# The Defense Spending on Offense Problem Has an AI Twist No One's Fully Reckoning With
The pitch sounds clean: attackers are using AI to move faster, so defenders should use AI too. Match speed with speed. Level the playing field. It's the kind of logic that lands well at a Black Hat booth, and apparently it's landing well in budget meetings too.
New research from Omdia, presented at Black Hat USA 2026 in Las Vegas, shows enterprise spending on offensive security — penetration testing, red teaming, vulnerability assessments — is climbing as organizations scramble to keep pace with AI-accelerated adversaries. Theresa Lanowitz, principal analyst at Omdia, framed it plainly in conversation with Dark Reading: so far, agentic AI has proven more useful for attacking than defending. The question is whether that's a temporary imbalance or a structural feature of how these tools work.
## The Asymmetry That Actually Matters
The gap isn't just about who has better tools. It's about who faces consequences for using them recklessly.
An attacker deploying an autonomous AI agent that goes sideways loses a campaign. An organization deploying one against its own infrastructure — or a client's — and having it behave unexpectedly can lose an engagement, a contract, or trigger a legal incident. The asymmetry of consequences shapes how aggressively each side can actually lean into autonomous capabilities.
Lanowitz addressed this directly, noting the importance of limiting the "blast radius" of AI agents during offensive security operations. That's a real engineering concern, but it's also an implicit admission that these tools aren't yet mature enough to be turned loose without guardrails. Which raises an obvious question: if you're constraining your AI red team agent to prevent it from doing damage, how much of the attacker's advantage are you actually capturing?
A real adversary's AI agent doesn't worry about blast radius. It's trying to maximize it.
## Spending Up, But the ROI Question Is Unsettled
The surge in offensive security investment makes strategic sense on its face. Traditional annual or quarterly pen tests — the kind where a firm comes in, pokes at your perimeter for two weeks, and hands you a PDF — are genuinely inadequate against threat actors who can identify and exploit vulnerabilities within hours of disclosure. The Omdia research points to this velocity problem explicitly: the speed at which adversaries weaponize new vulnerabilities has outpaced what legacy defensive programs can keep up with.
Continuous red teaming, automated vulnerability assessment, and agentic tools that can simulate attacker behavior without sleeping are logical responses. The market is responding accordingly.
But "we're spending more on offensive security" doesn't automatically translate to "we're better defended." Offensive security done poorly — or rushed into production before practitioners understand what the AI agent is actually doing — creates its own category of risk. Misconfigured scanning tools have accidentally taken down production systems. Red team agents with overly broad permissions have created exploitable artifacts on client networks. The history here is checkered even before AI enters the picture.
## Who's Actually Equipped to Use This Responsibly
There's a tiering problem in this market that the optimistic spend numbers obscure. Large enterprises with mature security programs, experienced red team operators, and the legal infrastructure to govern autonomous tool use are reasonably positioned to experiment with agentic offensive tools. They have the baselines to know when something goes wrong, and the expertise to interpret what an AI agent is telling them.
Mid-market companies — which represent the bulk of the organizations suddenly concerned about AI-enhanced attacks — often don't have that foundation. They're being sold on AI-powered pen testing as a cost efficiency play precisely because they can't afford to run a proper red team program. The pitch is compelling: get continuous, automated security validation without the headcount. The risk is that these organizations end up with AI-generated findings they lack the expertise to triage, prioritize, or remediate.
Bad signal at scale is worse than less signal. A vulnerability scanner that flags 400 critical issues on a network where security staff can meaningfully act on maybe 20 per week doesn't improve security posture — it creates alert fatigue and an illusion of coverage.
## Black Hat as Bellwether
It's worth reading Black Hat's vendor floor as a real signal about where enterprise dollars are going. The conference has long served as a reliable leading indicator of the security market — products that get serious attention there tend to show up in procurement pipelines 12-18 months later. AI-augmented offensive tools dominated this year's floor presence, and that's consistent with what Lanowitz's research is showing in budget data.
What's less visible in the conference narrative is failure. Black Hat showcases what's possible; it's quieter about engagements where agentic tools caused problems, made noise that tipped off defenders during authorized tests, or produced findings that turned out to be garbage. Those stories exist. They're just not in the keynotes.
---
## HackWire Analysis
The framing of "granting the same AI advantages to the defender" is intellectually honest in a way a lot of vendor pitches aren't — it acknowledges the current asymmetry rather than pretending AI is already a net-positive for defense. That candor is notable and earns Omdia's research more credibility than the typical "AI will save cybersecurity" boosterism.
But here's the structural problem the framing doesn't fully resolve: offensive security has always lived in an uncomfortable regulatory and liability gray zone, and autonomous AI agents amplify every ambiguity. Scope creep during a manual pen test requires a human making a bad judgment call. Scope creep by an agentic AI happens at machine speed and may not be immediately detectable. The governance frameworks for responsible use of autonomous offensive tooling are nascent at best — bug bounty platforms are only beginning to work out policies, and most enterprise legal teams haven't thought through the liability exposure.
The spend surge also carries a vendor-capture risk. Organizations that don't have mature offensive security programs are going to be heavily reliant on vendor-supplied AI tooling to interpret results. That creates dependency on the vendor's threat modeling assumptions, their training data, and their definition of what constitutes a finding. If those assumptions don't match your environment, you can spend a lot of money getting confidently wrong answers about your actual risk.
The real defensive investment that precedes any of this — the one that makes AI-augmented offensive tools valuable rather than noise — is the unsexy work of asset inventory, exposure management, and mean-time-to-patch. Organizations that can't answer "what's on our network" aren't going to be saved by an AI red team agent.
— HackWire Editorial
---
## Related Coverage