In August 2025, two rooms at DEF CON told the same story from opposite ends. In one, DARPA’s AI Cyber Challenge put autonomous systems on stage to read unfamiliar code, find the flaws, and prove the patches held, with no human at the keyboard. A few halls away, at the AI Village, machines ran the other direction: mapping a target, chaining its weaknesses, breaking in, and getting sharper with every failure. Two rooms, one fact. Both sides now learn at machine speed.
That fact quietly retires the way the security industry has organized itself for a generation. For thirty years we bought controls and counted them: antivirus, firewalls, the SIEM, the EDR, a product for every verb in detect, prevent, respond. Underneath all of it sat an assumption so old nobody said it aloud, that the defender was the bigger, better-resourced mind and the attacker could not out-think a well-run shop. When expert reasoning costs almost nothing and is available to everyone, that assumption is gone. The bigger brain stopped being something you could own.
The moat moved from tools to loops
Here is the uncomfortable part for anyone with a booth. Every defensive product is an artifact, and every artifact teaches. A detection signature encodes what an analyst learned about a family of attacks; publish it, or let it fire once, and it tells the adversary exactly what to evade. A tuned classifier is a compression of yesterday’s labels. A patch is the fossil of a fixed bug. Each is real work. None of it is a moat, because each can be reconstructed, routed around, or simply out-iterated by the same cheap cognition the other side just bought.
What does not commoditize is the loop that produces the next capability faster than the adversary retires the last one: capture what happens, connect each decision to how it turned out, ground the models in what has actually been validated, and improve. A tool has a coverage number. A loop has a rate and a direction. Those two properties are the only ones cheap cognition does not level, because they come from operating a real environment over real time, and that is the one input a competitor cannot download.
So the contest is a race between two learning systems. And a race between learning systems has an ugly symmetry: if both sides think at machine speed on the same commoditized models, why does either one ever win?
The question nobody is measuring
Cryptography answered a version of this question decades ago, and it answered it with a number. A modern cipher does not ask you to trust that its designers were clever. It tells you, in bits, what breaking it must cost. The promise is not “we tried hard.” The promise is a work factor, stated in advance, independent of how ingenious the attacker is.
Cybersecurity has never had that number for the thing that now matters most: not whether your machine was compromised, but whether its judgment was. So ask it plainly. What does it cost to make a learning machine believe a lie, and keep believing it?
Today’s answer is humiliating. Research through 2025 and 2026, still lab work rather than fielded practice and carried with that caveat, has repeatedly shown that poisoning a fraction of a percent of what a model learns from, on the order of a few documents in a few thousand, is enough to flip a learned decision. Call it one forged document in two thousand. In cryptography’s vocabulary, the work factor of a lie is about one. One cheap, well-placed input can buy a consequential decision, and deleting it afterward undoes none of what it taught.
We would never ship a cipher with one bit of security. We would not call it a cipher. Yet that is roughly the integrity guarantee under which the industry is now wiring autonomous systems into its defenses. The scandal is not that poisoning works. It is the price.
Make the lie prove itself
The title of the book this essay is drawn from is a play on proof-of-work, the mechanism that makes a blockchain claim expensive to assert. A learning loop built correctly should do the same thing to deception. Before the machine believes, a falsehood should have to supply its proof of lie: the volume of independent-looking reality an adversary must forge to push a conclusion over the loop’s threshold. The whole program of a serious defense, in one sentence, is to raise that price from one toward something a liar cannot afford, and to make everything under it reversible.
And here is the turn that makes the fight winnable, because it does not depend on having a smarter machine than the other side. It depends on a property of information itself.
Truth is redundant. A lie is not.
A true state of the world is corroborated from many uncorrelated directions, because reality leaves evidence everywhere it touches. Accumulating that evidence is cheap for whoever is telling the truth. A lie has no such backing. To be believed, it must manufacture the independence it does not have, forging enough uncorrelated-looking sources to cross the line, and then hold that forgery in place against a loop that keeps re-checking its conclusions and revoking whatever fails to corroborate. Corroboration is cheap for truth and expensive for a lie, and the gap between those two costs is the defender’s edge. It is not a feature you can buy. It is a law you can build on.
The part that should keep you up
Scale that question past a single corpus and it gets darker, which is where the book goes and this essay only points. In 2026, researchers described state-run operations building fake reference sites and institutes for an audience of machines, to shape what AI systems learn as fact. When cognition is cheap, the high ground is no longer any model. It is the corroborated record that everyone’s models are trained and grounded on, and it is under deliberate attack.
Closer to home, there is the problem every metric in security eventually hits: the moment a number decides budgets, it becomes a target, and three sets of hands reach for it, the defender’s, the vendor’s, and the adversary’s. Which surfaces the hardest question in the field, and it is not a technical one at all. Who grades the defenders, when almost every grader is paid by the graded? The autonomous pentester is scored against its own findings. The AI SOC grades its own triage. The benchmark is run by the party it ranks. Independence, it turns out, is the one thing no vendor can supply for itself, and the scarce asset the whole industry is short of.
What comes after the smart machine
None of this is a counsel of despair, and it should not read as one. Every advantage that cheap cognition erases for the defender, it erases for the attacker too, and what survives the leveling structurally favors the side that lives closest to the truth. Reality keeps handing out its corroboration for free. Checking a claim stays cheaper than forging one. The contest after intelligence is not who thinks best. It is who can prove what they know, price what a lie would cost, and afford to unlearn what turns out to be poison.
The moat was never the smarter machine. It was knowing what it costs to fool one, and building so that a lie can never again be cheap.
Sava Marinkovich is the author of Proof of Lie: Learning Faster Than the Adversary in Cybersecurity’s Zero-Cost-Cognition World (Judgement Press, 2026). The essay is the doorway. The book is the instrument: how a modern defense learns, where that learning can be poisoned, how to measure both, and who has the independence to say any of it is real.
Proof of Lie publishes in 2026. Leave your email on the book page and we’ll notify you the moment pre-orders open.