AI Mindset · Model Cheatsheets
Specialist AI

When the General Model Is Not Enough

OpenEvidence’s own privacy policy says user data, including questions and prompts, may be sold to third parties or otherwise monetized as a commercial data feed. The same policy says user questions aren’t covered by HIPAA. Yet the vendor’s April 25, 2025 announcement says it’s fully HIPAA compliant. Two first-party documents, both live. They can’t both govern. Settle which one does, in writing, before any patient data goes near the tool. That’s the shape of this whole category. Specialists are purpose-built tools for one domain: coding, legal, finance, support, enterprise knowledge and health. The domain layer is what you buy. The policy page is what you sign up to.

Verified October 1, 2026General vs verticalCoding · Legal · FinanceSupport · Knowledge · HealthBuild vs buy
1 / Meet Specialist AI

A different question from “which model is best”

General assistants are brilliant generalists. But in regulated, data-heavy or workflow-bound work, the less clever tool often wins. Strange, right? It wins because the domain is already inside it: the case law, the codebase, the EHR, the data room. The 2026 market has a credible specialist for most professional functions. The skill is knowing when to reach for one.

What they are

Domain layer over a frontier model

Here is the part the demo skips. Most vertical tools run on the same OpenAI or Anthropic models as your general assistant. The brain is rented. What you pay for is the layer on top: proprietary data, workflow, integrations, evaluation and accountability.

  • The intelligence is often rented
  • The domain layer is the product
  • Judge the layer, not the demo
Why they win

Depth a generalist cannot fake

A general chat starts every conversation cold. A specialist already holds your repository, your matter history, your permission model, your compliance posture and the workflow the work actually follows. You can’t fake that with a better prompt.

  • Context that lives in your systems
  • Guardrails for regulated work
  • Integrations into systems of record
The catch

Price, lock-in and overlap

Specialists cost more. They embed your data deeply. And they often overlap with the general assistant you already pay for. So the call is economic and architectural. Capability is only one input.

  • Your Copilot may already do 80%
  • Migration is rarely easy
  • Buy only for the part that clears the bar

General assistant or vertical specialist?

Start from the job, not the vendor. Move down only when the job earns it.

Broad, low-stakes, occasional
Use the general assistant you already have

Drafting, summarizing, one-off analysis, exploration. ChatGPT, Claude, Copilot or Gemini usually handle all of it. Don’t buy a specialist for a job the generalist already does.

  • No new contract or integration
  • Human stays close to the work
  • Reserve budget for real depth
2 / The 2026 Map

A specialist for most professional functions

Pick a professional function. There’s probably a well-funded, credible specialist for it, doing work a general assistant only skims. That’s the shape of the market in late 2026. Names change fast, and so do the boundaries. So read this as a snapshot of categories, not a permanent leaderboard.

DomainWhat the specialist addsLeading examples
CodingRepository context, autonomous multi-file agents, CI and pull-request integrationCursor (now owned by SpaceX), Cognition (Devin)
LegalCase law, contracts, firm knowledge, citation discipline and conflict-of-interest enforcementHarvey
Finance and researchDeep analysis across private documents, public filings and licensed market data, now delivered into other tools over MCPHebbia
Customer service and long-horizon workOutcome-priced agents across chat, voice, email and messaging, now extending to goals that run for weeksSierra
Enterprise knowledgePermission-aware search and agents across all company apps, with an agent identity model the vendor still labels betaGlean
HealthcareAmbient clinical notes inside the EHR, extending into workflow and revenue cycle; evidence at the point of careAbridge, OpenEvidence
3 / Coding Agents

The most mature vertical, and the most contested

Software is where vertical AI has gone furthest. It’s also where the general assistants fight hardest. Claude Code and OpenAI Codex are the generalist coding agents. Cursor and Cognition are the purpose-built ones. Both sides keep shipping. Cursor put Grok 4.7 in the editor on September 21. Cognition says it crossed $1B in annualized revenue run rate on September 25. And here’s the thing nobody says out loud about this pair. Cognition is the only vendor here with a full published price list, so it’s the only one you can budget against without booking a call. Even that list stops short of Enterprise, which Cognition bills in Agent Compute Units at an order-form rate it doesn’t publish.

Cursor IDE agent · SpaceX-owned

Cursor sells a coding agent for ambitious software: deep codebase understanding, autonomous and parallel agents, and bring-your-own-model across OpenAI, Anthropic, Gemini, SpaceXAI and others. Its enterprise page, read October 1, 2026, claims 64% of the Fortune 500, more than 50,000 enterprises and 93% engineer preference in head-to-head evaluations. All vendor claims. Now read what that page leaves out. It names SpaceXAI as a model provider and never mentions SpaceX ownership. SpaceX acquired xAI on February 2, 2026 and Cursor on August 14, 2026. So Cursor and its model supplier are sister companies, not arm’s-length parties. Grok 4.7 arrived in Cursor on September 21. Cursor’s post carries no price and defers the detail to x.ai. xAI’s own post fills the gap. Grok 4.7 is served at the same price and speed as Grok 4.6: $2.00 per million input tokens, $0.50 cached and $6.00 output, below 200k tokens. On data, Privacy Mode is opt-in. Off is the starting position.
· The acquisition in Cursor’s own words, August 14, 2026: “Cursor has officially been acquired by SpaceX.” No valuation and no terms are disclosed.
· cursor.com/security, last updated August 25, 2026: “When enabled, we will not train on your data.”

  • Acquired by SpaceX on August 14, 2026, no terms disclosed
  • Grok 4.7 at Grok 4.6’s price, per xAI: $2.00 in, $6.00 out per million tokens
  • Privacy Mode is opt-in, so no training is not the default
  • Router plan gating unconfirmed: docs block automated fetches

Cognition (Devin) Autonomous SWE

Cognition runs Devin, marketed as the first autonomous software engineer. It plans, writes, tests and ships code inside your codebase and your tools. September was busy. A Series E on September 8 says Cognition raised over $2B at a $48B valuation, led by Andreessen Horowitz and Accel. SWE-2, which Cognition calls its most advanced coding model yet, landed September 10. Fusion shipped into Devin Desktop and the Devin CLI on September 11. A multi-year Strategic Collaboration Agreement with AWS followed on September 15. And on September 25 Cognition said it crossed $1B in annualized revenue run rate. Vendor statements, all of them, and none audited. The part a procurement sheet needs is the price list, because nobody else here supplies one. But it binds self-serve buyers only. Enterprise is billed in Agent Compute Units at the rate set in your order form, and no ACU rate is published anywhere. Training is on by default. Paid plans can opt out. Somebody has to go and click it.
· The Series E wording: “Cognition has raised over $2B at a $48B valuation.”
· The training wording, from the undated Devin documentation: “By default, we may use your data for model training purposes.”

