AI is pushing cybersecurity from “optional investment” to “mandatory expenditure”. As AI lowers the attack threshold and shortens the vulnerability exploitation window, the security risks faced by enterprises continue to rise, and the importance of cybersecurity has gradually shifted from a single line item in traditional IT budgets to an indispensable component of AI infrastructure.
According to JPMorgan Chase’s latest report, the second-quarter earnings season has further consolidated analysts’ confidence in the security software sector. Analyst Brian Essex estimates, the total addressable market (TAM) corresponding to AI-driven incremental security spending over three years may exceed 4.3 trillion U.S. dollars. Compared with previous technology cycles such as cloud computing and the mobile internet, JPMorgan Chase believes that the adoption rate of this round of security demand may be faster, as enterprises are not simply pursuing efficiency improvements but facing continuously rising security risks.
This change has already been reflected in enterprise procurement and the operating data of security vendors. Multiple vendors have disclosed that the ARR, booking amount and related orders for AI security products are growing rapidly, while customer procurement models are shifting from single-point products to platform-based solutions, indicating that enterprises are integrating AI security into their longer-term IT infrastructure planning.
JPMorgan Chase predicts, a large number of current AI security projects are still in the early stage of the sales cycle, and the fundamental impact this year may be relatively limited. However, as orders are gradually converted, relevant demand is expected to accelerate starting from the fourth quarter of this year and further release in 2027.
01 AI lowers the attack threshold, bringing new pressure to enterprise security lines of defense
One of the biggest changes brought by AI is that it greatly shortens the time window between the public disclosure of a vulnerability and its exploitation. JPMorgan Chase data shows, the average vulnerability exploitation time has dropped from 63 days in 2018 to 5 days in 2023, and further decreased to negative 7 days in 2025, which means attackers may complete the weaponization of vulnerabilities before patches are released. Among the known exploited vulnerabilities, about 29% have been weaponized on or before the day of public disclosure.
Generative AI has further improved the automation of attacks. The report cites relevant cases from Anthropic, noting that its model has been able to independently search for zero-day vulnerabilities, develop available exploit programs, and complete full network penetration tests. The head of offensive cybersecurity at Anthropic also predicts that other competing models may only take a few months to reach similar capabilities.
At the same time, the development of open-source models is also lowering the access threshold for such capabilities. After AI models gradually acquire the capabilities to execute code, discover vulnerabilities and automatically complete the attack chain, cyberattacks no longer rely entirely on a small number of high-level attackers, and the number of potential attack subjects that enterprises need to face is increasing.
The drop in attack costs has further amplified this change. Data cited in the report shows that the cost of scanning security vulnerabilities across the entire operating system has dropped to less than 50 U.S. dollars, and the cost of developing a complete remote control attack tool is less than 1,000 U.S. dollars, while the traditional black market price is about 500,000 to 2 million U.S. dollars. The change in the cost curve of attack capabilities also means that the enterprise defense side must invest more resources in automated detection and real-time response.
02 Earnings reports verify demand growth, enterprise procurement accelerates the shift to platform-based models
The second-quarter earnings reports provide more direct verification for AI security demand. The report points out that AI-related products from multiple security software vendors have quickly generated revenue after launch.
At the same time, enterprise procurement methods are also changing. As the number of security tools increases, customers are increasingly inclined to reduce the number of vendors and integrate identity, network, endpoint, data and AI security capabilities into a unified platform. The platform-based model and elastic commitment pricing have therefore accelerated their popularization, allowing customers to shift budgets to new AI security products within the framework of existing contracts without restarting the full procurement process.
This model not only helps expand contract scale, but also may improve customer retention. However, JPMorgan Chase reminds that the revenue recognition of elastic contracts of some vendors lags behind, so indicators such as ARR and booking amount are more valuable for reference than current-period revenue when judging actual business momentum.
The expansion of AI infrastructure has further created new security demands. As sovereign AI, emerging cloud service providers and cutting-edge AI labs expand their computing power deployment, demands for firewalls, SASE, data security and air-gapped deployment are growing synchronously. Some enterprises have also begun to require AI data and models to operate within their own control scope, making cybersecurity and data governance gradually become an inseparable part of AI infrastructure construction.
03 2027 may become the key year for AI security spending to accelerate its realization
The report believes that the real growth of AI security spending may not have been fully reflected in this year’s performance. Since enterprise procurement usually has a long sales cycle, a large number of AI-related projects are still in the stages of evaluation, trial and deployment, so it is reasonable for management to remain cautious about the short-term performance impact.
As these projects enter the order conversion stage, JPMorgan Chase predicts that the contribution of AI security demand to the industry’s fundamentals will gradually appear starting from the fourth quarter of this year, and will accelerate significantly in 2027. In other words, the order and product growth currently seen in the market is more likely to be a leading indicator of revenue and profit growth in the next stage.
From the perspective of segmented fields, the benefit scope is not concentrated in a single product, but covers multiple links including real-time detection and response, non-human identity governance, supply chain security, data security and exposure management. AI not only adds new attack entry points, but also creates new risks related to identity, data and software supply chains, so enterprises need to make up for multiple security links synchronously.
Based on this, JPMorgan Chase judges that this round of AI security investment is more close to a continuous structural expenditure cycle, rather than a short-term product theme. As AI further moves from experiments and pilots to enterprise production environments, the importance of security budgets is expected to continue to rise.
This article is from the WeChat official account “Hard AI”, written by a researcher focusing on technology production and research, and published with authorization from 36Kr.
