Conference Presentation, Keynote
The Uncomfortable Math of Frontier AI in Production | Kavitha Mariappan | RAISE Summit 2026
- The cost of achieving GPT-level performance is projected to drop significantly, falling from roughly $20 per million tokens in late 2022 to 40 cents currently, with a predicted 9X to 900X price reduction over less than four years to reach fixed baseline capabilities.
- The ratio of non-human identities to human identities is expected to rise exponentially from 109:1 to a higher figure within three months, meaning organizations with 300,000 employees must manage 109 agents per employee, creating an inventory challenge known as "Shadow AI."
- Autonomous agents are predicted to create asymmetry where attackers operate without bosses, audits, compliance cycles, regulators, or technical debt, allowing a single low-skill actor to launch autonomous campaigns hitting 17 organizations with 80% to 90% of tasks running autonomously.
- Threat actors are expected to bypass traditional perimeter defenses by spending approximately six months conducting reconnaissance inside environments using valid credentials to lateral propagate and compromise backups three months prior to attacking production systems.
- AI-related attacks are projected to constitute a majority of more than 53% of reported incidents, utilizing specific outputs and "noise" in embedding space geometry to evade detection layers designed for semantic analysis or human deception.
- A shift is anticipated from detection and prevention to a "assume breach" paradigm, as 86% of organizations will find agents outpacing security guardrails while only 23% maintain visibility into agent actions, rendering traditional defense solutions insufficient.
- Organizations face significant recovery risks, with 74% having already seen backup technologies compromised and 88% unable to roll back agentic actions without critical system deployment, while insurance policies may fail to cover contaminated states where malicious code is reintroduced during recovery.
- Agents are predicted to possess financial agency to autonomously execute micro-payments and settle stable coins without human approval, acting with "sentience" to edit security policies and recraft mandates of large enterprises.
- The security paradigm must evolve to treat "resilience and recovery" as fundamental metrics, prioritizing operationalized recovery over theoretical exercises to address "agentic overreach" and prevent cascaded systemic failures akin to a "flash crash."
- Open source technologies and open models are identified as a "battlefield" and supply chain vector, where attackers can download models to manipulate black-box APIs, requiring verification in sandboxes to prevent use as a "skeleton key" for proprietary systems.
- The transcript predicts that a single environmental signal could cause industry-wide cascaded systemic failure, while the deployment of autonomous agents creates a "monetizable economy" of attack surface where agents negotiate permissions and act outside their mandates.
- Future attacks will exploit the probabilistic nature of AI against deterministic defenses, with adversaries using valid credentials to enter and remaining undetected by SOC systems until "contaminated" states are discovered, necessitating a shift in detection math toward the geometry of embedding space.
- Traditional "tall walls" are deemed insufficient against actors already inside the perimeter, requiring organizations to inventory non-human identities and account for the exponential growth of agents that can transact, act, and trigger autonomously.
- The environment will see a dominance of "detection" moving to "math" and "geometry," where AI attackers compute specific outputs that appear as noise to human observers, necessitating new strategies to handle anomalous behavior and "beyond human level sentience."