The Real Cost of an AI Security Line Is the Control It Replaces
AI security spend should be judged against the control it displaces, not against a fictional baseline where the same budget was doing nothing.
Proof of Value Is the Wrong Isolated Test
Dark Reading, 16 September 2026, described AI security spending rising ahead of clear evidence that the tools deliver measurable protection. Infosecurity Magazine, 15 September 2026, reporting IANS research, added the more important constraint: AI has become the dominant destination for net-new cybersecurity spending while total security budgets remain flat. Those two observations change the investment question.
In a growing budget, a new control can be tested against the incremental value of spending more. In a flat budget, the question is harsher. Every net-new AI dollar is also a dollar removed from another control, process, assessment, platform, exercise, or response capability. The relevant comparison is not AI security versus zero. It is AI security versus the specific reduction in annualized loss exposure that is weakened, delayed, or abandoned elsewhere.
That is why “proof of value” is an incomplete demand when applied to AI security in isolation. A control can have value and still be the wrong marginal allocation. Another control can be boring, old, and poorly marketed, yet still reduce more expected loss per unit of budget. Conversely, an AI control can look speculative and still be justified if the displaced line was producing less risk reduction than assumed. The disciplined question is comparative, not theological.
Classical annual loss expectancy uses ALE = ARO x SLE, a formulation associated with the NIST SP 800-30 and CISSP lineage. A quantitative cyber risk management methodology refines that into risk as loss event frequency times loss magnitude. Loss event frequency is threat event frequency times vulnerability, where vulnerability is the probability that a threat event becomes a loss event, based on threat capability against resistance strength. Frequency and magnitude are treated as probability distributions and simulated through Monte Carlo simulation, producing a range rather than a single point estimate.
That model matters because AI security business cases often blur which variable is actually being moved. Threat event frequency is how often a threat acts against an asset. Resistance strength affects whether those events become loss events. Detection and response may reduce vulnerability, reduce loss magnitude through faster containment, or both. A claim that a tool “reduces risk” is not yet a risk claim. It becomes one only when it says which term changes, in which direction, and with what uncertainty.
The Missing Cost Term
Return on security investment is often expressed, following CISA and several organizations, as ROSI = (ALE x Mitigation Ratio – Cost of Control) / Cost of Control. In simpler operational language, it asks how much expected annualized loss is reduced for the budget spent. That is useful, but it can be misleading when the budget is zero-sum.
Standard ROSI treats the cost of control as money. In a flat budget, the real cost also includes the loss reduction forgone somewhere else. That opportunity cost is not measured in currency. It is measured in annualized loss exposure that returns to the portfolio because another line is cut, capped, or under-maintained.
This is where both AI enthusiasts and AI skeptics often argue past each other. The enthusiastic case shows what the new AI control might reduce. The skeptical case asks whether that reduction is proven. Both can miss the portfolio question: what risk reduction is being surrendered to pay for it? If the displaced line was weak, poorly evidenced, or no longer aligned to the threat environment, the AI proposal may clear the hurdle even with uncertainty. If the displaced line was quietly suppressing high-frequency loss events or materially reducing loss magnitude, the same AI proposal may fail even if it works as advertised.
The practical comparison is marginal. Estimate the simulated annualized loss exposure before the reallocation. Estimate it again after adding the AI line and reducing the displaced line. Then report how often the reallocation improves the portfolio across the simulation. A single ROI figure hides the very uncertainty that matters most.
This framing also prevents a common practitioner error: confusing threat event frequency with loss event frequency. Fear-driven spend is not irrational by definition. Threat perception can be information about threat event frequency. A new adversary technique, changing attacker economics, or increased exposure can justify revising the frequency distribution. But threat perception is not automatically evidence that a proposed AI control improves resistance strength, lowers vulnerability, or reduces loss magnitude. The model has separate terms for a reason.
The Displaced Control Needs Evidence Too
The most uncomfortable part of the comparison is that the incumbent control also has to be measured. Many legacy controls survive because their value is assumed. They have an objective, a policy statement, a maturity rating, a renewal history, and perhaps a dashboard. None of that is the same as demonstrated risk reduction.
Infosecurity Magazine, 15 September 2026, reporting Fenix24, gave a useful reminder: of more than 800 clients, only four came close to achieving their stated ransomware recovery targets of 24 to 48 hours. The point is not to generalize that result beyond its stated context. The point is that stated control objectives and demonstrated performance can diverge sharply.
That observation cuts against lazy AI adoption, but it also cuts against lazy preservation of the status quo. A recovery capability that exists on paper may not reduce loss magnitude as much as the business case assumes. A detection process with impressive alert counts may not materially change vulnerability if escalation is slow or containment is inconsistent. A training program may be credited with changing user behavior without evidence that it changes loss event frequency. A vulnerability management line may be funded as if remediation translates cleanly into lower exploitability, even where prioritization and asset coverage say otherwise.
The same evidentiary discipline should apply to the proposed AI line and the line it displaces. The AI proposal should identify the model term it affects. If it claims earlier detection, the effect may appear as lower vulnerability for certain threat events or lower loss magnitude through faster containment. If it claims better prioritization, the mechanism may be improved resistance strength because scarce remediation capacity is aimed at exposures that matter more. If it claims deterrence, that is a threat event frequency claim, and those are usually harder to substantiate for a single defensive control.
The displaced line needs the same treatment. Its effect should be estimated from observed performance, not from the stated objective. Control owners and operational records matter here because the inputs are local: incident timelines, containment intervals, test results, backlog patterns, exception volumes, recovery exercises, coverage gaps, and actual decision latency. The model supplies the comparison discipline, but the performance signal must come from how the control actually behaves.
Portfolio Discipline Beats Control Theater
A better AI security investment memo would not ask whether AI is promising or overhyped. It would show the portfolio trade.
The memo would express the new AI line as a distribution of change in simulated annualized loss exposure per unit of spend. It would express the displaced line in the same unit. It would name the model term each control moves and separate threat event frequency from vulnerability and loss magnitude. It would make uncertainty visible instead of compressing it into a single return figure. Most importantly, it would compare the AI line against the specific control it replaces, not against doing nothing.
That approach is stricter than demanding “proof of value” from AI alone. It asks whether the reallocation improves the portfolio after accounting for opportunity cost. It also makes room for evidence that is imperfect but decision-relevant. Security investment rarely comes with laboratory certainty. The question is whether the available evidence changes the simulated loss distribution enough to justify moving scarce budget.
This is the uncomfortable discipline of flat-budget security. New controls do not enter an empty room. They enter a portfolio already full of assumptions, some measured and some inherited. AI security spending may be proactive and still be rational. It may be fashionable and still be wrong. The difference is not settled by enthusiasm or skepticism. It is settled by comparing the risk reduction bought with the risk reduction given up, in the same unit, under the same uncertainty, across the same simulation.