  • $1B annualized revenue run rate claimed September 25, 2026 (vendor statement)
  • Self-serve list published; Enterprise billed in ACUs at an unpublished order-form rate
  • Training on by default; paid plans can opt out, Enterprise needs written consent
  • FedRAMP Class D (High) In-Process: a queue position, not an authorization
Coding vendor detailCursorCognition (Devin)
OwnerSpaceX, since August 14, 2026; no terms disclosedIndependent; Series E on September 8, 2026 at a stated $48B valuation
Latest model newsGrok 4.7, September 21, 2026; priced by xAI at $2.00 input, $0.50 cached, $6.00 output per 1M tokens below 200kSWE-2, September 10, 2026; Fusion harness for Fable and Astra, September 11, 2026
Self-serve priceHobby free; one $20 a month entry price over Pro, Pro+ and Ultra; one $40 per user a month over Teams Standard and PremiumFree; Pro $20 a month; Max $200 a month; Teams $80 a month minimum, $40 per full seat, up to 200 members
Enterprise priceCustomAgent Compute Units at the order-form rate; no ACU rate published
Training defaultNo training only with Privacy Mode enabled; Privacy Mode is opt-inMay train by default; paid plans can opt out; Enterprise only with express prior written consent
Retention publishedNoDuration of the customer relationship
CertificationsSOC 2 Type II, ISO 27001, ISO 42001, AIUC-1SOC 2 Type II, obtained March 2024, no renewal date; FedRAMP Class D (High) In-Process since July 13, 2026
Status flagsProjects in beta since September 10, 2026; Router plan eligibility unconfirmed; Origin hosting with no stated statusFedRAMP In-Process is not an authorization
Price sourcecursor.com/pricing, undated, read October 1, 2026docs.devin.ai, undated, read October 1, 2026; cognition.com/pricing is a 404
Deals since July 2026Firetiger, August 13, 2026TierZero; The Interaction Company; the Dioxus team, September 10, 2026
$1,339
Cheapest run of Cursor’s July 20 agent-swarm rebuild of SQLite in Rust, on Opus and Composer (vendor report)
$10,565
Most expensive run of the same project, on GPT-5.5, nearly an eightfold spread for identical work (vendor report)
70,000 to 1,000
Merge conflicts across the swarm, cut from over 70,000 to under 1,000 as the approach was tuned (vendor report)
4 / Legal · Finance · Knowledge

Where domain data is the moat

Raw intelligence is the cheap part here. What matters in legal, finance and enterprise knowledge is grounded access to the right documents, under the right permissions, with the right citation and audit discipline. These tools compete on the corpus and the controls. The model underneath is almost beside the point. The pace is uneven now, and that itself is information. Glean publishes dated release notes most weeks and joined OpenAI’s B2B marketplace on September 29. Harvey made Agentic Search generally available across iManage, SharePoint and Google Drive on September 30. Hebbia has published nothing since September 10.

Harvey Legal

Agents for law firms and enterprise legal teams, grounded in case law, contracts and firm knowledge. Harvey is the most active vendor here, with roughly 28 posts between September 3 and September 17 alone. Its homepage, read October 1, 2026, claims more than 200,000 professionals, 3,000 or more firms and in-house teams, more than 70 countries and 80 or more AmLaw 100 firms (vendor claims). Two of those moved in two weeks: firms from 2,400 to 3,000, AmLaw 100 from 75 to 80. So read the homepage again on the day you quote it. What shipped: Agentic Search across iManage, SharePoint and Google Drive went generally available on September 30. What hasn’t: Harvey II, announced August 18, carries no availability language at all. And the Everlaw MCP integration is still “are building.” On data, Harvey says it doesn’t train on your work. It doesn’t say how long it keeps it. And there’s no price anywhere.
· Harvey’s training wording: “We don’t use inputs, outputs, or uploaded documents to train underlying models.”
· harvey.ai/pricing returns a 404, read October 1, 2026.

  • 3,000 or more firms and teams, 80 or more AmLaw 100 (vendor claims)
  • No training on inputs, outputs or uploaded documents
  • No published customer-data retention period
  • Harvey II has no availability language and no price

Hebbia Finance

Hebbia calls itself the leading AI platform for finance. Its product page now leads with two things, Matrix and Max. Skills appears as something Max can use, and Agents isn’t presented as a product at all. Matrix runs analysis across private documents, public filings and licensed market data. Connectors include SEC filings, CapIQ, FactSet, PitchBook, Preqin, expert networks, Snowflake and SharePoint. Matrix 2.0 landed August 26, 2026. Daloopa arrived in Hebbia on September 1. A founder essay followed on September 10, and nothing since. Max has drifted without anyone clarifying it. It’s marketed as a co-equal flagship with a demo call to action. But the July 30 line that it’s “rolling out to a small set of firms first” has never been retracted, sixty-three days on. On price, hebbia.com/pricing is broken rather than empty. On data, Hebbia gives the cleanest single sentence here.
· Hebbia’s training wording: “Your documents, prompts, and outputs are never used to train Hebbia’s models or any model provider we work with.”
· The pricing page renders “Failed to load page data from Contentful.” and no price.

  • Matrix 2.0 shipped August 26, 2026
  • Documents, prompts and outputs never used for training
  • Pricing page returns a Contentful error, not a price
  • Max marketed as a flagship with no stated general availability

Glean Enterprise knowledge

Work AI that unifies permission-aware search, an assistant and agents across your company apps. Start with a small tell. Glean’s own pages disagree about its connector count: “more than 250” on the platform overview, “275+” on the pricing page. Both are undated. Quote whichever you read, with the date. That pricing page carries no plan names, no prices, no seat model and no minimum. Just “Get a demo.” Glean’s May 28, 2026 press release puts the business at $300M ARR (vendor claim). August 26 brought six launch posts in one day. Read Transform’s status carefully, because the launch doesn’t. Glean’s navigation lists it “Coming soon,” and glean.com/products/transform is still a 404. September brought something shipped instead: interactive artifacts on September 9, available the same day. On September 29 Glean joined OpenAI’s B2B marketplace. And its release notes are good news for you. Each release has its own dated, stable page, back to April 2025.
· Transform, in Glean’s words: “an early preview of what we’re building.”

