AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·Market8 min read

What AI Security Actually Costs in 2026: Pricing, Deployment, and ROI

Not one dedicated AI-security startup publishes pricing. We checked them all on September 5, 2026 — here is every verified public price point that does exist, from $0.10-per-thousand hyperscaler guardrails to HiddenLayer's $5M marketplace unit, plus the four pricing models behind the quote wall and the TCO questions procurement should ask.

S
Sofia Reyes
Head of Compliance
2026-09-02

Not one dedicated AI-security startup publishes pricing. The only public numbers in this market are hyperscaler guardrail APIs (fractions of a cent per screened text unit), dev-tool tiers ($0–$60/month), and cloud-marketplace listings running from $10,000 to $5 million a year.

We checked every vendor we could name on September 5, 2026 — Akto, Pillar Security, Lasso Security, Noma Security, Zenity, Prompt Security, HiddenLayer, Lakera, Cranium, Cisco AI Defense. None of them puts a usable first-party price on its own website. Every one routes you to a demo. That makes "what does AI security cost" a genuinely hard question, and it is exactly why this post exists: below is every verified public price point we found, the four pricing models you will meet behind the quote wall, and the questions that separate a real price from an anchor. Last verified: September 5, 2026.

Who actually publishes AI security pricing?

Three groups: the hyperscalers, whose guardrail APIs are metered like any other cloud service; developer-tool gateways with self-serve tiers; and cloud-marketplace listings, where a handful of quote-only vendors are forced to print a list price. Everything below is first-party and was on a public page on the date shown.

Vendor / productModelPublished numbersSource
AWS Bedrock GuardrailsPer 1,000 text units, per policyContent filters $0.15/1K text units; denied topics $0.15/1K; sensitive-information filters $0.10/1K (regex free); contextual grounding $0.10/1K; Automated Reasoning $0.17/1K per policy; image content filters $0.00075/image; word filters free. A text unit is up to 1,000 characters.AWS Bedrock pricing page, Sept 5, 2026
Azure AI Content SafetyFree tier + pay-per-recordF0: 5,000 text records + 5,000 images free per month. Standard tier: $0.375 per 1K text records and $0.75 per 1K images (East US, via the Azure Retail Prices API — rates vary by region). Commitment tiers exist, e.g. $169/month for 250K image units.Azure pricing page + Retail Prices API, Sept 5, 2026
Google Model ArmorPer million tokensFree to 2M tokens/month standalone, then $0.10 per 1M tokens. Bundled inside a Security Command Center Enterprise subscription: 3B tokens/month included.Google Cloud SCC pricing, Sept 5, 2026
Portkey (gateway + guardrails)Per-logged-request tiersFree: 10K logs/month. Production: $49/month for 100K logs, $9 per extra 100K. Enterprise: custom. Open-source self-hosted gateway, guardrails included: free.portkey.ai/pricing, Sept 5, 2026
Arthur AI (monitoring/evals)Per-use-case tiersFree: up to 4 use cases, unlimited seats. Premium: $60/month, up to 100 use cases. Enterprise: custom. Evals engine is open source.arthur.ai/pricing, Sept 5, 2026
Prompt Security (SentinelOne)AWS Marketplace, per-user dimensionsSix contract dimensions (employees, AI code assistants, homegrown apps, plus self-hosted variants), each listed at $10,000 per 12-month contract. Listing invites private offers.AWS Marketplace listing, Sept 5, 2026
HiddenLayer AISec PlatformAWS Marketplace, per-unit contract$5,000,000 per 12-month contract per unit; one unit is full platform access. Non-refundable, non-cancellable per the listing.AWS Marketplace listing, Sept 5, 2026
Nightfall AIPer-user, per-yearPublishes the structure (two packages, data add-on tiers) but renders the dollar figures client-side. Third-party transaction data from Vendr: median contract $25,000/year across 41 purchases, range $12,000–$73,200.nightfall.ai/pricing + Vendr (third-party), Sept 5, 2026

Notice the spread on the marketplace shelf alone: Prompt Security's $10K dimensions to HiddenLayer's $5M unit is a 500× range, in the same store, for products a buyer might shortlist against each other. That is what a market without published pricing looks like.

What are the four pricing models you'll actually meet?

Every quote we have seen in this market reduces to one of four shapes. Knowing which one you are in tells you what your bill does at 10× scale.

  • Usage-based (per token or text unit). The hyperscaler model. Bedrock Guardrails runs $0.07–$0.17 per 1,000 text units depending on policy; Model Armor is $0.10 per million tokens. Cheap to start, but it scales 1:1 with AI traffic — and policies stack. Run Bedrock content filters, denied topics, and PII filters together and you are at roughly $0.40 per 1K text units before grounding checks. An app pushing a billion characters a month pays about $400/month for that three-policy stack, linearly forever.
  • Per-seat, per-year. Nightfall's stated model, and how Prompt Security's marketplace dimensions scale. Predictable, maps to workforce-AI use cases, and the model behind most mid-market contracts — Vendr's Nightfall median of $25K/year is the best public anchor for what per-seat deals actually close at.
  • Per-logged-request gateway tiers. Portkey's $49/month for 100K logs. The dev-tool on-ramp: self-serve, cancellable, and the only shelf where you can put a credit card down today.
  • Platform fee (annual contract, units not tiers). HiddenLayer's $5M unit is the extreme; most quote-only enterprise platforms live here at undisclosed figures. The marketplace list price is an anchor for a private offer, not a price.

