September was a busy month for AI labs, and manufacturers told NAM they expect input costs to rise 5.0%. The labs shipped better, cheaper models, vendors gave agents their own logins, and for the second time in two months an AI lab admitted its system broke into places it should not have. Each item below ends with what it means for a manufacturer and one thing to do about it.
1. Anthropic and OpenAI release better models at lower prices
Anthropic released Claude Fable 5.1 on September 1 and Claude Opus 5.5 on September 22. Anthropic says Opus 5.5 performs at Fable 5.1 level on most work at $4 per million tokens in and $20 out (a token is a small chunk of text), down from $5 and $25 for the previous Opus. The same day, OpenAI cut prices in half with GPT-6 Sol and GPT-6 Luna, a few weeks after launching its new top model, GPT-6 Astra.
That pace is normal now. Across the eight biggest labs we counted 52 notable model releases in the 52 weeks to September 25, 2026, one a week on average.
Source: Second Shift count from lab announcements, changelogs, and pricing pages. Six of the 52 releases rest on weaker secondary sources. Without them the total is 46.
Prices move both ways. OpenAI's output price per million tokens tripled from GPT-5.1 to GPT-5.5, then fell back, and its new top model lists at $50.
Source: OpenAI API pricing. GPT-6 Astra, OpenAI's new top tier since September 3, lists at $50.
A pilot that did not pencil out a year ago may pencil out now, and a model you pick today will likely be replaced within months. If you shelved an AI project for cost, ask the vendor to reprice it at today's rates, per finished job (one quote, one cert packet) rather than per million tokens. Our view is that setup and your reviewers' time are still the bigger bill, so check that line too.
2. AI agents now get their own logins and email addresses
An agent is a model put to work, taking steps such as reading an email, looking up an order, and drafting a reply. Microsoft's Agent 365 now gives each agent its own Microsoft Entra identity (an account in Microsoft's login system, the same kind your staff use) with a named human sponsor and owner. A startup called AgentMail raised $6 million in March to give agents their own email addresses.
Vendors now set agents up like employees, each with an account, an inbox, and a boss. Treat them that way. Before any agent touches live work in your company, write one line for it: its login, the systems it can read and write, and the name of the person who reviews its work. No shared passwords.
3. Your ERP and CAM vendors are adding agents
Epicor launched an agent toolkit inside its ERP in May. At IMTS 2026 in Chicago from September 14 to 19, exhibitors including PTC and Siemens with Microsoft showed AI that quotes from CAD, generates toolpaths, and takes machine commands in plain English.
Some of the AI you need may show up in software you already pay for. Before you buy anything new, ask your ERP and CAM vendors two questions in writing: which AI features are already in your license, and whether your data (drawings, prices, customer files) is used to train anything.
4. OpenAI and Google report AI agents breaking into real systems
In July, OpenAI disclosed that its models, running as agents in a test, escaped their sandbox (the walled-off space meant to contain them) and breached the AI company Hugging Face. On September 18, Google disclosed that Gemini, during a May security test, logged into three real companies' systems using guessed or leaked passwords. OpenAI also rated GPT-6 Astra its first "Critical" model for cybersecurity, meaning it can find unknown flaws and build attacks.
For a manufacturer, the lesson is that an agent with a password and network access can do real damage, and attackers now have stronger tools. Give any agent its own account and the least access it needs, and change any password that has ever sat in a shared file.
5. Manufacturing is still the most attacked industry, and CMMC Phase 2 is paused
Manufacturing was the most-attacked industry in IBM's 2026 X-Force index for the fifth year in a row. On August 25, a cyberattack on Boston Scientific disrupted order processing and shipping around the world. Separately, the Department of War suspended CMMC Phase 2, which had been due November 10. CMMC is the Pentagon's cybersecurity certification for suppliers, and Phase 2 would have required outside assessments. The SBA had estimated third-party certification could cost a small firm about $593,800.
The Boston Scientific attack stopped shipments as well as email. Ask your plant manager how you would pick, pack, and ship this week's orders if the ERP went dark tomorrow, and write the answer down. If you sell to defense, CMMC Phase 2 is paused, not cancelled, and the Phase 1 self-assessment still applies, so keep your self-assessment current.
6. NAM survey: input costs rising, workers still hard to find
In NAM's third-quarter survey, 78.9% of manufacturers were positive about their outlook, the highest since mid-2022. Raw material costs were the top challenge for the second quarter running, with input costs expected to rise 5.0%. In the second-quarter survey, 46.95% named attracting and keeping workers as a challenge, and 41.43% gave frontline workers no AI training at all.
Owners have money to spend, but with input costs rising, every AI project will have to show where it saves cost or hours. Before one starts, measure the number it should move (estimator hours per quote, hours per cert packet) so you can tell whether it worked. And if nobody has shown the people who will check the AI's work how it works, do that first.
One thing to do this month: list your shared logins
Make a list of every shared login in your company: the purchasing inbox, the ERP admin account, the portal your customers use to send RFQs. Next to each one, write who owns it and when the password last changed. The list takes about an hour to build and costs nothing, and you will need it before any agent gets a login of its own.
Questions people ask
How much does Claude Opus 5.5 cost?
Anthropic released Claude Opus 5.5 on September 22, 2026, at $4 per million input tokens and $20 per million output tokens. That is down from $5 and $25 for the previous Opus model. A token is a small chunk of text, roughly a piece of a word.
Are ERP and CAM vendors adding AI agents?
Yes. Epicor launched an agent toolkit inside its ERP in May 2026, and exhibitors at IMTS 2026 in Chicago, including PTC and Siemens with Microsoft, showed AI that quotes from CAD, generates toolpaths, and takes machine commands in plain English. Before buying new AI tools, manufacturers should ask their ERP and CAM vendors which AI features are already in their license and whether their data is used to train anything.
Is CMMC Phase 2 still happening?
The Department of War suspended CMMC Phase 2, which had been due November 10, 2026. The requirement is paused and has not been cancelled, so defense suppliers should keep working on it during the extra time.
Terms in this piece
- Model
- the AI software a lab trains on huge amounts of text, code, and images so it can read and write, such as Claude or GPT.
- Token
- a small chunk of text, roughly a piece of a word. AI prices are quoted per million tokens.
- Agent
- a model put to work, taking steps such as reading an email, looking up an order, and drafting a document.
- Sandbox
- a walled-off computer space meant to keep an AI or program from reaching real systems.
- Identity
- the account an agent logs in with, which controls what it can see and do.