  • Two Glean pages disagree on connectors: 250+ and 275+
  • Dated per-release notes you can cite, back to April 2025
  • No published prices, plan names or seat model
  • Glean Transform is “Coming soon,” not available
Vendor detailHarveyHebbiaGlean
Latest shipped featureAgentic Search for document systems, generally available September 30, 2026Daloopa in Hebbia, September 1, 2026Interactive artifacts, September 9, 2026
Announced, not availableHarvey II, August 18, 2026; Everlaw MCP integration, September 3, 2026Max, gated since July 30, 2026Transform, August 26, 2026; agent identity, beta since July 15, 2026
Published priceNone; harvey.ai/pricing is a 404None; the pricing page returns a Contentful errorNone; plan names appear only in release notes
Training positionNo training on inputs, outputs or uploaded documentsDocuments, prompts and outputs never used for trainingNot readable; the relevant legal pages block automated access
Retention publishedNo; audit logs kept one to ten yearsNoNo
Certifications listedSOC 2 Type II, ISO 27001, ISO 42001; no HIPAASOC 2 Type 2, ISO 27001:2022, GDPR; no HIPAANot established from readable pages
Subprocessor listUpdated September 21, 2026, with a processing location per providerNot published; hebbia.com/trust is a 404Updated July 28, 2026, 21 named entities
Glean

Agents with an identity of their own, still labeled beta

An agent can “use its own scoped service credentials instead of borrowing the identity of the person who invoked it,” with admin controls for credential scoping and audience management. So access rights split from invocation rights, and audit trails name the agent rather than whoever triggered it. It’s the most interesting governance move in this market. And it’s still beta, seventy-eight days in. Glean labels features beta in its docs while launch pages read as shipped, so go by the docs. Pilot it. Keep it out of a dated rollout plan until Glean says it’s generally available.
· The admin page, last updated September 30, 2026, still carries “Beta: This feature is in beta and may change.” It adds that the agent runtime never receives the raw secret.
· The July 15 launch post never says “generally available.”

  • Public beta since July 15, 2026
  • Docs read October 1, 2026 still banner it as beta
  • Scoped credentials per agent; the runtime never sees the raw secret
  • Audit trails name the agent
Glean

A vendor benchmark against a named competitor

One of the six August 26 posts names a rival in its title: “Right-sizing intelligence: Glean saves 81% on token costs and is preferred 78% of the time versus Claude Cowork.” Both figures are Glean’s own claims about a named competitor. Produced by Glean. Published by Glean. In Glean’s comparative marketing. Record that the post exists and what it asserts. Don’t endorse either number. If a token-cost or preference figure is going to move a purchase, run the comparison on your own corpus and your own queries. A vendor’s idea of “right-sizing” is a claim about which jobs need which model. That judgment is exactly what you’re buying.

  • 81% token-cost saving: Glean’s claim
  • 78% preference rate: Glean’s claim
  • Vendor comparative marketing, not an independent test
  • Reproduce it on your own workload before citing it
Harvey

A specialist arriving inside a suite

Harvey showed up as a new connector in Microsoft 365 Copilot in Microsoft’s August 2026 roundup. The specialist and the generalist have stopped being alternatives on a shortlist. They’re layers now. So ask three questions. Who owns the connector? Whose permission model applies inside it? Where does the audit trail land? For a law firm, Ethical Wall enforcement with Intapp, generally available since July 23, is why that matters. Conflict policy has to travel with the tool into every surface it appears on. The September 3 Everlaw announcement is the same pattern again. Ask those questions twice there, because Harvey and Everlaw say they “are building” the MCP integration, not that it’s live.

  • Harvey is now a Microsoft 365 Copilot connector
  • The Everlaw MCP integration is announced, not shipped
  • Two permission models meet in one workflow
  • Confirm walls and audit coverage in the connected surface
Hebbia

Beyond your own documents

The corpus is no longer just the data room. Hebbia’s July 10 integration post is the clearest statement of that scope: private files sit alongside public filings and licensed market data in a single view. So the diligence question changes. It used to be “can it read our documents.” Now it’s “which third-party licenses do we already hold, and which does this tool require of us.” Matrix adds a second version of the same question, because Hebbia now says its output leaves through MCP into Claude, ChatGPT and Cursor. That’s an egress question. When you put it to Hebbia, quote the right page.
· That distribution claim lives in the September Disclosure post of August 31, not in the Matrix 2.0 launch.

  • One view over three kinds of data
  • License terms become part of the buy
  • MCP distribution adds an egress question
  • Source every number back to a filing
Evaluate a legal or finance tool
For this vertical tool, tell me: which underlying model it uses, exactly what proprietary data or workflow it adds on top, how it handles citations and source traceability, and where our data is stored and processed. Separate vendor marketing from verifiable fact.
Overlap audit
Compare what this specialist does against what our existing Microsoft 365 Copilot and ChatGPT already cover. Identify the specific 20% of the workflow the specialist really adds, and whether that 20% justifies the cost and integration.
Test a vendor comparison
This vendor published a comparison claiming a cost saving and a preference rate against a named competitor. Design a test I can run on our own documents and queries that would confirm or refute both numbers, and tell me what the vendor’s methodology would have to look like for the claim to hold.
5 / Customer & Clinical

Specialists that act, and specialists that must be right

Two frontiers where being wrong costs something real. And on one of them, a vendor’s privacy policy and its own HIPAA announcement say opposite things about the same clinician asking the same question. Customer-facing agents take actions for actual users. Clinical tools carry a different weight of error entirely. Both show the same thing: the guardrails and the paperwork matter more than any capability claim.

