So it’s finally happening. On September 29, 2026, at DevDay, OpenAI reopened its $200 ChatGPT Pro plan to new subscribers, and the plan now buys about half of what it used to. Codex and Work usage drops from 20 times the Plus allowance to 10 times. GPT-6 Pro messages in ChatGPT drop from 200 a week to 100. The price stays at $200. If you want the old experience back, there is a new Pro 500 plan with an “Ultrafast” speed tier, at $500 a month.
It’s a terrible deal for the people who were paying for it. To be fair, it’s also something we should all have seen coming. No AI company can hand out near-unlimited frontier compute for a flat monthly fee forever. The subsidy was always going to end, and now it is ending. The question is what that does to your company, because your employees are going to react to it whether you have a plan or not.

Key takeaways
- From October 30, 2026, ChatGPT Pro 200 includes 10x the Plus allowance in Codex and Work (down from 20x) and 100 GPT-6 Pro messages a week (down from 200). Existing subscribers keep the old allowance through October 29.
- The cut is not evenly felt. OpenAI halved API prices for GPT-6 Sol and Luna, so light users barely notice. GPT-6 Astra, the model heavy users actually wanted, kept its price, so Astra users lose roughly half their usable tokens.
- When a sanctioned AI tool gets rationed, people route around it: personal accounts, other vendors, and freshly minted API keys. That is shadow AI, and it is already expensive. IBM found breaches involving shadow AI cost organizations $670,000 more on average.
- Treat AI usage like any other resource with a budget and an attack surface: know who uses what, where the data goes, which keys exist, and what happens when a vendor changes the rules overnight.
What actually changed
Here is the before and after for the $200 plan, based on OpenAI’s DevDay announcements and the coverage from The Next Web and Engadget.
| Pro 200 before | Pro 200 from Oct 30, 2026 | Pro 500 (new) | |
|---|---|---|---|
| Price | $200 / month | $200 / month | $500 / month |
| Codex and Work usage | 20x Plus | 10x Plus | Highest allowance OpenAI offers |
| GPT-6 Pro messages in ChatGPT | 200 / week | 100 / week | Higher |
| Ultrafast (up to 300 tokens/sec in Codex) | No | No | Yes |
Existing Pro 200 subscribers get a one-time usage credit to soften the change, and OpenAI says it will not bring back the five-hour limit on Pro 200. But the direction is clear. The best experience now costs two and a half times as much.
How we got here: a month of rationing

This did not come out of nowhere. In mid-September, OpenAI paused new Pro 200 sign-ups, saying demand for GPT-6 Astra was “really unprecedented.” The $200 accounts, where people ran Astra hardest, were putting the most strain on OpenAI’s systems.
A week later, existing subscribers started hitting hard caps they had never seen before. One thread on the OpenAI developer forum describes limits that appeared with no notice and a message that just said “Limit reached. Try again after 4:59 PM tomorrow.” Another subscriber in the same thread wrote: “I’m giving this whole thing one more week; after that, everything’s going to Claude.”
Keep that last quote in mind. It is the most important line in this whole story for anyone running security or IT, and we’ll come back to it.
Why “unlimited” AI was never going to last
A flat subscription works when most users are light and a few are heavy. Frontier AI broke that math. Agentic tools like Codex don’t send one prompt and stop. They plan, call tools, retry, and resend their whole context on every turn. Our team saw this firsthand while building Trooper, a proxy that sits between agents and models: long sessions replay the same history again and again, and trimming that replay cut token usage by 89%.
That is why the price of a model per million tokens tells you little about what a task costs. As we wrote when Sonnet 5 launched, a model can be cheap per token and expensive per task if it takes three times the steps.
Now look at the API prices OpenAI set alongside the cut:

The Pro 200 allowance is effectively a dollar budget measured at API prices. Halve the budget and halve Sol and Luna prices, and Sol and Luna users come out about even. Keep Astra at $10 input and $50 output per million tokens, and Astra users lose half their work. The cut lands exactly on the heaviest, most valuable workloads, which is precisely where it hurts OpenAI’s margins most.
This isn’t an OpenAI problem, by the way. Every lab is buying the same GPUs and paying the same power bills. Expect every “unlimited” or “20x” plan to be repriced, rationed, or split into tiers over the next year. Plan for that as a certainty, not a risk.
The part nobody is talking about: what your employees do next
When a tool people depend on suddenly runs out at 2 p.m., they don’t stop working. They find another way. In practice that looks like this:
- Personal accounts. The developer who hit their cap on the company plan opens a personal ChatGPT or Claude account and keeps going, pasting in the same code, contracts, and customer data.
- Vendor hopping. “Everything’s going to Claude” is fine as a procurement decision. It is a problem when each employee makes it on their own, with their own card, and nobody reviewed the data terms.
- Raw API keys. Heavy users figure out that pay-as-you-go API access has no weekly cap. So they create keys, drop them into
.envfiles, CI variables, and agent configs, and share them in Slack. - Unvetted wrappers and gateways. Browser extensions, “free GPT-6” sites, and self-hosted proxies that promise more usage for less money, each with its own access to your data and your keys.
None of that is hypothetical. The numbers from the last year already show it happening:

