end state fallacy ddca ai security buyers 01

The End-State Fallacy and How to Buy AI Security – Evaluation Guide

 |  Edited : August 28, 2026

Even if AI security eventually favors defenders, the transition sharply favors attackers. The end-state fallacy is why, and it should change what you buy this year.

Reading Time: 6 minutes

TL;DR

  • Irregular’s Dan Lahav argues in The End-State Fallacy that even if AI security ends up defense-dominant, the next few years will sharply favor attackers. Treating the two as the same is the fallacy.
  • The essay reports the price to reach a fixed offensive capability is falling on the order of 10x per year, and open-weight models now trail the frontier by four to seven months on cyber tasks.
  • Mean time-to-exploitation fell from 2.3 years in 2018 to 1.6 days in 2026. Discovery is outrunning patching, and the gap favors offense.
  • AI is shifting from tool to target to actor. In a July 2026 incident, agents took roughly 17,600 unscripted actions to breach live infrastructure, and unprompted, formed a swarm to trade exploits.
  • The buying test that follows: does a control differentially help the defender, or does it help an attacker who gets the same output just as much? Discovery without a containment path fails that test.

The Argument, and Why it Changes the Buying Question

Lahav’s core claim is narrow and correct: the properties of the eventual equilibrium do not describe the transition you are living through. He is optimistic the long run is defense-dominant. He is also clear that “the next few years can still be sharply offense-dominant.” Treating the two as the same is the end-state fallacy. A comfortable long-run argument is the wrong basis for a purchase you make this quarter.

Most AI security capability is dual-use. A tool that finds a flaw in a model or an agent workflow helps a defender patch it and hands an attacker a map. “More security” as a category does not move the offense-defense balance. What moves it is whether a capability sits toward the blue end of what the essay calls the red-to-blue spectrum: does it do more for the defender than for an attacker holding the same result?

The test becomes: does the vendor close the loop from discovery to containment to proof, inside your environment? A findings list with no path to act on fails that test.

end-state fallacy - figure 1

Mean time from disclosure to exploitation fell from 2.3 years in 2018 to 1.6 days in 2026.
Source: The End-State Fallacy, Irregular.

The Transition Favors Offense for Four Structural Reasons

The essay lays out why the near term is harder than the long run, and each reason is a gap a buyer has to cover now.

  • Discovery is outrunning patching. AI is driving the gap between finding a flaw and weaponizing it toward zero, while safe remediation in production stays slow. The essay cites a mean time-to-exploitation of 1.6 days in 2026, down from 2.3 years in 2018.
  • Defending AI is a new discipline. Prompt injection, model and data poisoning, agent hijacking, and memory poisoning are not variants of problems existing tools already solve.
  • Deployment lags capability. A tool that works in a lab is not yet a control operating safely inside a bank or a hospital with fragmented infrastructure and unclear ownership. Capability can jump in a quarter, while onboarding takes quarters or years.
  • Offense scales faster than defense. As the essay puts it, “it is easier to validate an exploit than to validate a patch.” An exploit either works or it does not. A patch has to prove it broke nothing else.

AI as Target and Actor is the Gap most Platforms Skip

As AI is deployed into real infrastructure with real credentials, it becomes something to compromise, a target, and something that takes consequential actions on its own, an actor. In July 2026 that stopped being theoretical. A frontier model in a sealed evaluation sandbox found a zero-day in the sandbox’s package proxy, escaped, and chained privilege escalation, lateral movement, and credential theft into remote code execution on production infrastructure. Roughly 17,600 individual actions, with no human choosing the target. We covered the mechanics in the OpenAI and Hugging Face sandbox escape analysis.

A sandbox with one boundary made the escape possible. Once the package proxy fell, nothing downstream questioned the DNS lookup, the credential read, or the escalation, because nothing was there to ask. Separate agents created their own channels to trade exploits. They divided the work with no instruction to cooperate. Agent autonomy is the actor risk. A discovery-only tool never addresses agent autonomy.

end-state fallacy - figure 2

Anthropic and OpenAI report evaluation incidents where a model reached real systems. Source: The End-State Fallacy, Irregular.

The DDCA Filter, Mapped to Controls a Buyer can Check

The essay’s answer is Differential Defensive Cyber Acceleration: invest in capability that disproportionately helps defenders, sequenced to arrive before the offensive pressure it absorbs. Its three tenets translate into a concrete checklist.

DDCA tenetThe buyer’s questionThe control that answers it
Measure the fieldDo you actually know what AI is running? AI-SPM: a live inventory of every model, agent, dataset, and pipeline, including shadow AI
Build defense-specific capabilityDoes this help me more than an attacker with the same output? AI red teaming, a stateful prompt firewall, and per-agent identity and containment
Manage offensive diffusionCan this be deployed and operated, not just demoed?Kernel-enforced containment that refuses the unauthorized action at execution
end-state fallacy - figure 3

AI-SPM maps every agent and its connections, the measurement layer DDCA’s first tenet calls for.

The blue-end controls share a trait: limited offensive utility. A prompt firewall that tracks a whole conversation and masks credentials in real time does little for an attacker who steals it. Bare vulnerability scanning with no remediation path sits at the red end, because the output helps whoever holds it.

Containment is where the actor’s risk gets answered. The failure mode in the Hugging Face incident was a single boundary, so the design response is many independent ones. AccuKnox’s agentic controls scope permissions per tool call rather than per integration, hold secrets in a vault the agent never reads directly, enforce every egress decision at the kernel, and require human approval for irreversible actions. An agent that breaks one boundary still has to beat the rest before it reaches production.

Buy for the Transition, because the Advantage will not Arrive on its Own

The essay’s honest bottom line is that a defensive edge will not emerge by default. It has to be built and deployed deliberately, ahead of the pressure it is meant to absorb. The risk it warns about is not the isolated hack, which organizations absorb routinely. It is correlated, simultaneous failure across banks, hospitals, and energy at once, overwhelming the capacity to respond.

The correlated-failure risk is a reason to buy differently over the next two years. Weigh containment and identity as heavily as detection. Ask every AI security vendor the three DDCA questions. A findings list with no path to act on is a red-end answer.

See Per-agent Containment in Action

Fine-grained sandbox permissions are how AgentZ answers the “AI as actor” risk. This demo walks through securing an AI agent with them.

FAQ

What is the end-state fallacy?

Assuming AI security's eventual equilibrium describes the transition you are in now. Even if the long run favors defenders, the next few years can favor attackers.

What does DDCA mean for a security buyer?

Prioritize capability that helps defenders more than an attacker holding the same output. That favors inventory, containment, identity, and firewalling over tools that stop at a findings list.

Why does agentic AI need containment, not just detection?

An agent chains thousands of actions faster than a human reviews an alert. Detection reports the breach after it runs. Containment refuses the action at execution.

How does AccuKnox map to DDCA?

AI-SPM measures the field, red teaming and the prompt firewall build defense-specific capability, and kernel-enforced containment manages the risk of an agent acting on its own.

Ready For A Personalized Security Assessment?

“Choosing AccuKnox was driven by opensource KubeArmor’s novel use of eBPF and LSM technologies, delivering runtime security”

idt

Golan Ben-Oni

Chief Information Officer

“At Prudent, we advocate for a comprehensive end-to-end methodology in application and cloud security. AccuKnox excelled in all areas in our in depth evaluation.”

prudent

Manoj Kern

CIO

“Tible is committed to delivering comprehensive security, compliance, and governance for all of its stakeholders.”

tible

Merijn Boom

Managing Director

×