Safety Becomes a Luxury Good When AI Agents Do the Work

Every security leader has lost this argument at least once. You’re in a planning meeting, you flag that a system needs a real verification step, a proper check before it acts, and someone with a budget line asks the question that ends the conversation: “Do we actually need that, or is it gold-plating?” The control is slower. It costs money. The feature ships sooner without it. And so, quietly, it doesn’t get built, and everyone agrees to revisit it later, which means never.

Now scale that single meeting up to an entire market of AI agents competing on price and speed, and you have one of the sharpest warnings in DeepMind’s recent paper on intelligent delegation. The researchers put it plainly: if checking an agent’s work is expensive, safety becomes a luxury good. That phrase deserves a security leader’s full attention, because it describes a failure mode you can already feel forming.

Verification is not free, and that’s the whole problem

The things that make delegated AI work trustworthy, rigorous verification of outputs, cryptographic proofs that a task was done correctly, multiple agents cross-checking each other, a human in the loop on consequential calls, all cost something real. They add latency. They burn compute. They need people. This is the premium to pay for reliability and is similar to the software quality assurance discipline – the price you pay, in time and money, to actually know the work was done right rather than just assuming it was.

And here’s the trap. In a competitive market, the agent or the vendor that skips the premium is faster and cheaper. The one that pays for thorough verification looks slow and expensive next to it. So the market, left to itself, rewards exactly the wrong behaviour: cut the checks, win on price, and let the consequences land later and elsewhere. This isn’t speculation about some distant future. A paper published just this year modelled the same dynamic at the level of the AI labs themselves and described it as a collective-action problem, every firm would privately prefer a slower, safer race, but no single one can afford to slow down while the others sprint. What’s true for the labs is true inside your own walls, and true for every vendor pitching you an agentic tool.

The two ways this bites you

This plays out in two directions, and a CISO is exposed on both.

The first is your vendors and the market you buy from. When you’re choosing between agentic tools, the cheaper one will often be cheaper precisely because it skipped the verification you can’t easily see. The expensive one may be expensive because it does the checking properly. If you procure on price alone, you are systematically selecting for the tools that cut the corners, and you won’t find out which corners until something fails. Cheap and “good enough” is exactly how an unverified agent gets into your environment, the same way cheap-and-good-enough is how anything risky gets adopted without a decision being made.

The second is inside your own organisation, and it’s the part the paper warns about most directly. If high-assurance verification is expensive, then within your business the teams and use cases with budget get the safe, checked, monitored version, and the teams without it get the cheap, optimistic, unverified path. Safety stops being a baseline and becomes a tier you can afford or can’t. The well-funded product line gets human oversight on its agents; the cost-pressured back-office function runs them unchecked, on the quiet assumption that nothing there matters enough to verify. That assumption is usually wrong, and it’s where the breach comes from.

You cannot let the market set your safety floor

The instinct under cost pressure is to make verification proportionate, light-touch where you can afford it, skip it where you can’t. That instinct is right up to a point and catastrophic past it, because it lets your budget, rather than your risk, decide what gets checked. The paper’s answer, and mine, is that some things are not negotiable regardless of cost.

  • Define a minimum verification floor that cost cannot breach. Decide, deliberately, which classes of agent action always get verified no matter which team runs them or how tight their budget is, anything that moves money, touches regulated data, changes access, or can’t be undone. Below that floor you can tier and economise. At or above it, “we couldn’t afford the check” is not an acceptable sentence. The floor is set by consequence, not by department spend.
  • Make the safe path the cheap path wherever you can. A lot of the “safety is expensive” framing is a false binary. Verification that’s built into the platform, automated, and reused across teams costs far less per use than a bespoke check bolted on each time. If safety is only available as an expensive add-on, you’ve designed it to be skipped. Invest once in shared, default verification so the cheapest path for your teams is also the checked one, and you defuse most of the luxury-good problem before it starts.
  • Interrogate cheap vendors on what they left out. When an agentic tool undercuts its competitors significantly, treat that as a question, not a bargain. Ask precisely what verification, monitoring, and oversight the price does and doesn’t include. Sometimes cheap is genuinely more efficient. Sometimes cheap is the reliability premium quietly removed and handed to you as risk. You need to know which, before you sign, not after.

The longer-term cost the paper points at is subtler and worse: a world where the careful, verified way of doing things prices itself out, and a generation of systems, and the people running them, simply never learn what good and safe looked like, because the market never paid for it. You can’t fix the whole market. But you set the floor inside your own organisation, and you decide whether safety there is a baseline everyone stands on or a luxury only some budgets can reach. If you let cost make that call, it will choose cheap over safe every single time, and you will find out which tasks needed the floor only after one of them fails without it.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

Responses