workspace business tiers, reaches all Pro web users in the coming weeks, and the standalone app stays free to start.


5

Free AI models now run cyberattacks that cost a few dollars

The UK's AI Security Institute published its first public measure of how far freely downloadable AI models trail the best paid ones at running cyberattacks. The answer: four to seven months, down from six to ten a year earlier. Two Chinese open models, GLM-5.2 and DeepSeek V4-Pro, now match closed systems from a few months back, and they run for a small fraction of the price. One full-scale attack simulation that cost about $85 on a leading paid model ran for $1.19 on DeepSeek.

The skill barrier is falling with the price. Safety limits built into open models are easy to strip out, because no one controls who runs a downloaded copy. For any business holding customer records, near-frontier attack ability is now within reach of anyone with a laptop and a few dollars.

The same technology can defend. A firm called Tracebit hid short strings inside decoy files that trip an attacking model's own safety rules and make it refuse to go on. Across 152 test runs against five leading models, planting one string cut the share of attacks that reached full administrator access from 57% to 5%. Against the strongest attacker, Anthropic's Opus 4.8, it fell from 93% to zero.


6

Customers can now buy inside Google's AI answers without visiting a store's site

A shopper who asks Google's AI Mode to recommend a product can now tap a Buy button on the result and finish the purchase without ever reaching the seller's website. Google turned this on for eligible US merchants through what it calls the Universal Commerce Protocol, an open checkout standard it built with Shopify, Walmart, Target, Etsy and Wayfair. The store stays the seller of record, and payment runs through Google Pay.

For any business with something to sell, its own website is no longer the only storefront. Whether a product appears inside these answers depends on the data in its Google Merchant Center listing, the same feed that drives search results. Forrester, in that 2027 report, told marketers to treat visibility inside AI answer engines as a real budget line for next year.

Share This Brief

Previous Editions

Last 90 days

July 16, 2026

AI becomes the top reason US employers cut jobs, and the cuts spread past tech

Non-coders now build the software their businesses run on, ransomware holds at a new higher baseline, and Anthropic sends AI engineers into mid-sized firms.

July 15, 2026

Meta is sued over AI layoff scoring, and entry-level hiring keeps shrinking

OpenAI tells companies to price AI by outcome, Cloudflare narrows the web AI agents can read from September 15, and Apple's new Siri skips the EU.

July 14, 2026

AI writes most of Google's new code, and 200 economists warn the shift is speeding up

Uber spent its 2026 AI budget by April, OpenAI's new agent deleted files it was not told to touch, and blocked data centers are lifting power bills.

July 10, 2026

OpenAI's new agent runs whole jobs on its own, and AI labs move in on consulting work

The EU forces SAP to loosen its 22% maintenance fees, and a single US order shows how fast a government can switch off an AI model.

July 9, 2026

Australia names the office jobs most exposed to AI, and GPT-5.6 opens to the public

ChatGPT's voice can now search and reason mid-conversation, and experienced buyers stop standardizing on one AI vendor as token spending runs 13 times higher than a year ago.

Showing 1 to 5 of 20