Who Pays? What AI-Powered Cyberattacks Mean for the Economy

AI-powered cyberattacks could cost economies billions. Advanced large language models (LLMs) such as Anthropic’s Mythos are increasingly able to identify, attack, and patch “zero-day” (unknown) and “N-day” (known) software vulnerabilities with minimal human oversight. This creates extraordinary opportunities for both cyber attackers and defenders, as the same models that can fix bugs can also exploit them.

While public and private sector actors are working to contain this capability, dispersion may be inevitable: Despite heavily restricted access to Mythos, there are already reports of unauthorized use, and the recent leak of Anthropic’s Claude source code inspires little confidence that it can keep its models hermetically sealed. As rival AI firms, including OpenAI, develop their own products capable of executing attacks, Mythos isn’t the only LLM that poses a risk; publicly available and Chinese models can also present a threat. To account for this greater risk, firms must prioritize cybersecurity throughout the production cycle, and AI companies should consider how to safely allow a diverse range of customers to use their cybersecurity LLMs. To encourage responsible private sector conduct, the U.S. government should clarify legal frameworks for cybersecurity and AI liability.

What Are the Economic Costs of Cyberattacks?

The costs of cyberattacks are difficult to estimate, but recent examples demonstrate that a single incident can cost businesses millions of dollars. Ransomware attacks can be particularly expensive. Colonial Pipeline, for instance, paid $4.4 million to hackers in 2021, while casino operator Caesars paid $15 million in 2023, and law firm Weil, Gotshal & Mange paid $19 million in 2026. Yet, regardless of whether firms pay the ransom, the cost of ransomware goes beyond initial payments due to operational disruptions, reputational damage, legal fees, recovery expenses, and other “clean up” costs. Figure 1 demonstrates the cost of ransoms versus these other reported business costs, which are likely underestimated.

Emma Surnow

Research Intern, Economics Program and Scholl Chair in International Business
Remote Visualization

Other types of cyberattacks, such as data breaches and crypto theft, can also incur significant losses. For example, a 2018 data breach cost Equifax, a consumer credit firm, $221.5 million in short-term costs, $575–700 million in legal settlements, and at least $1 billion in court-ordered cybersecurity improvements. In February 2025, North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit. In total, cyberattacks can cost companies hundreds of millions of dollars, resulting in higher costs for consumers and layoffs for employees. When cyberattacks breach multiple firms and cause downstream disruptions, incidents can cost economies billions. Table 1 contrasts the low-end estimated losses to individual companies versus economies.

Remote Visualization

As AI accelerates the discovery and execution of exploits, these losses could multiply. Using Mythos, Anthropic reports that large technology companies have increased their zero-day identification rate by a factor of five to ten, resulting in over 10,000 vulnerabilities discovered within a month of release. AI can also enhance the sophistication of cyberattacks. While not every vulnerability results in an attack, and not every attack results in significant losses, hackers only need one effective vector to cause billions in damage.

These cyberattacks will likely cause stock market shocks. Though small cyberattacks cause only minor short-term dips in price, major incidents can incur significant, prolonged devaluations. Figure 2 displays the stock market effects of several cyberattack disclosures. These decreases in value can represent millions of dollars in investments.

Remote Visualization

Who Will Suffer the Most from AI Cyberattacks?

The costs of AI-empowered malware will not be evenly distributed. While a recent history of ransomware could suggest that high-value targets will suffer more from an increase in attacks, disparities in cybersecurity resources suggest otherwise. Ultimately, the heaviest losses may fall to small and foreign firms.

Depending on attackers’ expected payoffs, some sectors and countries are more likely to be targeted by cyberattacks. “Big-game hunting” cyberattacks are optimized for large profits—disproportionately targeting wealthy countries and companies. By industry, the financial, healthcare, manufacturing, retail, legal, industrial, and technology sectors are most affected by ransomware and data breaches; this is because their need for operational speed, access to capital, and possession of personally identifiable information (PII) and intellectual property makes them more likely to pay exorbitant ransoms. Yet, while wealthy companies and countries offer the largest payouts for hackers, they can also afford the best cybersecurity.

Meanwhile, many small- and medium-sized enterprises (SMEs) cannot access sufficient security resources and, as a result, are more likely to be impacted by cyberattacks. AI advancements will likely exacerbate this disparity. For the first two months following Mythos’ release, only about fifty critical-infrastructure organizations were allowed to access the model. When this membership was expanded to about 200 organizations, access remained largely limited to multinational “critical” companies. This selective access was premised on the importance and strong security of these large firms, suggesting that SMEs will likely be barred from the most advanced models in the future. Even if a similar model does become available, smaller organizations may not be able to afford the tokens and personnel needed to deploy it.

The White House has also attempted to ban Mythos for foreign firms, suggesting that, in the future, these firms may not be able to access the best U.S.-built cybersecurity models and may be more vulnerable to attacks. Consequently, big game hunting may proliferate abroad, while, within the United States, SMEs may suffer the most. Cybersecurity might become yet another barrier to entry for small and foreign companies, particularly in industries that deal with sensitive PII and intellectual property. These economic inequities may drive higher market concentration and distort the competitive landscape.

Who Are the Relative Winners?

Though a rise in cyberattacks is a net negative, some companies and sectors will incur fewer costs. Organizations with the financial means (and political connections) needed to secure frontier-model access will probably suffer fewer breaches. Less–digitally connected and PII-intensive sectors, such as agriculture and mining, are also less likely to be targeted; indeed, these industries had relatively few cybersecurity incidents in 2025.

