The arrival of AI agents in security solutions, such as in the Security Operations Center, is not only a technical change. It is also starting to drive a commercial change.
Most of the discussions around AI agents in security solutions have focused on what the technology can do, such as, automate alert triage, accelerate investigations, support threat hunting, improve vulnerability prioritization, assist analysts with malware analysis, and many other use cases. These are certainly important technical developments. But there is another change underway that may prove to be nearly as significant. AI agents are starting to be priced like junior analysts with “salaries” to match.
Pricing in the security solutions market has traditionally been built on crude proxies to value. Seats/users, servers, mailboxes, and endpoints, are relatively easy to count, but were never especially precise measures of the value that a solution created for customers. AI agents could give the security market a pricing unit that is closer to realized customer value than those other proxies are.
In that sense, the rise of AI agents could be good commercial news for both vendors and customers. The value exchange between market participants can become even clearer and more mutually beneficial.
Why security pricing has relied on distant proxies to value
For years, most security products have been priced according to measures such as the number of users, employees, endpoints, servers, mailboxes, or network devices covered by a product. There are understandable reasons for this. These metrics are visible, auditable, and simple for both procurement teams and vendors to count. In some categories, they also make good sense. If a product is delivered directly to individual end users, user-based pricing aligns well with the service provided. Think of Microsoft 365 or MFA credentials.
In many other areas of security those measures have been only rough proxies to the value provided. An organization with many users may derive relatively little value from a given security solution, while another with fewer users may derive very high value. A customer with a modest endpoint count may face sophisticated threats, high-value data exposure, or challenging regulatory obligations, while an organization with many more endpoints may have comparatively lower exposures. But if the value measure is users or endpoints, a mismatch between cost and value often results.
The problem is not that user-based or node-based pricing is irrational. It is that they often measure what is easy to count rather than what the customer truly values.
Why true value-based pricing has been difficult
In theory, the ideal has always been to price according to value delivered. If one customer organization receives limited value, it should pay less. If another receives significant value, it should pay more. In a well-functioning market, that creates the possibility of a “fairer” split of the value created between the vendor and the customer.
In practice, however, true value-based pricing in security has also been difficult to attain since the core value delivered is often risk reduction, and risk reduction is notoriously hard to observe and measure. How can you price according to breaches that did not happen, attacks that were contained earlier, or analyst time that might have been wasted but was not? As a result, the industry often defaulted to easier to count value measures.
AI agents deliver a clearer unit of work
AI agents will not entirely solve the problem of measuring security value, but they do make actual work performed more visible. Including, and importantly, work consisting of complex, multi-step processes. This is still a meaningful shift. AI agents do not make risk reduction easy to value, but they can make human-like units of work easier to identify, count, and audit. Instead of pricing by users or assets, both vendors and customers can increasingly think in terms of work being completed or at least augmented.
Examples of those security related work units include:
- Access reviews conducted
- Alerts or emails triaged
- Investigations completed
- Threat hunts run
- Malware samples analyzed
- Vulnerabilities discovered, prioritized, and remediated
Pricing based on these and other types of distinct security work processes moves pricing closer to outcomes by tying costs to work that is more directly connected to value. These represent jobs that regularly need to get done, whether manually or now increasingly with specialized AI agents.
Why Now with AI agents?
Security vendors have long offered forms of automation, such as SOC workflows, automated vulnerability scanning, and continuous user authentication. What is different now with specialized AI agents versus those traditional automations is that the agents can, with agency, independently conduct more complete, multi-step operations. Organizations don’t need to code these workflows in advance; they just need to point the given specialized agent at the problem. This is much more like what they would do with a junior security analyst.
In some cases, the agent is a direct substitute for labor. In others, it is augmenting the productivity of experienced practitioners. This is why new AI-agent pricing can be more defensible than traditional pricing models. If an alert triage agent handles a large volume of repetitive work that would otherwise require a junior analyst or managed service provider to conduct, the customer can directly compare the cost of the agent to the equivalent time of a junior analyst or the cost of a managed service provider. If a vulnerability agent helps a team focus scarce remediation efforts on the exposures that matter most, the value may be measured through improved productivity and reduced vulnerability backlog rather than by an unrelated user or endpoint count.
The more completely an agent owns and executes a specific workflow, the easier it becomes to define a pricing unit that makes sense to both sides. The cost of the AI agent can be directly compared to the alternative for which it is a substitute.