- 39.7% of AI interactions involve sensitive data, counting prompt text, pastes, and file uploads, according to Cyberhaven’s 2026 AI Adoption and Risk Report. The same report found 32.3% of ChatGPT use and 58.2% of Claude use at work happens through personal accounts. Rationing the company plan pushes those numbers up, not down.
- Shadow AI breaches cost $670,000 more. In IBM’s 2025 Cost of a Data Breach report, one in five organizations had a breach linked to shadow AI. Of the organizations that had an AI-related incident, 97% lacked proper AI access controls, and 63% had no AI governance policy at all.
- AI-enabled breaches now average $6 million. The 2026 edition found one in four malicious breaches was AI-enabled, a 56% jump in a year, costing about $1 million more than the $4.99 million global average. More than 20% of organizations reported a breach targeting their AI models or applications.
- AI API keys are the fastest-growing leaked secret. GitGuardian counted 1,275,105 leaked AI-service secrets on public GitHub in 2025, up 81%, and eight of the ten fastest-growing secret types were AI-related. Worse, 64% of secrets leaked back in 2022 still worked.
Put those together with a rationed Pro plan and you can predict the next six months: more personal accounts, more keys in more places, and more company data sitting in tools nobody approved.
The AI plumbing itself is a target too. CISA has added a LiteLLM flaw to its exploited list; the proxy that many teams use to share and meter model access could be turned into remote code execution and a dump of every provider key it held. And agents that read untrusted content can be steered by it, as the OpenClaw attacks and the Agentjacking research we covered in The Attackers Got AI Before We Did showed.
Cost control and security are now the same job
We’ve argued before that the real risk with AI is the gap between deployment and governance. The Pro 200 cut makes that gap visible in the finance report as well as the risk register. The same questions answer both: who is using which AI tools, with which accounts and keys, sending what data, at what cost.

1. Inventory what’s actually in use
List every AI tool, plan, and API key the company pays for, then compare it with what’s actually running. Sign-in logs from your identity provider, OAuth grants, expense reports, DNS and proxy logs, and code scanning for keys will each show you tools the others miss. Expect the second list to be longer.
2. Budget by team, not by seat
A seat price tells you nothing now that plans are metered underneath. Give each team a monthly budget in dollars or tokens, find out who your heavy users are before the vendor does, and decide ahead of time whether they get a bigger plan, API access, or a cheaper model for routine work. Most tasks don’t need the flagship model.
3. Give people a sanctioned route that doesn’t run out mid-day
Shadow AI is mostly a supply problem. If the approved route caps out at 2 p.m., people leave it. Offer a company account with a known allowance plus a metered fallback through a gateway you control, so hitting a limit means “switch to the fallback,” not “open a personal account.” Patch and lock down that gateway like any other internet-facing service; it holds your most valuable keys.
4. Treat keys and data flows as security telemetry
Every AI API key is a credential with a spending limit attached to someone’s card. Scan repos and CI for them, rotate on a schedule, and revoke on leave. Send identity, endpoint, and network logs where someone (or something) actually reads them, and alert on new AI domains, uploads of large files to AI tools, and keys used from unexpected places.
5. Plan for the next repricing
This was OpenAI in September. It will be someone else next quarter. Keep at least two approved vendors for important workflows, keep prompts and agent configs portable, and write down what happens when a plan changes: who decides, how fast, and what employees are told so they don’t improvise.
Where Jutsu fits
Jutsu doesn’t sell AI seats, and it won’t make your ChatGPT plan cheaper. What it does is make sure that when people route around a rationed tool, you see it and can respond, instead of reading about it in an incident report.
- AgentSOC pulls in Google Workspace audit and login events, Wazuh host events, and syslog from your firewalls and proxies. AI agents enrich, triage, and correlate those alerts, so a new sign-in pattern, an upload to an unapproved AI service, or a key used from a strange IP turns into an investigated incident rather than one more line in a log. Response runs through AgentSOAR (block IPs, isolate hosts, disable users, each with revert), and anything uncertain escalates to a person.
- Exposure shows what an attacker sees from the outside in about ten minutes, including breach and dark web data, leaked secrets (masked before storage), and an AI readiness score. It’s a quick way to find the gateway nobody patched or the key that already escaped.
- Red Team runs MITRE ATT&CK-mapped attack simulations against authorized targets, so you can check whether data leaving through an unapproved channel actually trips a detection. We wrote about why that matters in Your Automated Pentest Looks Clean.
If you’re new to the idea of AI agents doing SOC work, start with What Is an AI SOC? and What Is an Agentic SOC?. And if you want to see it on your own data before the October 30 cutover lands, the Free plan covers 5 assets and 50 AI investigations a month, no credit card.
The bottom line
OpenAI halving Pro 200 is annoying, but it’s also honest. Frontier AI costs real money to run, and the era of paying one flat fee for as much as you can use is closing across the industry. The companies that come out of this fine are the ones that already know who uses AI, how much, with which keys, and where their data goes. Everyone else is about to find out, one personal account at a time.
FAQ
When does the ChatGPT Pro 200 usage cut take effect?
The lower allowance applies from October 30, 2026. Subscribers who were active at the eligibility cutoff, or in the seven days before it, keep the previous allowance through October 29, 2026, as long as their subscription stays active. The price stays at $200 a month.
How much less does Pro 200 include now?
Codex and Work usage drops from 20x to 10x the Plus allowance, and GPT-6 Pro messages drop from 200 to 100 a week. Because GPT-6 Sol and Luna API prices were also halved, people who mostly use those models see little change. GPT-6 Astra users lose about half their usage.
What is the ChatGPT Pro 500 plan?
A new $500-a-month tier with OpenAI’s highest usage allowance and access to Ultrafast, which generates up to 300 tokens per second in Codex and Work.
What is shadow AI?
Shadow AI is any AI tool, account, or API key that employees use for work without IT or security approval. Personal ChatGPT or Claude accounts, browser extensions, and self-created API keys are the common forms. IBM’s 2025 research found breaches involving shadow AI cost $670,000 more on average.
How can a company control employee AI usage without banning it?
Give people an approved route with enough capacity that they don’t need to go around it, budget usage by team, route API access through a gateway you control, scan for leaked AI keys, and monitor identity and network logs for unapproved AI services. Bans mostly push usage onto personal devices where you can’t see it.