Sierra Agents that act

Sierra began in customer experience, across chat, voice, email and messaging, priced on outcomes. It has pushed well past that. Horizon, announced July 16, targets goals that run for days, weeks or months, such as loan origination and prior authorization. September added multimodal agents on the 10th, AIUC-1 certification on the 17th and Ghostwriter on the 28th, now a named product rather than a demo. On price, say it plainly: there’s no rate card. Outcome pricing exists only as prose. No per-resolution rate, no platform fee, no minimum, no billing term. On September 29 Sierra joined the OpenAI Marketplace. That’s still not a rate. But it’s the first published way anyone can actually pay Sierra. Two numbers you’ve probably seen aren’t Sierra’s. Neither 40% of the Fortune 50 nor a roughly $15.8B valuation appears anywhere on its site. On data, Sierra publishes one good sentence and nothing more.
· Sierra’s data wording: “Your data is only used as you instruct, and is never shared with other customers.”
· sierra.ai/pricing returns a 404, read October 1, 2026.

  • Joined the OpenAI Marketplace September 29, 2026
  • No rate card: sierra.ai/pricing is a 404
  • Data used only as instructed, never shared between customers
  • The 40% and $15.8B figures are not first-party

Abridge Clinical documentation

Abridge turns doctor and patient conversations into structured clinical notes in real time, inside Epic. That’s still accurate. It now names one of five product lines: Clinicians, Revenue Cycle, Nursing, Clinical Decision Support and Care Signals, the last co-developed with Kaiser Permanente. All five run on what Abridge calls its Contextual Reasoning Engine, with Linked Evidence for auditability. The July 20 Altrina acquihire adds browser-based agents and EHR workflow automation. The biggest item in the window landed September 22. Abridge was selected under the VA enterprise contract to bring ambient AI to veteran care nationwide. Read the money carefully, because the headline number is about to be misquoted at you. The $775.72 million ceiling is shared across all eligible vendors over five years. It isn’t Abridge’s award. Abridge says it’s already live at more than 75 VA medical centers through pilots (vendor figure).
· Abridge’s training and retention position sits behind an access request in its trust center.
· Abridge publishes no price anywhere, and abridge.com/security is a 404.

  • Five product lines on one Contextual Reasoning Engine
  • Selected under the VA enterprise contract September 22, 2026
  • The $775.72M ceiling is shared, not Abridge’s award
  • Clinician reviews every note

OpenEvidence Clinical evidence

A medical answer engine grounded in licensed clinical literature, free to clinicians and deployed across health systems. Start with the contradiction, because it decides whether you can use this at all. The privacy policy says user questions and prompts may be sold or monetized as a commercial data feed, and that user inputs aren’t covered by HIPAA. The vendor’s April 25, 2025 announcement says it’s fully HIPAA compliant. Both are first-party. Both are live. The announcement records what OpenEvidence said in 2025. The policy is the live page, so treat it as governing until OpenEvidence confirms otherwise in writing. Ask for the business associate agreement, which isn’t published. The rest is confirmable. NEJM Group content agreement, February 19, 2025. JAMA Network, June 5, 2025. DeepConsult and a $210M round at a $3.5B valuation, July 15, 2025. Nothing on the announcements index carries a 2026 date, so don’t call that funding recent.
· The policy wording: “Your user data, including your questions/prompts, may be sold to third parties or otherwise monetized as a commercial data feed.”

  • Privacy policy: questions and prompts may be sold as a data feed
  • Same policy: user inputs are not covered by HIPAA
  • April 25, 2025 announcement: fully HIPAA compliant
  • Free at the point of use: no pricing page or enterprise plan
Vendor detailSierraAbridgeOpenEvidence
Latest dated itemOpenAI Marketplace, September 29, 2026VA enterprise contract selection, September 22, 2026Funding round and DeepConsult, July 15, 2025; nothing dated 2026
Published priceNone; outcome pricing described in prose onlyNoneFree; no pricing page, seat model or enterprise plan
Training positionData used only as instructed, never shared with other customersBehind an access requestQuestions and prompts may be sold or monetized as a data feed
Retention publishedNoBehind an access requestUp to one year after account deactivation
HIPAAListed on the trust pageListed in the trust centerPolicy: inputs not covered. Announcement, April 25, 2025: fully compliant
Certifications listedSOC 2, GDPR, PCI, FedRAMP High, CCPA, CSA STAR, ISO 27001, ISO 42001; AIUC-1 announced September 17, 2026 but not listedCCPA, SOC 2 Type 1 and Type 2, TX-RAMP; no ISO 27001, no HITRUSTNot established
Gated or missing documentsTrust center renders in a browser onlyModel cards, network diagram, pentest summary, security whitepaperBusiness associate agreement not published
6 / Build vs Buy

A decision framework, not a vibe

These calls are expensive and they keep coming back. Specialist or generalist. Buy or build. Run them on purpose, then run them again, because the thing you evaluated in July may arrive through a different surface in September.

The evaluation path

Four checks before you sign anything.

Job
Name the job and its stakes

Write down the one specific, repeated task. Its volume. What an error costs. What rules apply to it. Vague jobs never justify specialist spend.

  • One concrete workflow
  • Volume and error cost
  • Regulatory context
7 / Behavior Playbook

Six habits for buying a specialist without regret

None of these habits is about the model. They’re about what you read, what you write down and who owns the result. Each one comes from a vendor above that already caught somebody out.

01

Read the live page before the launch post

A dated article is authoritative for what was announced and when. A live page is authoritative for what is true today. When they disagree, the live page governs the present and the article governs the record. Keep your own dated copy of the live page, because it carries no history.

02

Treat announced as unavailable

Harvey II, Hebbia Max, Glean Transform and the Everlaw integration are announcements, not products. Diarize the date, re-read the source page on the same cadence, and keep a dated copy of the row you depend on. A date written down once and trusted is how you miss a deadline that moved.

03

Get the price in writing

Here a written quote is usually the only price that exists. Six of the eight vendors publish nothing usable. Cognition’s list stops at Enterprise, where Agent Compute Units bill at an unpublished order-form rate. And tell a broken pricing page from a deliberate one before you draw a conclusion.

04

Give every training switch an owner

Cursor’s Privacy Mode starts off. Cognition may train by default until a paid plan opts out. A default like that is a configuration task, not a feature. Name the person who sets it, and have them check it again after every plan change or renewal.

