Projected Cyber Security Costs from Frontier AI

A response to Tyler Cowen — sealed August 10, 2026 · C. Fable & B. Carson · doi:10.5281/zenodo.21879325

Start hereWhat this page is, in plain English

This site answers one question: how much extra will cyberattacks cost the world in 2027 and 2028 because of AI — on top of what those costs were already going to be?

To answer it, we ran many thousands of simulated futures, built from published data plus clearly-labeled judgment calls — every one of them written down and locked on August 10, 2026, before any results were computed, so nothing could be quietly adjusted afterward.

Two headline numbers sit just below. The median is what a typical year looks like; the mean is the average once rare catastrophic years are counted. The mean is much larger, and that gap is the main finding: most of the expected cost comes from a small chance of disaster, not a steady drumbeat.

Anything with a dotted underline explains itself when you hover over it (tap it on a phone). And every assumption here is adjustable — if you would have chosen differently, move the sliders and watch the answer change.

Headline · 2028 · sealed reference spec

The predictive distribution simulation pending

Excess global cost attributable to frontier AI, calendar 2028, under the sealed reference specification: log-linear counterfactual × full 2015–2024 window, regime weights 30/45/25, Channel-4 posture Moderate, systemic stratum pooled across variants A (anchored) and B (fresh) with equal weight (D-04). The median–mean wedge is the headline finding: the median tells you the modal year, the mean tells you what the tail costs.

Typical year (median)
half of simulated 2028s land below this · median Δ, $B
Average year (mean)
pulled up by rare catastrophes · mean Δ, $B
Median–mean wedge
what the tail adds, $B
Chance the AI-caused increase tops $100B
P(Δ > $100B) · the “material but manageable” line

Reference spec always quoted with the min–max range across all nine counterfactual cells (D-12b): range pending. Resource-vs-transfer split (D-09): pending.

Interactive

Every parameter is a knob

The sealed defaults below are Brad Carson's dated beliefs (Aug 10, 2026). Disagree? Move the sliders — the full distribution recomputes in your browser from the simulator's per-regime draws. Nothing is hidden behind a point estimate.

Regime mixture knob

Sealed: 30% offense / 45% balanced / 25% defense (D-07)
Offense 30%
Balanced 45%
Defense 25%

Channel 4 posture knob

Sealed: Moderate — triangular $2B / $12B / $60B (D-13)

Counterfactual cell knob

Sealed reference: log-linear × full 2015–2024 (D-05, D-12b). Structural form breaks at 2026Q2 (D-12c).
Full 2015–24ex-COVIDShort 2018–24

Exceedance thresholds knob

Sealed: $25B · $50B · $100B · $200B (D-06 — committed before any code ran)

Your distribution

sealed spec
Median
Mean
Wedge
P90 / P99
simulation pending The Python simulator has not produced out/results.json yet.
Drop its contents into the RESULTS object and everything lights up.
LevelChance the increase ends above it

Placebo check (D-12): measured excess over 2025Q1–2026Q1 — out-of-sample but pre-break — should be ≈ 0 for this cell. Value: pending.

Structure · caps & safeguards

Two knobs the browser can't turn — and where defense lives

The two sealed choices below are real, named knobs in the published code, but they cannot be recomputed on this page: they change the simulated paths themselves, not how the stored draws are re-mixed. They are documented here as loudly as the live sliders — turning either one requires re-running the published code (see repo).

Annual aggregate cap knob re-run required

Sealed: Central $3.5T/yr · S2 per-event cap $250B · tail-shape prior ξ 0.65 / 0.95 / 1.45 (D-14)
Why the cap is a loud knob: the published tail-index literature puts cyber dollar losses in infinite-mean territory (the ξ prior reaches 1.45). With such tails the simulated mean does not exist without truncation, so the cap choice partially determines E[Δ] — readers who think our mean is too small or too large should turn this knob first.
Changing the cap requires re-running the published code (s3_annual_cap_busd, s2_cap_busd, xi_prior) — see repo. Every number on this page is the sealed $3.5T run.

