The Fastest Runner Hits the Brakes First: The AI Safety Business Finally Finds Its Payers

09/16 2026 573

On September 12, Dario Amodei, founder of Anthropic, issued a lengthy article titled . The man holding the world's top models publicly advocated for the industry to slow down the pace of model capability iteration in exchange for one to two years to deploy safety safeguards. His reasoning is specific enough: starting in the summer of 2026, AI's ability to assist in building the next generation of AI will evolve rapidly. Without restraint, the speed of technological breakthroughs will completely outpace human understanding and control.

Dario's proposed plan unfolds in three steps: invite independent third parties to reside within companies, granting them access rights equal to core risk control; have the entire industry jointly define capability red lines and establish mandatory safety checkpoints; then extend this framework globally. Within hours, OpenAI's Altman responded with "I agree with Dario," and Musk rarely echoed the sentiment. Three years ago, a thousand-person open letter calling for a pause in large model training sank without a trace. This time, things are different—the person calling for the brakes holds the steering wheel and has detailed the brake plan down to audit permissions and checkpoint granularity. Over the past year, incidents of AI agents breaking through sandbox isolation and autonomously accessing external websites have occurred repeatedly. Even the labs themselves admit that models are becoming unpredictable.

Capital markets, however, are reading a different signal: speed limits haven't slowed AI down but have instead made the business of "installing brakes on AI" a clear payer and budget category for the first time.

01. Brake Pad Economics: Model Vendors Start Paying for Safety

The biggest difference between this round of AI safety trends and the previous wave of cybersecurity lies in the source of budgets. Traditional cybersecurity funds come from corporate IT cost items, which are cut first during economic downturns. AI safety funds are directly embedded in AI capital expenditures—the stronger the model capabilities and the higher the usage volume, the higher the proportion of safety spending. Safety investment is becoming a "companion tax" that follows computing power, with its ceiling determined by the intensity of AI investment.

Dario's plan for third-party resident audits, translated into business language, equates to mandating external safety assessments for every round of model upgrades. With independent audit rights, procurement rights also become independent—assessment agencies, red team services, and runtime protection platforms shift from optional choices to fixed stations on the assembly line.

The bills have already started flowing. Ten days before Dario's article, Anthropic launched an enterprise-oriented "Frontier Safety Assurance" plan, bundling zero-data retention and abuse detection for model clients. A concurrent industry initiative rallied support from AWS, Microsoft, Google, JPMorgan Chase, NVIDIA, and other giants. OpenAI expanded its collaboration with CrowdStrike, integrating models into the latter's agent runtime protection platform. Okta's "AI Agent Management" product contributed nearly one-third of new bookings in a single quarter. Credo AI, a dedicated AI governance platform, doubled its revenue last year, with client budgets shifting from exploratory spending to core operational infrastructure.

Demand is also evolving. Early AI safety focused on content, filtering harmful information and blocking prompt injection. Now, the focus has shifted to agent runtime safety—permission control, behavioral auditing, and escape detection. An agent capable of autonomously invoking tools poses several orders of magnitude higher risk than a chatbot, driving up protection prices accordingly.

Research firm Mordor Intelligence estimates the global AI cybersecurity market will reach approximately $30.9 billion in 2025 and rise to $86.3 billion by 2030, with a compound annual growth rate of 22.8%. U.S. stock pricing has already led the way: Wells Fargo reiterated its overweight ratings for CrowdStrike and Palo Alto Networks, setting target prices at $230 and $475, respectively, with a straightforward logic—whoever controls AI's runtime entry points can take a cut of every AI dollar spent.

The brilliance of this business model also lies in its pricing structure. Assessment evaluations are charged per session, following model iteration rhythms—the more frequent model releases, the denser the assessment orders. Compliance platforms operate on annual subscriptions, becoming difficult to replace once embedded in enterprise workflows. Red team testing is priced per project, with high average order values and reliance on expert experience, making it hard to automate in the short term. These three layers superposition (superimposed) form a revenue model with naturally high repurchase rates.

02. Domestic Order Books Show AI Safety Revenue Is Calculable

Drivers in the domestic market are equally clear. Pre-launch filings and safety assessments for large models have become standard procedures. After the implementation of mandatory national standards for labeling generated synthetic content, companies incurred additional expenses for label detection and compliance modifications. By July 2026, 1,028 large model services had completed filings, each representing tangible third-party service procurement. According to IDC, China's AI safety market will reach approximately 4.4 billion yuan in 2025, with the safety agent sub-sector expected to hit 34 billion yuan by 2030.

Demand is also expanding. State-owned enterprises have deployed over 1,000 AI application scenarios, with finance, government, and energy sectors—which tolerate zero errors—including model robustness verification and prompt injection defense in their procurement lists. Safety budgets once followed compliance inspections; now they follow AI project approvals—every new agent application launched generates additional runtime protection orders.

Where the money lands on financial statements is becoming clear. AnHeng Information's HengNao safety vertical large model completed algorithm filing with the Cyberspace Administration, generating over 58 million yuan in pure AI revenue last year, up more than 230% year-on-year, with growth accelerating in the first half of this year—making it the A-share company with the clearest AI revenue trajectory. NSFOCUS secured 117 million yuan in AI safety orders in the first half of the year, with its AI vulnerability mining agent achieving a global first-place finish in international evaluations with over 95% vulnerability reproduction rates, grasping both offensive and defensive capabilities. QiAnXin's Large Model Guardian earned enhanced-level certification from the Ministry of Public Security and partnered with Hygon Information to deploy AI safety all-in-one machines, with AI new products contributing incrementally to its 4.392 billion yuan annual revenue. VenusTech's "three-piece suite" of large model application firewalls, security access proxies, and safety assessments passed a year of market validation, earning inclusion in multiple AI safety sub-sector representative vendor lists by international institutions. Sangfor is selling AI safety management suites to SMEs through channel sink (sinking) strategies.

At the valuation level, these companies still carry traditional cybersecurity labels: the sector as a whole faces profitability pressures, with valuations lingering at low levels. The market is actually pricing them as "traditional cybersecurity valuations + AI safety options," with AnHeng's 230% AI revenue growth and NSFOCUS's over 100 million yuan in orders signaling the start of option valuation. Guojin Securities previously identified QiAnXin, AnHeng, and VenusTech as key targets in its computer industry deep report; Guosheng Securities further judged in a recent research note that AI safety commercialization trends are clear, naming cybersecurity vendors with deep layouts. The only remaining disagreement is that AI safety revenue still accounts for single-digit percentages of these companies' overall revenues. For options to become core businesses, a one- to two-year fulfillment period is needed. The observation signals are simple—whether orders surge and whether AI categories are separately listed in financial reports. When both materialize, revaluation will come quickly.

An often-overlooked layer exists: safety capabilities are now feeding back into these companies' core businesses. Using AI to transform security operations centers and freeing analysts from massive (massive) alerts directly improves gross margins and labor efficiency. For the cybersecurity sector, which has struggled with consecutive losses and sought paths to reduce deficits, AI-driven cost improvements are as tangible as revenue increments.

The one- to two-year window Dario seeks for the industry is precisely the period safety vendors need to solidify capabilities into products and products into subscription revenues. During the last internet boom, cloud and firewall sellers emerged victorious; in this AI boom, the moment speed limits are imposed, brake pad manufacturers have entered their golden age.

- End -

Solemnly declare: the copyright of this article belongs to the original author. The reprinted article is only for the purpose of spreading more information. If the author's information is marked incorrectly, please contact us immediately to modify or delete it. Thank you.