05

Ask which surface it arrives on

Hebbia arrives inside Claude, ChatGPT and Cursor over MCP. Harvey arrives inside Microsoft 365 Copilot. Each time, ask whose permission model, data terms and audit trail apply there. And ask whether the embedding vendor’s model terms match the ones the model maker publishes.

06

Keep a human of record

Every filing, diff, clinical note and customer action needs a named professional who signs it. Every long-running goal needs an owner and a checkpoint schedule. “The agent handled it” isn’t a sign-off. A name is.

8 / Watch Outs

A $48B valuation is not a fit for your workflow

Three risks here that a general assistant doesn’t carry. You often pay a premium for someone else’s model. You embed sensitive data deeply. And you bet on a market that’s consolidating while you read. At least eight deals have landed across these eight vendors since July 10, 2026. Cursor acquired Firetiger on August 13. SpaceX acquired Cursor the next day. The Dioxus team joined Cognition on September 10. Deals come in bursts, so don’t mistake one busy stretch for a yearly pace, or a quiet one for a settled market. These vendors announce on their own blogs, on their own schedule.

Rented intelligence

Many verticals wrap OpenAI or Anthropic. Confirm the domain layer is real before you pay specialist prices for someone else’s model.

Overlap you already own

Your Copilot, ChatGPT or Claude may already cover most of the job. Buy the specialist for the measured gap only. And this is getting harder to judge, not easier. Hebbia says Matrix now runs inside Claude, ChatGPT and Cursor over MCP. Harvey is a Microsoft 365 Copilot connector. So the same capability can reach one user through two contracts at once.

Vendor comparisons name competitors now

Glean’s August 26 post claims it “saves 81% on token costs and is preferred 78% of the time versus Claude Cowork.” Those are Glean’s figures about a named rival, published in Glean’s own marketing. Treat any head-to-head number from a vendor as a hypothesis to test on your corpus. Stay just as skeptical when a competitor answers with numbers of its own.

Data and compliance

Vertical tools touch your most sensitive data: legal, clinical, financial. Three of the eight vendors here say plainly that they don’t train on your work. Three default the other way, with an opt-out you have to go and find. Two publish no answer a buyer can read. And only two publish anything like a retention period. The table below sets out each position in the vendor’s own terms. Add one more question for MCP distribution. When the specialist runs inside another vendor’s assistant, whose data-processing terms apply?

The terms that need a human with a browser

Four Glean pages decide Glean’s data terms, and a tool can’t open any of them. glean.com/legal/dpa, glean.com/legal/ai-addendum and glean.com/legal/security-standard are blocked to automated access by Glean’s own robots.txt. trust.glean.com builds its content in the browser, so anything else gets metadata and nothing more. Those four pages are where the answer sits on whether Glean trains on your data, how long it keeps it and when it deletes it. No other page on Glean’s estate answers those questions. Two more trust centers behave the same way, Sierra’s and Abridge’s, and Abridge keeps its model cards, network diagram, pentest summary and security whitepaper behind an access request on top. So put this on a person’s calendar, not in a backlog. Open the four Glean pages. Ask Glean for the Limited Retention Addendum its own legal index lists. Request the gated documents from Sierra and Abridge. It’s an hour of someone’s time and it decides whether the contract is signable.

Lock-in

Proprietary data and workflow make these tools hard to leave. Check export and migration before you embed one in a critical path.

Announced is not available

Five things on this map have been announced without becoming buyable, and the day counts are getting hard to defend. Harvey II, introduced August 18, 2026 with no availability language of any kind and no pricing: forty-four days, and the September changelog still doesn’t mention it. Hebbia Max, “rolling out to a small set of firms first” since July 30: sixty-three days, now marketed as a flagship with no general-availability statement and no retraction of the gating line. Glean agent identity, in public beta since July 15 and still beta-bannered in documentation updated September 30: seventy-eight days. Glean Transform, launched with fanfare on August 26, listed “Coming soon,” called an early preview by Glean itself, and still a 404 at its own product address: thirty-six days. And Harvey and Everlaw, who said on September 3 that they “are building” an MCP integration: twenty-eight days, same wording. None of these belongs in a dated rollout plan. If one of them is load-bearing in yours, ask for a date in writing and read “soon” as a no.

A capability matrix expires in days

Fable 5.1 reached Harvey and Microsoft 365 Copilot on its September 1 launch day, Glean on September 3 and Cognition’s Fusion harness by September 11. Three weeks later Glean had added Claude Opus 5.5, GPT-6 Sol and GPT-6 Luna on September 22 and Claude Sonnet 5.5 on September 29. By then OpenAI had already superseded GPT-6 Sol with GPT-6.1 Sol. Glean is the easy one to track, because each release gets its own dated page at its own stable address and you can link a colleague to the proof. The others are harder: Harvey announces model support inside prose posts, Cognition inside harness notes. So any capability matrix you circulate should carry the date it was compiled and the page each row came from. Two weeks is long enough to make it wrong in either direction.

Consolidation, at speed

At least eight deals across these eight vendors since July 10, 2026. In the seventeen days to July 27: Cognition bought TierZero and welcomed The Interaction Company, Harvey bought Benchmark, Sierra bought Takeoff, Abridge took on the Altrina team. On August 13, Cursor acquired Firetiger, which builds agents that work on software once it reaches production. No terms were disclosed. On August 14, Cursor announced that it “has officially been acquired by SpaceX,” completing a process begun in April. Again no valuation and no terms. On September 10, the Dioxus team joined Cognition, no terms. Money moved too. Harvey took a strategic investment from Goldman Sachs and J.P. Morgan on July 28 with no new valuation published. Cognition announced a Series E on September 8 it says raised over $2B at a $48B valuation. One of these eight vendors is now owned by a launch company. That sharpens the point. It doesn’t soften it. The specialist you sign with may not merely be a different company in a year. It may sit inside a group whose priorities have nothing to do with your codebase.

