The Hidden Cost Explosion
AI finds more risk. Supplier dependence, regulatory clocks, insurer proof, and board defensibility turn that risk into administrative work. The hidden cost is the work of proving security across all of those surfaces at once.
CVE submission growth from 2020 to 2025, cited from NIST.
Average weekly vendor assessment work in Whistic's 2025 survey.
Initial supplier assessments requiring follow-up in the same survey.
Regulatory clocks increasingly convert proof into timed work.
Inspect the public evidence and the model assumptions.
Proof work grows fastest when the pressures collide.
This model starts 2022 at a baseline and shows how finding volume, supplier review, regulatory clocks, and insurance proof combine into more administrative work.
Modeled growth in proof workload from the 2022 baseline to 2028.
Share of the 2028 modeled workload created by interactions between drivers.
Modeled index, not a market forecast. Replace assumptions with run data.
Row detail
Select a row to see the fields behind the chart. Public-source rows carry source IDs and caveats where the source provides them.
- year
- 2028
- Finding pressure
- 5.4
- Supplier exposure
- 2.25
- Regulatory clocks
- 2.4
- Insurance proof
- 2.05
- Supplier interaction
- 1.2302
- Regulatory interaction
- 0.729
- Insurance interaction
- 0.3113
- Direct driver load
- 12.1
- Work created between drivers
- 2.2705
- Modeled proof workload
- 14.3705
- Interaction share
- 0.158
- source tier
- Evident model
- caveat
- Indexed model from the research paper; not a measured market forecast.
Optimization target: economic impact, not just passing proof.
Evident's trust graph should not stop when proof exists. It should ask whether proof was rejected, whether an incident created real cost, whether admin cost missed its target, and where reusable evidence can reduce the next cycle.
Every public claim stays attached to a source tier and caveat.
| Publisher | Source | Tier | Status |
|---|---|---|---|
| AI Incident Database | AI Incident Database Snapshots | Public primary | registered |
| CISA | Known Exploited Vulnerabilities Catalog | Public primary | downloaded_1623_records |
| Cloud Security Alliance | STAR Level 1 Security Questionnaire CAIQ v4 | Public primary | registered |
| CVE Program | CVE List V5 | Public primary | registered |
| European Commission | Cyber Resilience Act Reporting Obligations | Public primary | registered |
| European Union | Digital Operational Resilience Act | Public primary | registered |
| European Union | NIS2 Directive | Public primary | registered |
| FIRST | EPSS Current Scores | Public primary | downloaded_341602_records |
| HHS OCR | Breach Portal Notice to the Secretary of HHS Breach of Unsecured Protected Health Information | Public primary | registered |
| MITRE | CWE List | Public primary | registered |
| MITRE | MITRE ATLAS Data | Public primary | registered |
| NAIC | Cyber Insurance Report | Public primary | registered |
| NAIC | Report on the Cybersecurity Insurance Market | Public primary | registered |
| NIST | NVD CVE API 2.0 | Public primary | downloaded_4000_records |
| OMB/OIRA | OMB/OIRA Paperwork Burden Inventory | Public primary | registered |
| OWASP Foundation | OWASP Top 10 for LLM Applications | Public primary | registered |
| SEC | Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure | Public primary | registered |
| Shared Assessments | What's New in the 2025 SIG Update | Public survey/vendor | registered |
| Whistic | Third-Party Risk Management 2025 Impact Report | Public survey/vendor | registered |