Artificial intelligence is pushing cybersecurity from a discretionary budget line into an essential expenditure. As AI lowers the barrier to entry for attackers and compresses the timeframe for exploiting vulnerabilities, the security risks confronting businesses continue to escalate, making cybersecurity a critical component of AI infrastructure rather than a mere line item in traditional IT budgets.
According to the latest report from JPMorgan, the second-quarter earnings season further reinforced analysts' confidence in the security software sector. Analyst Brian Essex estimates that AI-driven incremental security spending could represent a three-year total addressable market exceeding $430 billion. Compared with earlier technology cycles like cloud computing and mobile internet, JPMorgan believes the adoption rate for this wave of security demand may be faster, as enterprises are not simply pursuing efficiency gains but responding to mounting security threats.
This shift is already showing up in corporate procurement patterns and the operating results of security vendors. Multiple companies have disclosed rapid growth in annual recurring revenue, bookings, and related orders for AI security products, while customer purchasing has moved from point solutions toward platform-based approaches, signaling that enterprises are embedding AI security into longer-term IT infrastructure planning.
JPMorgan anticipates that many AI security initiatives are still in the early stages of the sales cycle, meaning the fundamental impact this year may be limited. However, as orders gradually convert, related demand is expected to accelerate starting in the fourth quarter of this year, with a further surge anticipated by 2027.
AI Lowers the Attack Barrier, Adding Pressure to Corporate Defenses
One of the most significant changes brought by AI is the dramatic compression of the window between public disclosure of a vulnerability and its exploitation. JPMorgan data shows that the average time to exploit a vulnerability has fallen from 63 days in 2018 to 5 days in 2023, and further to negative 7 days in 2025, meaning attackers may weaponize vulnerabilities before patches are even released. Among known exploited vulnerabilities, approximately 29% are weaponized on or before the day of public disclosure.
Generative AI has further enhanced the automation of attacks. The report cites cases from Anthropic showing its models can independently hunt for zero-day vulnerabilities, develop functional exploit code, and complete full penetration tests. Anthropic's offensive security lead also expects that competing models could reach similar capabilities within just a few months.
Meanwhile, the rise of open-source models is lowering the barrier to acquiring these capabilities. As AI models become increasingly capable of executing code, identifying vulnerabilities, and automating attack chains, cyberattacks no longer rely solely on a small group of highly skilled attackers. The pool of potential threat actors that enterprises must defend against is expanding.
The declining cost of attacks further amplifies this shift. Data cited in the report shows that the cost of scanning an entire operating system for vulnerabilities has dropped below $50, while developing a complete remote access tool costs under $1,000, compared with a traditional black-market price of roughly $500,000 to $2 million. This change in the cost curve for attack capabilities means defenders must allocate more resources to automated detection and real-time response.
Earnings Validate Demand Growth as Procurement Shifts Toward Platforms
Second-quarter earnings provided more direct validation of AI security demand. The report notes that several security software vendors have seen AI-related products generate revenue quickly after launch.
At the same time, enterprise procurement methods are evolving. As the number of security tools grows, customers increasingly prefer to consolidate vendors, integrating identity, network, endpoint, data, and AI security capabilities into a unified platform. Platform-based models and flexible commitment pricing are therefore gaining traction, allowing clients to redirect budget toward new AI security products within existing contract frameworks without initiating a full procurement process.
This approach not only helps expand contract value but may also improve customer retention. However, JPMorgan cautions that some vendors' flexible contracts involve revenue recognition delays, so metrics like ARR and bookings may provide a more reliable gauge of actual business momentum than current-quarter revenue.
The expansion of AI infrastructure is creating additional security demand as well. With sovereign AI initiatives, emerging cloud providers, and frontier AI labs scaling up compute deployments, demand for firewalls, SASE, data security, and air-gapped deployments is growing in tandem. Some enterprises are also requiring AI data and models to run within their own control environments, making cybersecurity and data governance inseparable components of AI infrastructure buildout.
2027 Could Be the Pivotal Year for Accelerating AI Security Spending
The report argues that the true growth in AI security spending may not yet be fully reflected in this year's financial results. Given the typically long sales cycles in enterprise procurement, many AI-related projects remain in evaluation, trial, and deployment phases, so management caution about near-term performance impact is reasonable.
As these projects move into the order conversion stage, JPMorgan expects AI security demand to begin contributing to industry fundamentals gradually from the fourth quarter of this year, with notable acceleration by 2027. In other words, the current order and product growth visible in the market may be a leading indicator for the next phase of revenue and earnings expansion.
Looking at sub-segments, the beneficiaries are not concentrated in a single product but span real-time detection and response, non-human identity governance, supply chain security, data security, and exposure management. AI introduces new attack surfaces while also creating fresh identity, data, and software supply chain risks, requiring enterprises to strengthen multiple security domains simultaneously.
JPMorgan concludes that this round of AI security investment more closely resembles a sustained structural spending cycle rather than a short-term product theme. As AI moves further from experimentation and pilots into enterprise production environments, the importance of security budgets is poised to keep rising.