Do not infer ownership, but do not ignore the signal

A partnership, a joint model launch or a shared brand is evidence of a relationship. It isn’t evidence of ownership. Cursor ran a public partnership with SpaceXAI from April 2026 and co-released Grok 4.6 with it on August 12. Cursor announced the acquisition itself only on August 14, 2026, in a dated post titled “Cursor is now a part of SpaceX.” Wait for the dated post rather than inferring from the pattern, even when the pattern turns out to have been right. An inference carries no date you can cite. Then look at what followed, because the commercial question outlives the announcement. Cursor’s enterprise page now names SpaceXAI as a model provider while saying nothing at all about the change of ownership. That silence is worth noting, but don’t read it as distance. SpaceX acquired xAI on February 2, 2026 and Cursor on August 14, 2026, so Cursor and its frontier-model supplier are sister companies inside one group. So the diligence question is concentration rather than supplier reliability. Ownership and model supply now change hands together. There’s one parent instead of two counterparties. The terms between them are intra-group rather than negotiated at arm’s length. That puts transfer pricing, affiliate terms and a single change-of-control event on the agenda in place of ordinary third-party supply risk. Get ownership, control and model supply written into the contract rather than inferred from a launch post. And put a change-of-control clause in anyway, because the inference does sometimes come true.

A missing price is not a discontinued product

Cursor’s pricing page publishes an entry price per group rather than a price per tier: one “$20 / mo.” over Pro, Pro+ and Ultra, one “$40 / user / mo.” over Standard and Premium. Those cards carry no placeholder and no loading state. So a missing per-tier price is a layout choice, and nothing is failing to render. It isn’t a discontinuation notice either. Cursor Start and Cursor for iPad aren’t listed at all. Whether Start was withdrawn or is geo-gated to visitors in India can’t be determined from outside India, so leave it unconfirmed. Hebbia is a different case and shouldn’t be filed with Cursor. hebbia.com/pricing returns “Failed to load page data from Contentful.” and no price at all. That page is broken, not minimal, and you can’t even tell whether a price was ever published there. Now look at the field. Harvey, Sierra, Glean, Hebbia, Abridge and OpenEvidence publish no usable price between them. Harvey’s and Sierra’s pricing addresses are 404s. Cognition is the only vendor here with a full published list. And neither cursor.com/pricing nor cursor.com/enterprise states a seat minimum for Teams or Enterprise, so that’s a question too. Three habits follow. Don’t diagnose a vendor’s page from what you expected to see on it. Tell a broken page apart from a deliberate one. And get any tier you intend to buy confirmed in a written quote, because on this map a written quote is usually the only price that exists.

Valuation is not fit

A famous, well-funded tool can still be wrong for your one workflow. Evaluate on your job, not on the funding round.

VendorPublished position on training, in its own termsRetention period published
HarveyNo use of inputs, outputs or uploaded documents to train underlying modelsNo. Logs only, 1 to 10 years
HebbiaDocuments, prompts and outputs never used to train Hebbia or any model provider it works withNo
SierraData used only as instructed, never shared with other customersNo
CursorNo training when Privacy Mode is enabled; Privacy Mode is opt-in, so the default is not privateNo
CognitionMay train by default; paid plans can opt out at any time; Enterprise requires express prior written consentYes. Duration of the customer relationship
OpenEvidenceQuestions and prompts may be sold to third parties or otherwise monetized as a commercial data feedYes. Up to one year after account deactivation
GleanNot stated on any page a buyer can open without a browserNot published
AbridgeBehind an access request in the trust centerBehind an access request in the trust center
Before you buy a vertical toolWhat to checkWho owns it
It wraps a frontier modelWhich model, and how fast the vendor adopts the next oneTechnical evaluation
It touches sensitive dataWhere data is stored and processed; compliance certificationsSecurity and legal
It overlaps tools you ownThe exact gap versus your existing general assistantBudget owner
It arrives through another vendorWhose permission model, terms and audit trail apply in that surfaceSecurity and procurement
It embeds deeplyData export and migration path if you leaveProcurement
It produces work of recordHuman review of every filing, diff, note or customer actionThe professional of record
It may be acquiredChange-of-control terms, and what happens to price, roadmap and supportProcurement and the budget owner
9 / Sources

Where these facts come from

These vendor pages change fast, and the category consolidates fast, so verify before you act on any specific tool. Capability claims are anchored to each vendor’s own dated posts. Valuations, funding, customer counts, benchmark scores and comparative figures are as reported by the vendor and are labeled that way in the text. Two Sierra numbers get quoted alongside them: 40% of the Fortune 50 and a roughly $15.8B valuation. Neither appears on any Sierra page at all, and the body marks them as reported elsewhere rather than first-party. Now the limits, which matter more than the list. Some facts here live only on pages that carry no date and can change without notice. Glean’s connector count comes from two undated pages that disagree with each other, 250+ on the platform overview and 275+ on the pricing page, both read October 1, 2026. The absence of any Glean price, plan name or seat model comes from that same pricing page. Glean’s $300M ARR figure comes from its May 28, 2026 press release. The group-price structure of Cursor’s pricing page, and the absence of Cursor Start and Cursor for iPad from it, were read October 1, 2026. Harvey’s 200,000 professionals, 3,000 firms and teams, 70 countries and 80 AmLaw 100 figures come from its undated homepage read the same day. Cognition’s price list, training default and retention line come from Devin documentation that carries no date, read the same day; cognition.com/pricing is a 404. The 404s at harvey.ai/pricing and sierra.ai/pricing, and the Contentful error at hebbia.com/pricing, are the direct evidence that none of those three publishes a price. Confirm any of these with the vendor before you rely on them. Four pages could not be opened by anything but a person with a browser: Glean’s DPA, AI addendum and security standard are blocked by Glean’s own robots.txt, and trust.glean.com builds its content in the browser. Sierra’s and Abridge’s trust centers do the same, and Abridge gates its model cards, network diagram, pentest summary and security whitepaper behind an access request. Undated product, security and pricing pages are cited below with the date they were read. Other items referenced in the body were read on the vendors’ own channels without being separately cited: Harvey appearing as a Microsoft 365 Copilot connector in Microsoft’s August roundup, the JAMA Network content agreement of June 5, 2025 on OpenEvidence’s announcements index, Hebbia’s September 1 Daloopa post, Sierra’s release-governance, Korea and voice posts, and Cursor’s August 6 Router explainer. One habit for OpenEvidence specifically. It serves announcements from three hostnames and each refuses a different set of addresses, so a refusal from one host is not evidence that a document is missing. Try another host.

