AI-powered attacks are forcing companies to rethink where their cybersecurity dollars go, and the shift is already showing up in budget lines. According to The Information, the rise of AI threats is reshaping how businesses spend on defense, pulling money toward tools built to counter machine-speed attacks. This is significant because security budgets tend to move slowly. When they move fast, it means the threat landscape changed underneath them.
What stands out is the timing. For years, security spending followed a familiar pattern: firewalls, endpoint protection, identity management, compliance. Now attackers have the same AI tools defenders do, and they’re using them to move faster than human teams can respond.
What’s actually changing
The old model assumed attackers were limited by human effort. Writing convincing phishing emails took time. Finding vulnerabilities took skill. Building malware took expertise. AI collapses all three.
A few shifts are driving the budget reallocation:
- Phishing got personal at scale. AI writes flawless, targeted messages in any language, in seconds. The typo-ridden scam email is disappearing.
- Deepfakes hit the finance department. Voice and video clones are now good enough to fool wire-transfer approvals. That moves social engineering from an email problem to a verification problem.
- Attack speed outpaced human response. Automated tools probe, adapt, and exploit faster than a security team can read the first alert.
- AI systems became targets themselves. Companies rolling out their own models now have to defend the models, the training data, and the prompts feeding them.
Each of these breaks an assumption that older security tools were built around. That’s why the spending is moving, not just growing.
Where the money is heading
The logical response is to fight AI with AI. Defenders are shifting toward tools that detect anomalies in real time, automate incident response, and flag synthetic content before it reaches an employee. Budget is also flowing toward identity verification that assumes a voice or face can be faked, and toward securing the AI systems companies are deploying internally.
The hard part is that this often means spending on new categories while the old bills don’t disappear. You still need the firewalls. Now you also need model security, deepfake detection, and AI-driven monitoring. For most security leaders, that’s a math problem with no easy answer.
Why it matters now
Security has always been a spending arms race, but AI changes the tempo. When one side automates, the other has to automate or lose. A defender relying on manual review against an automated attacker isn’t slightly behind. They’re structurally outmatched.
That’s the real story in the budget data The Information points to. It’s not that companies are spending more. It’s that the nature of the spend is changing, from tools that assume human-speed threats to tools that assume machine-speed ones.
What to do about it
If you run security or sign off on the budget, a few practical moves:
- Audit your verification, not just your perimeter. Assume a convincing fake voice or video will reach someone with approval authority. Add out-of-band confirmation for anything involving money or access.
- Test your own AI deployments as attack surface. If you’ve shipped an internal model or agent, treat its data and prompts as things that can be poisoned or leaked.
- Buy for speed, not just coverage. A tool that detects a breach in hours is worth less than one that responds in seconds when the attacker is automated.
- Train people on the new phishing. The “look for typos” advice is dead. Employees need to expect polished, personalized fakes.
Over the next one to three years, expect the split between AI-native security vendors and legacy providers to widen. The companies that treat AI defense as a bolt-on will keep paying for both without closing the gap. The ones that rebuild around machine-speed threats will spend smarter, even if they don’t spend less.
The budgets are the tell. When money moves before the headlines catch up, it usually means the people closest to the threat already know where this is going. For the full breakdown, the original reporting from The Information is worth a read.