Big Bad Wolf: AI Is Repricing Cybersecurity
Summary
This opinion essay argues that AI’s most important effect on cybersecurity is economic: it lowers the cost of tasks when success is easy to verify, while many defensive tasks remain expensive and uncertain to validate. The author uses bot management as an example of a security product that historically deterred attackers by making attacks more costly, while known-rule defenses such as web application firewalls remained cheaper to operate. AI can now help attackers discover vulnerabilities, write exploits, conduct social engineering, and vary automated attacks at scale; it can also analyze logs, detect anomalies, develop patches, and support other defensive tasks. The essay argues that offense retains several structural advantages. Attackers often have a cheap oracle, such as whether they gained root access or brought down a server, whereas defenders must determine whether a patch is safe, whether an adversary is truly deterred, and whether legitimate users will be blocked. Defense must protect every component and interaction, while an attacker needs only one successful breach, and AI itself adds another attack surface. Software entropy, human error, rapid AI-assisted coding, and unspecified behavior therefore continue to favor attackers. The author classifies security mechanisms as proof, probability, or price: structural guarantees, cryptographic hardness, and economically motivated defenses. AI most directly threatens the last category, including WAFs, bot management, endpoint detection, malware detection, and security operations that depend on repeatedly detecting and fingerprinting changing attacks. The essay concludes that reactive defenses and patching ecosystems may not scale when attacks become highly customized, although cheap obfuscation and related obstacles may remain useful. Its proposed long-term response is security by design: explicit capabilities, zero trust, typed interfaces, attested identity, sandboxing, reliable patches, and stronger penetration testing. The author’s conclusion is optimistic that AI can make structurally secure software cheaper to build than maintaining insecure systems.