Lower-cost AI reduces the barrier to entry for everyone. That helps defenders build and operate more efficiently, but it also gives attackers cheaper access to powerful capabilities for phishing, automation, abuse, and disinformation. When compute and model access become less expensive, more actors can scale up activity, and the volume and speed of malicious use usually rise with it.
Why lower-cost models change the balance for defenders and attackers
Cheaper models do more than reduce spend, they increase throughput. For defenders, that can mean faster analysis, broader automation, and lower operating cost for routine tasks. For attackers, the same economics lower the barrier to scaling phishing, content generation, reconnaissance, and fraud, so the marginal cost of malicious activity falls along with the cost of legitimate use.
The practical shift is that model access becomes less of a constraint and more of an enabler. When the same capability is available to many more actors, the question is not just whether the model is powerful, but how cheaply it can be repeated, adapted, and combined with other tooling.
That is why lower-cost AI often increases both overall volume and operational speed. Defenders can process more alerts, cases, or content checks, but attackers can also test more lures, generate more variants, and automate more of the campaign lifecycle.
Where the defensive benefit stops and the abuse case starts
On the defensive side, cheaper models are most valuable when they are applied to repetitive, bounded work such as triage, summarisation, pattern detection, and assistive drafting. The benefit is usually efficiency, not autonomy, because defenders still need human judgement for escalation, validation, and final decisions.
On the offensive side, cost reduction matters because attackers do not need a single perfect output. They need enough outputs to raise success rates. That makes low-cost models especially useful for social engineering, multilingual phishing, lure variation, bulk abuse, and rapid experimentation. The same price drop that helps a defender handle more tickets can help an attacker generate more convincing variants at scale.
In other words, cheap AI does not just make good actors faster. It also makes mediocre attacks cheaper to iterate, which is often enough to improve outcomes for the attacker.
One useful signal is scale pressure. When a capability becomes cheap enough to run repeatedly, the operator who can absorb failure, retry quickly, and vary content cheaply usually benefits the most. That is why broad availability often matters more than model sophistication alone.
Risk and Threat Considerations
Lower-cost models reduce the friction for both legitimate and malicious use, but they do not distribute that benefit evenly. Defenders often convert cost savings into better coverage and quicker response, while attackers convert those same savings into higher campaign volume, faster content generation, and more attempts per dollar.
Failure mechanism: Reduced compute and access cost lowers the cost of failure for attackers, so they can send more phishing, generate more disinformation, automate more abuse, and iterate faster until a tactic works. The risk rises when organisations assume the lower price point is only a productivity gain and fail to account for the increase in adversarial throughput.
Impact: Expect higher message volume, more variant diversity, and shorter time between attacker experiments. The result is not only more nuisance traffic, but a stronger chance that at least one malicious attempt will evade filters, fool a user, or be operationally efficient enough to sustain at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Lower-cost AI changes operational context and abuse exposure across the organisation. |
| PR.AC-01 — Identity Management, Authentication, and Access Control | Cheaper models can increase automated access and misuse paths that must remain bounded. | |
| DE.CM-01 — Continuous Monitoring | Rising model use can increase attack volume and requires stronger monitoring for abuse patterns. | |
| Recommendation — Align AI deployment decisions to the business context and scale assumptions they introduce. Limit automation privileges and access paths before expanding AI-enabled workflows. Monitor AI-assisted activity for unusual volume, variant generation, and abuse indicators. | ||
| NIST AI RMF | MAP 1.3 — AI Context and Intended Use | Cost reductions change how AI is used and where misuse becomes more likely. |
| MEASURE 2.1 — Map, Measure, and Manage Risks | The key issue is the risk shift from efficiency gains to scalable abuse. | |
| Recommendation — Document intended AI use cases and reassess risk when lower-cost models expand usage. Measure abuse potential, output scale, and error impact as cost falls. | ||
| CIS Controls v8 | 6.3 — Access Control Management | Lower-cost AI can amplify automation and misuse, so access must stay constrained. |
| 8.8 — Audit Log Management | Cheaper models can increase the volume of suspicious activity that must be detected. | |
| Recommendation — Restrict AI tool access and privileges to the minimum required for each workflow. Log AI-assisted actions and review spikes in generation, retrieval, and automation. | ||
| MITRE ATT&CK | T1598 — Phishing for Information | Lower-cost models directly aid scalable phishing and social engineering campaigns. |
| T1583 — Acquire Infrastructure | Cheap AI can help attackers scale the preparation and automation of abuse infrastructure. | |
| Recommendation — Tune detections for high-volume, variant-rich phishing and lure generation. Look for rapid infrastructure setup and automated campaign staging linked to AI abuse. | ||
Practitioner Guidance
What to prioritise: Measure whether cheaper AI is being used to expand defensive coverage, attacker throughput, or both. The right control question is not “is the model cheaper?” but “what new scale does that price point enable?”
Decision rule: If the model is being used for externally facing content, abuse detection, or automated decision support, treat cost reduction as a scaling event and recheck guardrails, rate limits, human review points, and abuse monitoring before increasing deployment volume.
What to measure: Track output volume, success rate, and escalation quality separately. A model that reduces unit cost but increases false positives, uncontrolled automation, or abuse susceptibility is not net safer.
Practitioner takeaway: Cheaper models are not inherently safer or riskier, the real issue is that they make scale easier, and scale is exactly what both defenders and attackers try to use to their advantage.
Related resources from NHI Mgmt Group
- Why do open-weight AI models increase fraud and impersonation risk?
- When do lower-cost AI models make sense for secure code analysis?
- Why do insecure AI models increase enterprise risk when they are connected to business data and workflows?
- Why do foundation models increase security and governance risk in enterprise AI systems?