One negative finding worth stating plainly: as of September 5, 2026, no vendor we checked publishes an explicit public per-agent price, even as every roadmap slide says "agentic." If your exposure is agent-shaped, start with our AI agent risk exposure calculator to size the problem before anyone sizes the quote.

How much budget do CISOs actually have for this?

Less than the category's marketing assumes. The IANS Research and Artico Search 2025 Security Budget Benchmark (587 CISOs surveyed in April 2025) found security budget growth slowed to 4% year over year, down from 8% in 2024, and security's share of IT spend fell from 11.9% to 10.9% — the first break in a five-year climb. More than half of CISOs reported flat or shrinking budgets. Gartner's verified figure for worldwide end-user information-security spending is $213 billion for 2025.

The practical read: AI security spend is coming out of reallocation, not new money. That is why the free tiers matter (Azure's 5K records/month, Model Armor's 2M tokens/month, Portkey's 10K logs) and why the mid-market clears around Vendr's $25K/year Nightfall median rather than the marketplace anchors. It is also why the ROI case has to be built, not assumed — vendor calculators bake in their own assumptions (Nightfall's assumes an 85% cut in manual investigation time), so interrogate the defaults. We walk through the honest version of that math in the CISO business case for agentic AI governance.

Why does nobody publish pricing?

Three reasons, none of them flattering.

  • The market is consolidating out from under its own price lists. In roughly two years: CalypsoAI into F5 ($180M cash), Protect AI into Palo Alto's Prisma AIRS, Robust Intelligence into Cisco AI Defense, Aim Security into Cato's SASE fabric, Prompt Security into SentinelOne, Lakera into Check Point — and WhyLabs shut down outright. Every acquisition converts a standalone price into a line inside a platform bundle. What little public pricing existed is being actively erased.
  • Value-based selling needs opacity. When one AWS listing says $10K and another says $5M for overlapping categories, publishing a number costs a vendor every deal where the buyer would have paid more. Quote-only pricing lets the same product cost whatever your incident history suggests you'll pay.
  • The category itself is unsettled. Seats, agents, tokens, requests, GB scanned — vendors have not agreed on what the billable unit even is, and per-agent pricing does not publicly exist yet. Hard to print a price list for a unit you haven't picked.

The result is a standard entry motion of free short proofs-of-value instead of free tiers — Nightfall advertises a 7-day POV, Lasso a free assessment, Zenity an assessment hub. Use them; they are the only free thing on the quote-only shelf. (For what it's worth, we publish ours: AccuroAI runs a 72-hour pilot, and deployment takes under 30 minutes — see workforce AI governance for how that works.)

What should procurement ask before signing?

Derived directly from the verified pricing models above. Take these into every AI-security negotiation:

  • Which unit drives the bill — seat, agent, token, logged request, or GB scanned? What is the contractual definition of that unit?
  • What happens to the price at 10× traffic? Usage-priced guardrails scale linearly; get the curve in writing.
  • Which guardrail policies are billed separately, and do they stack? (On Bedrock, Automated Reasoning is $0.17/1K per policy.)
  • What is already included free in a bundle we own — Security Command Center, Bedrock, Azure AI? Model Armor is free to 2M tokens standalone but includes 3B tokens inside an SCC Enterprise subscription. Bundling changes the effective price by three orders of magnitude.
  • Is the marketplace list price a real price or a private-offer anchor? Ask for the discount range off list; Vendr's Nightfall data shows 15–25% off is common.
  • Who pays inference and infrastructure for self-hosted deployments? Portkey's self-hosted gateway is free as software; the compute and ops are yours either way.
  • What are the renewal escalators, and is the contract cancellable? (HiddenLayer's listing is explicitly non-refundable and non-cancellable.)

For the full evaluation framework beyond price, use our AI-SPM buyer's guide for posture platforms, the workforce AI security buyer's guide for employee-facing tools, and the AI governance platform buyer's guide for the compliance layer. And if a vendor will not tell you what unit they bill on, that is your answer about the relationship to come — AccuroAI covers a 1,400+ application catalog under one model, and we will put the number in the first call: AI agent security has the details.

Frequently asked questions

How much does AI security cost per month?

Public floors: $0 (Azure Content Safety F0, Model Armor under 2M tokens, Portkey free tier) to $49–$60/month for dev-tool tiers. Enterprise platforms are quote-only; the public marketplace anchors run from $10,000 to $5,000,000 per 12-month contract.

What is a typical enterprise AI DLP contract worth?

The best public signal is third-party: Vendr's transaction data for Nightfall shows a median of $25,000/year across 41 purchases, ranging $12,000–$73,200, with 15–25% discounts off list commonly reported. Vendors themselves publish no comparable figures.

Is there a pricing benchmark or survey for AI security tools?

No. As of September 5, 2026 we found no credible survey benchmarking AI-security tool pricing specifically — the IANS/Artico benchmark covers security budgets broadly, and OWASP's GenAI Security Solutions Landscape guides map vendors to risks but contain no pricing. Treat sites claiming such benchmarks with suspicion; the ones we found were unreliable.

Are the cloud guardrail APIs cheaper than a dedicated platform?

At low volume, dramatically — fractions of a cent per screened unit. But usage pricing scales linearly with traffic and multiplies per policy enabled, and the APIs cover model I/O filtering only, not discovery, posture, or governance. Compare at your projected 12-month volume, not your pilot volume.

Why did my shortlisted vendor's pricing page disappear?

Probably an acquisition. CalypsoAI, Protect AI, Robust Intelligence, Aim Security, Prompt Security, and Lakera were all absorbed into larger platforms between 2024 and 2026, and standalone pricing typically vanishes into the acquirer's bundle at the first renewal.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security