Post-event safeguard damping knob re-run required

Sealed: damping factor prior 0.5 / 0.7 / 0.9 (min/mode/max) · trigger $50B simulated 2027 systemic loss (D-15)
If a simulated 2027 crosses the $50B systemic-loss trigger, that path's 2028 AI multipliers and S3 probabilities are damped toward baseline: safeguard intensity responds to realized events. Anchor: the Hugging Face near-miss — no recoverable loss, yet within weeks a research slowdown, agent-authored security fixes in deployment, and a UK AISI incident report.
Trigger fired
14.4%
of 2027 paths
2028 mean w/o it
+$8B
damping forced off
2028 P99 w/o it
+$56B
damping forced off
Trigger frequency (14.4%) is from the full sealed run; the +$8B / +$56B isolation numbers are from a matched-seed reduced-draw comparison (2,000×2,000, anchored variant, common random numbers), in which the trigger fires on 6.0% of paths.
The loop creates negative autocorrelation between 2027 and 2028, thins the two-year cumulative tail, and makes “muddle through” partly endogenous rather than assumed.
Changing the prior or trigger requires re-running the published code (safeguard_damping, damping_trigger_busd) — see repo.

Where is defense in this model?

A common objection: “new safeguards will be deployed — your model ignores them.” It doesn't. Defense is priced in four places (D-15):

  1. The estimand nets out deployed defense by construction. Δ is an equilibrium excess-cost outcome (D-02): whatever defense actually gets deployed in 2027–28 is already reflected in the realized spend and loss series being measured against trend.
  2. Explicit defense parameters. Severity-truncation haircuts, containment probability, patch-race odds (sealed at 20%), containment cycle time — and the regime mixture is the safeguard-effectiveness uncertainty: “defense-dominant” is the world where safeguards win.
  3. Successful safeguards shift cost — they don't zero Δ. Blocked attacks still cost money: cost moves from Channel 2 (realized losses) to Channel 1 (defensive spend) and Channel 4 (compliance/friction). That is exactly why all channels are measured rather than losses alone.
  4. The post-event damping loop (left): safeguard intensity responds to realized events — a bad simulated 2027 damps 2028's deviation from baseline.
Stress tests · reference spec

What moves the number — and what would falsify it

Sensitivity tornado — swing of the 2028 mean

Each bar answers a question: if this one assumption is set to its low guess (P10) or its high guess (P90), how much does the 2028 mean move? Longer bar = more influential assumption (reduced-draw reruns around a $235B baseline). Top 8 of 60 parameters; hover a bar label for the technical name.

The count of everyday cybercrimes dominates the mean: the widest bars are all versions of one question — how much will AI multiply the number of routine scams, frauds and ransomware attacks (the S1 frequency multiplier)? The answer moves far more on how many incidents happen than on how bad each one is. “Defense shrinking losses” is where safeguard effectiveness pushes back.

Model vs the ILS market Channel 3 · $0 to headline

Matterhorn Re attaches at $9B US insured loss; the cat-bond market prices that at 2.23% a year. Converting the model's AI-world 2027 distribution through modal economic-to-insured (7.1:1) and US-to-global (2.45×) ratios:

Model · anchored
9.1%
P(attach)
Model · fresh
15.1%
P(attach)
vs market
4.1–6.8×
model / market

This check is pure validation — the confrontation is published instead of tuned away: either the model's tail is too fat or the market is underpricing agentic risk — PoleStar 2026-1 priced at/below guidance with no post-Hugging-Face repricing, so the wedge between technical indicators and softening rates is itself a finding.

The placebo says the counterfactual overpredicts — published anyway

The pre-committed falsification check (D-12): the quarters 2025Q1–2026Q1 are out-of-sample but pre-break, so measured excess there should be ≈ 0. It isn't. The reference cell reads −$37B/yr, and all nine cells are negative (−$19B to −$61B/yr): every pre-2025 trend family overpredicts 2025, because measured growth decelerated in 2022–25 relative to 2015–21. The bias runs in the conservative direction — a baseline that overpredicts understates the 2027–28 excess this page reports. Published per pre-commitment; sealed parameters untouched — only the trend family is on trial here.

CellPlacebo excess ($B/yr)90% band
Elicitation

Where would your weights land?

The regime weights are the epistemic prior over which world we're in for 2026–2028 — one of the three or four most consequential numbers in the paper. Before you drag sliders by feel, answer the three questions the weights were actually elicited against (analysis D-07 §6). Brad's sealed answers are shown alongside.

