AI May Amplify the Macro Cost of Cyberattacks in the U.S.
AI summary card
AI May Amplify the Macro Cost of Cyberattacks in the U.S.
Goldman Sachs estimates total U.S. cyberattack costs at about $300 billion in 2025, or roughly 1% of GDP, and expects AI-assisted attacks to significantly push those costs higher over the next few years.
- AI models lower the barrier to attack, enabling attackers to discover and exploit software vulnerabilities faster and at lower cost.
- The direct monetary loss from cyberattacks is only part of the total cost; it also includes productivity losses, downstream spillovers, recovery and response costs, regulatory fines, and cybersecurity spending.
- The report estimates total U.S. cyberattack costs in 2025 at about $300 billion, including roughly $53 billion in adjusted direct losses, about $163 billion in response, recovery, and business interruption costs, and about $91 billion in cybersecurity spending.
- AI can also strengthen defense through automated threat detection, faster response, and simulated attacks to identify vulnerabilities in advance, but in the near term the net effect may still lean toward attackers.
- If a cyberattack hits critical infrastructure or a widely used technology platform, potential losses could be meaningfully larger than those from a normal technical outage.
Report interpretation
Overview
This report discusses how AI development affects cyber risk and estimates the potential macroeconomic cost of cyberattacks on the U.S. economy. It first reviews common cyberattack types and recent cases, then analyzes how AI can strengthen both attack and defense capabilities, and finally folds direct losses, data breach costs, spillover effects, productivity losses, and cybersecurity spending into a total cost estimate.
Core views
The core view is that cyberattack frequency and cost have risen significantly over the past decade, and AI models further lower the technical and cost barriers for attackers, which may make attacks faster, larger, and more sophisticated in the near term. Over the longer term, if AI defense tools continue to improve and reduce exploitable vulnerabilities, the balance between offense and defense could eventually shift toward defenders. The report estimates total U.S. cyberattack costs in 2025 at about $300 billion, or around 1% of GDP.
Analysis framework
The report uses a Q&A-style macro framework, combining FBI IC3 reports, IBM, Verizon, HackerOne, the U.S. government budget, industry surveys, and academic research to evaluate attack frequency, direct losses, indirect costs, defense spending, and changes in AI model capabilities. It also uses historical high-impact cyberattack cases, critical infrastructure attack data, losses from outages at major technology platforms, and AI model cyber offense/defense testing results to explain the potential macro transmission channels.
Methodology notes
Direct losses, response and recovery costs, business interruption costs, cybersecurity spending
The report adjusts the FBI-reported direct monetary losses for underreporting, then adds data breach costs, spillover effects on other companies, productivity losses, and public- and private-sector cybersecurity spending to estimate the total economic cost.
Attackers benefit more in the short term; defenders may benefit over the long term
The report cites research suggesting that many AI cybersecurity capabilities can be reused by attackers, and that AI may reduce attack costs more than it reduces defense costs, implying a higher net risk in the short term. Over the long run, if defense tools reduce exploitable vulnerabilities, the risk balance may improve.
Systemic disruption and trust restoration costs
The report uses critical infrastructure attacks and outages at large technology platforms to show that if a widely used platform suffers a cyberattack, the costs can include not only downtime losses but also data destruction, asset losses, validation work, and long-term trust restoration costs.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- U.S. macroeconomyRising cyberattack costs may act as a tax-like drag
- Strengths
- The report provides a quantifiable total cost framework and combines direct and indirect costs in one assessment.
- Weaknesses
- The incremental impact of AI-assisted attacks is still difficult to estimate precisely, and the report acknowledges that it is too early for a definitive forecast.
- Comparison
- Compared with looking only at FBI-reported losses, the total cost including underreporting, recovery, productivity losses, and security spending is significantly higher.
- Risks
- If attack frequency, regulatory costs, or critical infrastructure incidents exceed expectations, total costs could move even higher.
- Cybersecurity value chainHigher AI risk may strengthen security budgets and tool demand
- Strengths
- Average corporate cybersecurity budgets, federal budgets, and bug bounty spending all point to rising defensive investment.
- Weaknesses
- Higher cybersecurity spending is itself an economic cost and may not fully translate into profit growth.
- Comparison
- AI can improve both threat detection and simulated attack capabilities, but it can also be reused by attackers, making defense needs more complex.
- Risks
- If AI attack capabilities spread faster than defensive capabilities, customer budgets may shift from prevention toward emergency recovery and compliance spending.
- Critical infrastructure companiesDowntime, data destruction, and trust restoration costs create higher tail risk
- Strengths
- The importance of critical infrastructure makes security spending and regulatory attention relatively rigid.
