AI

The Economics of Scale and the Danger of Silence: Cybersecurity AI’s Two Potential Breaking Points

Martin Holste

By: Martin Holste

7 min read

AI can help security teams investigate far more alerts, but scaling that capability may replace human alert fatigue with an expensive new problem: inference and token costs. At the same time, some of the most dangerous threats may generate very little noise, remaining dormant until the moment they can cause maximum damage. The article argues that smaller, local and sovereign AI models could make large-scale security analysis more economical while keeping sensitive data under greater control.

[For more news, click here]

We’ve all heard the pitch: AI can investigate more security alerts than any human team. While true, this risks positioning AI as the surefire fix, while overlooking critical considerations. For example, what happens when the technology designed to absorb the pressure becomes overwhelmed itself, or when the most dangerous threat generates almost no noise at all?

For years, the problem with security alerts has been that there are simply too many of them. Security teams learned to live with that reality through a pragmatic trade-off: investigate what looks most important, suppress or defer the rest, and accept that some signals will inevitably go unseen. That compromise made sense when the alternative was asking overstretched analysts to investigate everything.

The threats we’re seeing now expose weaknesses at both ends of that spectrum. Some attacks are dangerous because they arrive at such scale that even the systems built to help investigate them become overwhelmed. Others are dangerous because they remain quiet and unnoticed until the moment an attacker chooses to act. AI can help address both problems, but only if organizations can deploy it economically and trust it to act safely.

Silver Bullet or Spending Spiral?

The security incident disclosed by Hugging Face earlier this year is a striking illustration of the first problem and a useful corrective to how the industry talks about AI and alert volume. During its investigation, the company tried using commercial frontier models to analyze large volumes of attack commands, exploit payloads, and command-and-control artifacts. The models’ own safety controls treated the investigation queries as potentially malicious and blocked them, prompting Hugging Face to move the forensic work to an open-weight model running on its own infrastructure.

We’ve spent years hearing that AI will help security teams deal with alert volume. It isn’t that simple. AI introduces a scaling problem of its own: if the number of investigations increases dramatically, the limiting factor may no longer be how many alerts an analyst can read, but how much inference an organization can afford to run.

This matters because AI economics differ from the economics of human attention. A security team might previously have decided that investigating one-fifth of its alerts was the only practical option. If AI makes it possible to investigate all of them, that sounds like progress—until the organization discovers that doing so consumes an unsustainable number of tokens or amount of computing power. We risk solving alert fatigue only to create token fatigue.

Security models can’t simply be judged on whether they reach the right answer. They have to reach it repeatedly, at enormous scale, without turning every spike in malicious activity into an unexpected cloud bill. This is one reason local and smaller models are becoming more interesting: not every investigation needs frontier-level reasoning, and repetitive or highly contextual work often suits a model operating locally against an organization’s accumulated knowledge and with a different cost profile.

It also brings the sovereign AI conversation directly into security operations. Keeping sensitive security data, organizational context, and AI workloads within infrastructure controlled by an organization or jurisdiction can address questions of data sovereignty and control alongside those of cost. The question is no longer whether AI can investigate an alert, but whether it can investigate the next million economically.

Silent, Then Suddenly Severe

If Hugging Face shows what happens when there is too much to examine, the opposite failure is just as instructive: what happens when nobody looks at all? The recent attack on Canvas illustrates this well. It unfolded at an especially damaging moment, as schools and universities were approaching, or in the middle of, final examinations, turning activity that might otherwise have appeared only in low-priority alerts into an operational crisis.

The broader lesson isn’t specific to Canvas. Attackers don’t need a constant stream of alarms to cause significant damage. A threat that gains access, stays quiet, and waits can be just as dangerous as one that triggers dozens of high-severity alerts, and may be harder to detect precisely because security operations are conditioned to prioritize what demands attention now. In short, attackers can exploit the shelf life of defensive attention.

The same logic applies to a threat that may take years to materialize. In a “harvest now, decrypt later” attack, adversaries can steal encrypted information today and retain it until sufficiently capable quantum computers make that information readable. The breach and the moment of exploitation may therefore be separated by years, creating another category of threat that falls outside the traditional logic of alert prioritization.

AI Must Earn the Right to Act

If economics presents a financial roadblock to adopting AI to address the alert challenge, confidence presents the cultural barrier. Security teams have traditionally given software tightly defined instructions: if a condition is met, perform an action. Increasingly capable AI systems instead operate in a world of incomplete information and probabilistic reasoning. Asking an AI to quarantine a machine is very different from asking it to determine whether that machine is a disposable laptop or a critical system running operational technology on an oil rig.

The distinction isn’t about general confidence, but confidence in the specific facts on which a decision depends. If the AI knows that a machine is compromised but not what kind of machine it is, that uncertainty should matter before it takes an irreversible action. This points toward a different model of AI governance: confidence should be demonstrated, not declared. The system should show the evidence behind a decision, flag where its knowledge is incomplete, and distinguish actions that can easily be reversed from those that could disrupt a business.

That could change how autonomous security systems earn permission to act. An AI might initially make only recommendations while its decisions are observed, progressively earning execution rights as confidence in its performance grows and gaps are corrected. The objective isn’t to make AI infallible, but to make its reasoning transparent enough, and its actions sufficiently bounded, that humans know when they can safely let go.

The New Reality of Security Attention

We’ve spent years asking how security teams could examine more alerts without burning out. AI may finally make that possible, but it forces us to confront two questions we haven’t had to answer at this scale: How much does it cost to examine everything, and how much do we trust what we find?

The trouble with alerts was never simply that there were too many. At one end of the spectrum, the most dangerous signal may be the one nobody considers urgent. At the other, it may be the flood that makes meaningful investigation impossible. True cyber resilience depends on being able to withstand both extremes, maintaining the ability to identify, investigate, and respond even when threats arrive at an overwhelming scale or remain dormant for extended periods.

The challenge now is recognizing that solving one end of the spectrum cannot come at the expense of the other or simply move the bottleneck from analysts to tokens to trust.

Contributed by: Martin Holste, Chief Product Architect at Trellix

Martin Holste is Chief Product Architect at Trellix, where he focuses on the application of AI, cloud technologies and automation to cybersecurity operations. He previously served as Trellix’s CTO for Cloud and AI and has been closely involved in the company’s work around generative AI and AI-powered security operations. His work explores how organizations can deploy AI in security at scale while balancing cost, trust, governance and operational resilience.

Related Articles:
Exclusive: Hyperscalers Signal Rising Confidence in AI Multi-year Growth Cycle 

Exclusive: Yousef Barkawie on the Next Phase of AI in the Middle East

AI Is Moving Into the Systems That Keep Government and Industry Running

Share this article

Related Articles