Cursor for EnterpriseCursor (Anysphere) · checked October 1, 2026 · enterprise claims and certifications · names SpaceXAI as a model provider, silent on SpaceX ownership of both companiesCursor RouterCursor · July 22, 2026 · checked October 1, 2026 · model routing modes · plan eligibility is still unverifiable because docs.cursor.com blocks automated accessAgent swarms and the new model economicsCursor · July 20, 2026 · checked October 1, 2026 · what a multi-agent rebuild actually costCursor StartCursor · July 28, 2026 · ₹649 per month India tier · checked October 1, 2026 · still absent from the rendered pricing pageIntroducing Grok 4.6Cursor · August 12, 2026 · co-released with SpaceXAI, two days before the acquisition post · the concrete answer on model supplyFiretiger joins CursorCursor · August 13, 2026 · announced the day before Cursor’s own acquisition · no terms disclosedCursor is now a part of SpaceXCursor · August 14, 2026 · the acquisition, in Cursor’s own words · no terms disclosedGit at any scaleCursor · August 18, 2026 · its closing section introduces Origin code hosting with no availability status statedRun cloud agents on machines you manageCursor · September 2, 2026 · cloud agents on infrastructure you controlIntroducing ProjectsCursor · September 10, 2026 · a coordinator agent over thousands of subagents, in beta and rolling out to all usersIntroducing Grok 4.7Cursor · September 21, 2026 · no price and no availability tier stated · defers pricing detail to x.aiGrok 4.7SpaceXAI · September 21, 2026 · served at the same price and speed as Grok 4.6: $2.00 input, $0.50 cached and $6.00 output per million tokens below 200kCursor SecurityCursor · last updated August 25, 2026 · checked October 1, 2026 · Privacy Mode is opt-in, so no training is not the default · AIUC-1, ISO 27001, ISO 42001 and SOC 2 Type II · no infrastructure in ChinaDevin is now FedRAMP High In-ProcessCognition · July 13, 2026 · checked October 1, 2026 · Class D (High) In-Process on the FedRAMP Marketplace, in process rather than authorizedIntroducing Devin 2.2Cognition · February 24, 2026 · the dated Devin 2.2 announcementDo it all with Devin: Announcing our Series ECognition · September 8, 2026 · over $2B raised at a $48B valuation, led by Andreessen Horowitz and Accel (vendor statement)Introducing SWE-2: Pushing the Pareto FrontierCognition · September 10, 2026 · a numbered frontier model, with vendor benchmark claimsWelcoming Dioxus to CognitionCognition · September 10, 2026 · the Dioxus team joins Cognition · no terms disclosedIntroducing Fusion in Devin Desktop and CLICognition · September 11, 2026 · a lead and sidekick harness for Fable and Astra (vendor efficiency claim)Cognition and AWS team up to help ambitious teams ship more, fasterCognition · September 15, 2026 · a multi-year Strategic Collaboration AgreementCognition Crosses $1B in Annualized Revenue Run RateCognition · September 25, 2026 · a vendor statement with no third-party audit · names GE Aerospace, Rivian, Rohlik and ExaDevin self-serve billingCognition · undated · checked October 1, 2026 · the only full published price list on this map · Free, Pro $20, Max $200, Teams from $80 a month, Enterprise in Agent Compute Units · cognition.com/pricing is a 404Devin documentation, full textCognition · undated · checked October 1, 2026 · the default-on training position, the paid-plan opt-out, the Enterprise written-consent carve-out, retention for the duration of the relationship and the March 2024 SOC 2 Type II dateHarvey raises at an $11 billion valuationHarvey · March 25, 2026 · the $11B valuationY Combinator-backed Benchmark joins HarveyHarvey · July 16, 2026 · third acquisition of 2026 and record Q2 ARRIntroducing Harvey IIHarvey · August 18, 2026 · checked October 1, 2026 · no availability language of any kind and no pricing · the call to action is a demo requestHarvey Partners With Everlaw to Power Evidence-Backed Legal WorkHarvey · September 3, 2026 · an MCP integration the post says the two companies are building, not one it says has shippedPost-Training RLM Agents for End-to-End M&A DiligenceHarvey · September 8, 2026 · research on agents for end-to-end diligenceThe Brief: September 2026Harvey · September 16, 2026 · the monthly shipping list · makes no mention of Harvey IIAugmenting Human Preference in Complex DomainsHarvey · September 17, 2026 · a benchmark comparison in which Astra appears as a model under evaluation · no Harvey page mentions the Astra for Law API customer relationship OpenAI announced the same dayIntroducing Agentic Search for Your Document SystemsHarvey · September 30, 2026 · generally available across iManage, SharePoint and Google Drive, in Harvey Assistant and the Word add-inHarvey SubprocessorsHarvey · last updated September 21, 2026 · names Mistral AI, Baseten, Fireworks.ai, Parallel Web Systems, SuSea and RELX alongside Microsoft, OpenAI, Google Cloud, AWS, Anthropic, ElevenLabs and DeepL, with a processing location against eachHarvey Security AddendumHarvey · last updated December 26, 2025 · audit logs retained one to ten years · sets no deletion timeframe for customer data on terminationHarvey SecurityHarvey · undated · checked October 1, 2026 · no training on inputs, outputs or uploaded documents · SOC 2 Type II, ISO 27001 and ISO 42001 · HIPAA is not mentionedIntroducing Matrix 2.0Hebbia · August 26, 2026 · the flagship upgrade · its own wording is about carrying a workflow to the finish line, not the MCP line often attributed to itWhat’s New: September Disclosure 2026Hebbia · August 31, 2026 · the actual source of the deliverables quote and the Hebbia MCP distribution quoteEvery data integration, one viewHebbia · July 10, 2026 · private documents, public filings and licensed market dataIntroducing MaxHebbia · July 30, 2026 · checked October 1, 2026 · still rolling out to a small set of firms first, never retractedHebbia ProductHebbia · checked October 1, 2026 · Matrix and Max as the two headline products, Skills shown as a Max capability, no availability designation on MaxHebbia SecurityHebbia · undated · checked October 1, 2026 · documents, prompts and outputs never used to train Hebbia or any model provider it works with · SOC 2 Type 2, ISO 27001:2022 and GDPR · no retention period and no subprocessor listHebbia PricingHebbia · undated · checked October 1, 2026 · renders “Failed to load page data from Contentful.” instead of