The Attacker Writes Your Security Budget Now
Everyone selling AI-powered security is pitching the same graph: attacks go up, your agent scales to meet them, you sleep at night. Nobody's drawing the second line on that graph — the one where your bill scales with the attacks too. And here's the part that should stop you cold: the attacker controls the x-axis. When you meter defense by the token, you've handed the person trying to break in a dial that sets what you pay to keep them out.
Start with a number that made the rounds this month. Palo Alto Networks pointed Anthropic's Claude Mythos at its own source code and let it hunt. The model found more than two dozen critical vulnerabilities — a genuinely strong result, exactly the kind of thing that sells the agentic-security story. It also burned through more than a million dollars in tokens doing it. Sit with both halves of that. The defense worked and it cost a million dollars for one pass over one codebase. Now imagine that as your standing operational posture instead of a one-time experiment.
The pricing model changed the physics
Old security economics were boring, and boring was the feature. You bought an appliance, licensed a scanner. The cost was fixed, sunk, and known — a line item you set once a year and forgot. Attacks could triple overnight and your spend didn't move, because the machine doing the defending cost the same whether it inspected ten packets or ten billion. Defense was a fixed cost in front of a variable threat, and that mismatch was quietly the thing that made security budgetable at all.
Agentic AI deletes that property. A generative model answering a prompt has bounded cost — a human's sitting there, typing the next thing, the meter running at human speed. An agent has no such governor. It loops. It calls tools, reads the results, decides to call more, chains a dozen steps to run down a single lead. As a SecurityWeek piece put it plainly at the end of June: machine-learning detection costs you CPU cycles you already own, generative AI costs you bounded tokens, and agentic AI costs you unbounded tokens. That's not a pricing footnote. It's a phase change — defense moved from a fixed cost to a variable one, and variable costs have whatever ceiling the workload imposes.
Then ask the question the vendors skip: who sets the workload?
Denial of wallet
The attacker does. That's the whole trick, and the industry already has a name for it — denial of wallet. Old-school DoS crashes the box. This leaves the box running perfectly and drains the account behind it — defenses green across the board, doing exactly what they were built to do, while the bill detonates.
The mechanism is almost elegant, which is the part I can't stop turning over. A study out this year — Beyond Max Tokens — showed you can nudge an AI agent into a runaway tool-calling chain that inflates the cost of a single query by up to 658 times while the task still completes successfully. Read that again: the agent isn't broken, it isn't fooled into a wrong answer, it does the job — it just does it 658 times more expensively because someone shaped the input to make it thrash. Point that at a defensive agent and you don't need to beat it. You need to make winning cost more than the win is worth.
And this isn't theory waiting for its first victim. Sysdig has tracked the crude version for a while — LLMjacking on stolen cloud credentials clocking $46,000 a day against AWS Bedrock, a lifted Gemini key running up $82,000 in 48 hours. Those are just the smash-and-grabs using your keys directly. The subtler play doesn't need your credentials at all. It needs your defensive agent pointed outward and a stream of traffic crafted to make it burn its most expensive reasoning on garbage. The attacker pays pennies for the tooling that generates it. You pay per token to have your model take every piece of bait seriously.
The asymmetry, again — but on the money side this time
I've argued before that AI didn't hand offense a superweapon — it sped up both sides equally, and the slow human patch cycle in the middle became the real exposure. This is the same asymmetry wearing a different coat. Run the inversion Munger would run: don't ask how to detect more, ask what guarantees you bleed out even when detection works. The answer is a defense whose cost is unbounded and whose volume is set by the adversary. You can be right every single time and still lose, because being right has a per-unit price and the other guy controls the units.
That's the structural rot under the "just add an AI agent" pitch. It silently assumes the cost of defending is yours to control. It isn't anymore. The instant your security posture is metered by consumption, your budget becomes an attack surface — arguably the softest one you've got, because it's the one nobody threat-models. There's no CVE for "our SOC agent is economically DDoS-able." There's a finance meeting in Q3 where someone asks why the security line quadrupled, and the honest answer is an attacker decided it should.
None of this argues against AI in defense. The capability is real and you'll need it, because the offense already has it. It argues for treating the meter as a control surface with the same seriousness you'd give a firewall rule. Cap it. Budget the agent like a junior analyst who might loop forever on a bad ticket — because that's exactly what it is. Assume some fraction of your inbound traffic exists purely to make your defenses expensive, and build the governor before the attacker finds out you didn't.
The old question was whether your defense could stop the attack. The new one is whether you can afford for it to keep trying. Those aren't the same question, and the second one has a dollar sign where the answer used to be.
A defense you can't afford to run isn't a defense. It's a subscription the other side gets to cancel by spending it for you.
— Dustin