Companies that provide solutions to cybersecurity threats will likely see increased demand and investment. For example, while Anthropic provides the largest threat to cybersecurity, it also provides the primary solution; consequently, following Mythos’s release, Anthropic’s valuation and the demand for Claude has boomed. Other cybersecurity companies are also in demand: Crowdstrike, SentinelOne, Palo Alto Network, Okta, Fortinet, and the Nasdaq cybersecurity index stocks all rose in the months following Anthropic’s announcement of Project Glasswing.

Recommendations for the Private Sector

As AI empowers attackers, businesses need to reshape their approach to security and adopt a secure-by-design framework. Historically, a great deal of cyber defense has been done ex post facto by releasing patches to bugs after the product has already been published. This security model was feasible because zero-days were relatively rare, and there was a significant lag between vulnerability discovery and exploitation. The costs of cybersecurity and the unclear state of cyberattack liability also did little to encourage proactive defense. Companies could, in some ways, afford to procrastinate their cybersecurity for months or even years.

With artificial intelligence allowing hackers to identify and exploit vulnerabilities within hours, this bet becomes much riskier. From 2018 to 2026, the window between the public disclosure of a vulnerability to its weaponization collapsed from 2.3 years to 1.5 days. A cyberattack can now take minutes, but defenders cannot detect or remedy these attacks in a comparable time frame. Companies can no longer afford to release flawed products and bank on fixing bugs only once they come up; they need to emphasize security at the outset, as well as accelerate patching cycles and increase network motoring. However, this will slow the production cycle and increase upfront development costs.

In the absence of clear guidance, in consultation with the government, AI companies should decide who can access their advanced models, and how. So far, Anthropic has announced ID verification for users, severely limited Mythos access, and implemented stringent guardrails for its publicly available counterpart. However, this business model heavily reduces Anthropic’s customer base. Moreover, while it might constraint attackers’ abilities, it also leaves most defenders out to dry, rendering them particularly endangered if hackers do gain unauthorized access to premier models. Prominent cybersecurity researchers have also complained that the guardrails on public models have rendered them nearly obsolete.

Instead of debilitating guardrails, for small or foreign firms, AI companies could introduce “security-as-a-service,” similar to current penetration-testing services. They, or a trusted third-party, could access customers’ networks and scan for vulnerabilities with these cutting-edge AIs without ever giving the client direct access to the model.

Recommendations for Government

The U.S. government already works to protect critical infrastructure, set cybersecurity standards and frameworks, issue threat advisories, and confront attackers. Besides continuing and increasing this work, the public sector must address two questions: how to regulate access to these models, and whom to hold liable for cyberattacks.

First, the federal government should provide a clear regulatory framework for AI distribution. The government has recently reversed course on controls for Anthropic’s Mythos 5 and Fable 5 models through a Bureau of Industry and Security “Is Informed” letter. This approach does not seem financially or legally viable, as the government has not clearly justified the rationale or criteria for its restrictions, and its abruptness forced Anthropic to broadly ban access to these LLMs. While access to top-tier cybersecurity models should be controlled for security reasons, regulation needs to be predictable and legal, or AI innovation will become commercially unsustainable.

Second, holding organizations liable for cyberattacks could help encourage better cybersecurity. Typically, victims (the attacked company, not its customers) are held liable for cyberattacks: Following a ransomware attack and data breach, multiple government entities filed a lawsuit against Change Healthcare for failing to protect consumer data and Equifax settled a similar lawsuit in 2019. Holding companies liable for cybersecurity negligence and losses can force firms to invest more in cybersecurity.

However, punishing victims for cyberattacks is unfair when they exercise a reasonable standard of care and software providers are at fault. In this case, there does not appear to be a concrete legal precedent for liability. While the Biden administration favored suing software providers, this was not consistently enforced. For example, SolarWinds was not held liable for the 2020 supply chain attack that spread through its software. The government should decide whether firms can be held liable for providing insecure software, just as car manufacturers can be held liable for unsafe vehicles. Though this could impose more costs on providers, liability would encourage the release of more secure software.

Finally, the government should adjudicate whether the providers of AI models can be held liable for actions perpetrated by their models. The question is unsettled: Cases against OpenAI are ongoing, and Anthropic has escaped repercussions for Claude’s successful cyberespionage campaign in 2025. Firm’s liability for the misuse of their products likely depends on distribution regulations: While gun manufacturers are generally immune from liability for gun deaths, there are exceptions for knowingly violating gun-sale regulations. However, if product distribution is not regulated, liability becomes less tenable.

Conclusion

Empowered by advanced LLMs, a rise in cyberattacks could incur devastating costs. For large companies, this could mean millions in ransom, lost revenue, recovery, and legal fees; for small companies, this could mean bankruptcy. With the best cybersecurity tools confined to an exclusive club, SMEs and foreign firms may disproportionately suffer, resulting in more domestic market concentration. To protect themselves and others from cyberattacks, companies should ensure that their systems and products are secure from the outset, rather than relying on a reactionary defensive strategy. But this will cost them time and money. To encourage companies to forego the short-term gains of poor cybersecurity, the government should release a clear framework for cyberattack liability and the distribution of highly capable AI models. To even the playfield, AI companies should consider providing cybersecurity-as-a-service, so that small and foreign organizations are not left out as sacrificial lambs for hackers.

Emma Surnow is an intern with the CSIS Economics Program and Scholl Chair in International Business at the Center for Strategic and International Studies (CSIS).