- Weaknesses
- Losses from an attack can be highly nonlinear and may spill over to supply chains and downstream companies.
- Comparison
- Even a normal technology outage can cause losses of more than $1 billion; because cyberattacks add data validation and trust restoration complexity, potential losses can be even higher.
- Risks
- Ransomware, zero-day vulnerabilities, and supply-chain attacks may lead to prolonged operational disruption.
- AI models and software engineering platformsImproved model capabilities bring both productivity gains and cyber abuse risks
- Strengths
- Models can be used to automatically detect threats, help fix vulnerabilities, and simulate attacks.
- Weaknesses
- The same capabilities can lower the barrier for attackers by helping with malware development, phishing, and exploit generation.
- Comparison
- The report argues that AI is more likely to favor attackers in the near term, while whether defenders outperform over the long term depends on the maturity of security controls.
- Risks
- The more models can perform complex software engineering tasks, the more they may be used for highly automated cyberattacks.
- VZ.US, XYZ.US, USE.USThe securities codes appearing in entity recognition do not constitute investment advice in this report
- Strengths
- These codes can be used as follow-up entities for verification.
- Weaknesses
- The body of the report does not provide fundamental analysis, ratings, or target prices for these securities.
- Comparison
- This report is a U.S. macro and cybersecurity thematic study, not an individual stock coverage report.
- Risks
- Misreading file names or entity-extraction results as stock recommendations could lead to incorrect investment mapping.
Key data
- Estimated total U.S. cyberattack cost in 2025About $300 billionRoughly 1% of U.S. GDP, including direct losses, indirect costs, and cybersecurity spending.
- Adjusted direct monetary lossesAbout $53 billionBased on the FBI IC3's reported 2025 losses of $20.9 billion, adjusted for underreporting and ransomware underreporting.
- Response, recovery, and business interruption costsAbout $163 billionIncludes data breach costs, downstream effects on other businesses, and productivity losses.
- Cybersecurity spendingAbout $91 billionIncludes about $20.8 billion in federal cybersecurity spending and about $70 billion in private-sector cybersecurity spending.
- Number of FBI IC3 cyber incident reports in 2025More than 1 millionThe report suggests the actual incidence may be higher because many attacks are never discovered or reported.
- Average monetary loss per reported attack in 2025About $20,000; AI-related attacks about $40,000The report treats this as a lower-bound cost measure.
- Average cybersecurity spending of mid-sized and large companies in 2025About $25 millionBased on corporate survey data.
- Impact of AI-driven cybersecurity automation on data breach costsReduces costs by about $1.9 millionIBM data show that AI security automation can also shorten the time needed to identify and contain a breach.
- Time to breach by cyber criminalsAbout 29 minutes in 2025, versus about 98 minutes in 2021The report cites CrowdStrike data to show that attack speed has increased significantly.
- Success rate in AI model cyber offense/defense testingClaude Mythos Preview at about 73%The chart shows that by around 2026, frontier models have materially higher success rates in simulated enterprise cyberattack challenges.
Impact & implications
The investment implications mainly run through three channels: macro costs, corporate operating risk, and cybersecurity spending. If AI-assisted cyberattacks increase, companies may face higher costs for protection, compliance, insurance, recovery, and business interruption, and tail risk for critical infrastructure and large technology platforms becomes more pronounced. At the same time, demand may continue to grow for cybersecurity tools, AI-driven threat detection, identity and access management, bug bounty programs, offensive/defensive exercises, and simulated attack capabilities.
Risks
- AI models may be used by attackers to find and exploit zero-day vulnerabilities more quickly.
- Actual cyberattack incidence and losses may be underestimated due to underreporting.
- Attacks on critical infrastructure or major technology platforms may cause long-term losses beyond those of ordinary outages.
- Higher corporate cybersecurity and compliance spending may compress margins.
- In the near term, AI defense tools may not fully offset the rise in attack capabilities enabled by AI.
- Regulatory costs and disclosure requirements may rise after major attack events.
What to watch
- Trends in the number of cyber incidents and monetary losses reported in FBI IC3 data.
- The share of total losses attributable to AI-related cyberattacks.
- Ransomware and data breach incidents in critical infrastructure sectors.
- Changes in U.S. federal cybersecurity budgets and corporate cybersecurity budgets.
- Improvements in AI model capabilities for software engineering, vulnerability discovery, and cyber offense/defense testing.
- Adoption rates for AI-driven security automation, zero-trust architecture, identity and access management, and bug bounty programs.
- Regulatory requirements for cybersecurity disclosure, data protection, and critical infrastructure defense.