Early signs from the AI SOC market
The emerging AI SOC is one of earliest security domains where this pricing shift is becoming visible.
Alert triage is an excellent example of this. Without an alert triage AI agent or another form of automation, the organization faces a familiar choice: have people review large numbers of alerts manually, accept that many alerts will be ignored in the hopes that they are false positives, or some combination of the two. Both options carry costs. Manual review consumes scarce analyst time. Ignored alerts increase operational and security risk.
An AI SOC agent that conducts alert triage changes that equation by creating a repetitive and measurable work process that operates a machine speed. The customer is no longer just paying for software in the abstract. It can instead pay for successfully conducted alert triages.
This is why some of the most interesting pricing signals in the security market are starting to look less like conventional software subscriptions and more like what might be described as “salaries” for specialized AI-agents. The framing is notable because it connects cost to an understandable operational benchmark: the work output that would otherwise require inhouse human labor or outsourcing to a managed security service provider.
Why this can be positive for both buyers and vendors
If this pricing transition continues, and I think it will, it could create a healthier pricing model for both sides.
For buyers, pricing tied to actual work done can offer better alignment between spend and realized value. Organizations that use AI agents to automate a limited amount of work would pay less. Organizations that derive significant benefit from a high-volume, high-value agentic workflows would pay more. Both would be in a better position to justify the spending internally because the cost maps more directly to avoided labor, improved throughput, or faster responses.
For vendors, work-based pricing can reduce the economic distortions created by using weak value proxies. Instead of trying to indirectly infer value through counts of endpoints or users, vendors can charge according to units of work conducted that are more closely connected to what the customer is consuming and against their next best alternatives. This allows vendors to capture a fairer share of value in high-impact deployments that would otherwise be underpriced using one-size-fits-all measures. It can also reduce churn and pricing friction by lowering the risk that customers are overpaying for functionality that is not driving as many meaningful outcomes. This approach supports a win-win outcome.
What could still go wrong
None of this means this pricing transition will happen quickly or easily. This, after all, is changing a practice that has been in place for many years. Many buyers will be suspicious that they aren’t getting a good deal. What needs to be true for this new pricing approach to work?
First, quality control matters. Counting alerts triaged or investigations completed is not enough if the quality of the work is inconsistent or if the outputs require heavy downstream correction by human analysts. Volume of alerts triaged is a useful pricing unit only when the work delivered is credible, operationally usable, and of consistent quality.
Second, customers may worry about runaway usage. Bringing up nightmares of surprise Amazon AWS bills. Consumption-based pricing often looks attractive at first, but procurement teams will want safeguards if the adoption of AI agents causes usage volumes to rise quickly or unpredictably. A history of ignoring security alerts has no direct cost. But with AI agents no alert will be ignored unless otherwise directed to do so. A guardrail around the maximum contracted spend in a period would defend against this.
Third, value attribution is still difficult in some areas of security. A discrete workflow such as alert triage or malware analysis is easier to price this way than broad, process intensive improvements in resilience, posture, or risk reduction that depend on multiple tools and teams working together.
Fourth, some use cases remain poorly suited to workflow pricing. The model works best when the workflow is discrete, but operationally significant, the output is auditable, the labor substitute or augmentation is clear, and the customer can reasonably estimate avoided cost or productivity gain. It works less well when value is indirect, the workflow is highly collaborative, outcomes are difficult to attribute to a single tool, or quality matters more than throughput.
Finally, both vendors and buyers will need to adapt over time as contracts renew and AI agents are deployed into production. Product teams will need better telemetry, proof of work, and clear usage definitions. Procurement teams will need new benchmarks and to better understand their internal value drivers. Vendor revenue models may also become more variable as they depend directly on usage, not static licensing measures. Similarly, budgeting models may become more dynamic for customers.
A shift toward more defensible pricing units
Security pricing is unlikely to become “perfectly” value-based any time soon. The security industry will not suddenly discover a universal formula for measuring and thus pricing risk reduction. But the rise of AI agents does create something the market has lacked for a long time: a more visible and defensible unit of work and associated pricing.
This may prove to be one of the most important commercial consequences of AI in cybersecurity: a shift away from broad pricing proxies such as seats and endpoints toward models tied more directly to more meaningful and auditable outputs. Even if the near-term result falls short of pure outcome-based pricing, it would still represent an important economic improvement by aligning pricing more closely with customer value.