a price · a fault, not a published positionThe intelligence era is here: efficient, governed, and proactive AI powered by enterprise contextGlean · August 26, 2026 · the platform post that opened the six-post launch waveGlean Agents can now work independently, build faster, and stay governed at scaleGlean · August 26, 2026 · agents at scale, from the same launch waveIntroducing Glean Transform, your company’s mission control for AI transformationGlean · August 26, 2026 · announced as an early preview and listed “Coming soon” · still not available, and glean.com/products/transform is a 404Right-sizing intelligence: Glean saves 81% on token costs and is preferred 78% of the time versus Claude CoworkGlean · August 26, 2026 · the 81% and 78% figures, Glean’s own claims about a named competitorGlean interactive artifacts: bring any idea to life, grounded in your enterprise knowledgeGlean · September 9, 2026 · shipped and available the same day, with vendor usage figuresIntroducing agent identityGlean · July 15, 2026 · scoped service credentials for agents · public beta, and no first-party page states general availabilityGlean joins OpenAI’s B2B marketplace as a launch partnerGlean · September 29, 2026 · eligible enterprise customers can apply part of an OpenAI commitment toward qualifying partner products · states that Glean Assistant and Glean Agents run on the GPT-6 familyGlean release notes, September 3, 2026Glean · September 3, 2026 · a dated, stable per-release page · records Claude Fable 5.1 arriving in Assistant and AgentsGlean release notes, September 15, 2026Glean · September 15, 2026 · GLM-5.3, GLM-5.3 Flash, Kimi K3 and DeepSeek V4.1 Flash, plus 284 new vendor MCP server templatesGlean release notes, September 22, 2026Glean · September 22, 2026 · Claude Opus 5.5, GPT-6 Sol and GPT-6 Luna, plus 182 new MCP server templates · OpenAI superseded GPT-6 Sol with GPT-6.1 Sol on September 29Glean release notes, September 24, 2026Glean · September 24, 2026 · the only first-party page that names Glean plans, as Enterprise Flex and Glean Core SuiteGlean release notes, September 29, 2026Glean · September 29, 2026 · Claude Sonnet 5.5, PowerPoint export for HTML slide decks, IdP group spend limits on by default and 67 more MCP templatesGlean agent identity, admin overviewGlean · last updated September 30, 2026 · still carries the banner that the feature is in beta and may change · states that the agent runtime never receives the raw secretGlean SubprocessorsGlean · last updated July 28, 2026 · 21 named entities including Anthropic, OpenAI, Snowflake, Baseten, Fireworks.ai, Groq, Modal Labs, Brave, Deepgram, Exa Labs and Palo Alto NetworksThe next Horizon in agentsSierra · July 16, 2026 · long-horizon goals, priced on outcomesAgency: Secure, scalable sandboxes for agentsSierra · July 29, 2026 · sandboxes for agentsHyper-tau-bench: evaluating agents that build agentsSierra · September 8, 2026 · an open-sourced evaluation frameworkNext gen multimodal agents: an interface that morphs with the conversationSierra · September 10, 2026 · voice, text and visuals in one conversation, with MCP UI componentsSierra achieves AIUC-1 certificationSierra · September 17, 2026 · an independent audit by Schellman, per Sierra · the same certification Cursor announced on August 13Sierra ProductSierra · checked October 1, 2026 · outcome-based pricing described in prose, with no rate card published anywhere · names Ghostwriter, Explorer, Agent Studio, Horizon, Context Engine, Insights and ChannelsSierra joins the OpenAI MarketplaceSierra · September 29, 2026 · eligible customers can build agents with Sierra using their OpenAI commitments · the only published mechanism by which a buyer can pay SierraSierra Trust and reliabilitySierra · undated · checked October 1, 2026 · data used only as instructed and never shared between customers · lists SOC 2, HIPAA, GDPR, PCI, FedRAMP High, CCPA, CSA STAR, ISO 27001 and ISO 42001 · does not list AIUC-1Abridge welcomes the Altrina teamAbridge · July 20, 2026 · agents and EHR workflow automationWashU Medicine and BJC Health Bring Abridge to 4,000 CliniciansAbridge · September 2, 2026 · a customer deployment, published on the press pageAbridge Extends Intelligence to CDI and Coding Teams, Reviewing Inpatient Claims Before They’re SubmittedAbridge · September 14, 2026 · a capability launch, not customer contentAbridge ProductAbridge · checked October 1, 2026 · five product lines on the Contextual Reasoning Engine · no price published anywhereAbridge Selected to Bring Ambient AI to Veteran Care Nationwide Through the VA Enterprise ContractAbridge · September 22, 2026 · a five-year multiple-award vehicle with a $775.72 million ceiling across all eligible vendors, which is not Abridge’s award · already live at more than 75 VA medical centersOpenEvidence Privacy PolicyOpenEvidence (published by Xyla Inc.) · effective April 1, 2024 · checked October 1, 2026 · says user data including questions and prompts may be sold or otherwise monetized as a commercial data feed, and that user inputs are not covered by HIPAA · retention up to one year after account deactivationOpenEvidence is now HIPAA compliantOpenEvidence · April 25, 2025 · states the service is fully HIPAA compliant · read it against the privacy policy above and establish in writing which one governs your organizationOpenEvidence and NEJM Group Sign Content AgreementOpenEvidence · February 19, 2025 · the content agreement itself, which is a different thing from being featured by NEJM AIOpenEvidence Announces $210 Million Round at $3.5 Billion ValuationOpenEvidence · July 15, 2025 · also the first-party record of the DeepConsult physician agent · the most recent funding announcement on the index, which carries nothing dated 2026OpenEvidence AboutOpenEvidence · undated · checked October 1, 2026 · states the service is free and universally accessible · no pricing page, seat model or named enterprise plan exists anywhere first-partyIntroducing Astra for LawOpenAI · September 17, 2026 · names Harvey as an Astra for Law API customer, a relationship no Harvey page statesIntroducing GPT-6.1 SolOpenAI · September 29, 2026 · supersedes GPT-6 Sol, which Glean added on September 22Claude Fable 5.1 and Claude Mythos 5.1Anthropic · September 1, 2026 · the launch, and the 30-day retention requirement on Anthropic’s direct terms

AI Mindset

Explore the model cheatsheets