1 · By end-2028, do agentic-signature incidents (ephemeral-VM swarms, self-relocating infrastructure) make up a growing or shrinking share of major incidents?
Brad, sealedGrowing. (→ offense weight ≥ 30%.)
2 · What probability that median enterprise patch latency beats median exploit-development latency by 2028?
50%
Brad, sealed20%. Initial intuition was yes (self-described as weakly held); revised on rebuttal and confirmed. (→ defense weight ≤ 25%.)
Show the reasoning behind the revision
Mandiant M-Trends shows average time-to-exploit collapsing from ~63 days (2018–19) to ~32 days (2021–22) to single digits by 2023–24 — a compression that predates frontier AI. The majority of exploited vulnerabilities in recent years were exploited as zero-days, i.e. before any patch existed to deploy. Meanwhile median enterprise remediation for critical vulnerabilities remains ~30–90 days, and the binding constraint is institutional deployment — testing, change windows, legacy systems — not patch authorship. That is the wrong bottleneck for AI to fix at the median enterprise, even where agentic auto-remediation flips the frontier. Closing a ~10× gap in two years against an institutional bottleneck ≈ 20%.
3 · Forced to bet on the sign of Channel 1's (defensive-spend) deviation from trend in 2028: above trend (arms-race spending) or below (unit-cost deflation)?
Brad, sealedAbove trend. OpenAI's Black Hat USA 2026 presentation on the Hugging Face incident signals materially higher security spend; cross-currents noted but net above. (→ defense-dominant ≤ 25%.)
Show the sealed token-price caveat
Falling token prices deflate the unit cost of AI offense and AI defense alike, so cheap tokens are approximately neutral on the race while deflationary on the spend level — BUT this symmetry is not guaranteed: it may be that offensive cyber operations require expensive frontier-tier models while defense runs adequately on cheaper ones (or the reverse). Tier asymmetry would break race-neutrality; noted in the paper as an explicit caveat.

Suggested weights from your answers

Offense-dominant
Balanced
Defense-dominant

Brad's sealed weights (Aug 10, 2026)

Offense-dominant30%
Balanced45%
Defense-dominant25%

Mapping (documented, deliberately coarse — a starting point, not an inference): offense = 20 + {growing +10 / flat 0 / shrinking −10}; defense = 20 + (Q2 ÷ 4) + {below-trend +5 / above-trend 0}; balanced = remainder; all clamped to ≥ 5% and renormalized. Brad's sealed answers (growing, 20%, above) reproduce his sealed 30/45/25 exactly.

Transparency

Decision registry — every choice, and the roads not taken

Every methodological decision, logged as it was made, with alternatives and rationale. knob = a parameter you can change above and re-run. structural = baked into the code architecture — still forkable, but not a slider.

Method in brief

How the number is built

The design is the excess-mortality template from epidemiology, transplanted to cyber (D-01): fit pre-2025 baselines per channel, measure post-period deviations, and attribute the AI share via signature statistics — time-to-exploit compression, social-engineering efficacy, agentic-architecture incident counts. No cross-sectional asset-pricing coefficients, no salience-contaminated text indices.

Four channels, strict accounting (D-02): Δ = Δ₁ defensive spend + Δ₂ realized losses + a bounded Δ₄ friction/trust tax, each measured against its pre-2025 trend. Δ₁'s priors are symmetric — AI may deflate the unit cost of defense, so spend can come in below trend and the published distribution may straddle zero (D-10). Δ₃, risk premia in asset prices, contributes $0 to the headline: valuation effects capitalize expected Δ₁+Δ₂ flows, so adding them would double count. Channel 3 is used for timing, validation, and tail calibration only — including the ILS-market consistency check reported with the results.

The distribution is the answer (D-03): a compound frequency–severity Monte Carlo over three event strata with two uncertainty layers — an outer loop drawing parameters from priors (epistemic) and an inner loop simulating outcomes (aleatory), ~10⁴ × 10⁴ draws. The loss process is heavy-tailed (lognormal body, GPD tail near the variance-infinite region); the annual aggregate is dominated by whether a NotPetya-class-plus event occurs. That is why the median–mean wedge, not a point estimate, is the headline.

The counterfactual can't hide (D-05, D-12): all three functional forms × all three fitting windows are run and reported — the 3×3 matrix above — with log-linear × full-window as the reference cell, always quoted with the nine-cell range. The structural form breaks at 2026Q2, which makes 2025Q1–2026Q1 a built-in placebo window: out-of-sample but pre-break, its measured excess should be ≈ 0. A nonzero placebo is a misfitted counterfactual, visible to every reader.

The prior is sealed; the posterior is scheduled (D-07): at end-2027 and end-2028 the regime weights are re-scored against realized signature statistics and the posterior is published next to the sealed prior — the registered-report spirit without the journal.