Capability is not what separates an attacker from a defender. Incentives are.
Ben Thompson’s Stratechery piece of 24 August 2026 works this through in agentic cybersecurity, and the logic travels a long way past security. An attacker’s automated agent carries positive expected value. If the exploit fails, nothing has changed. If it lands once, the attack has paid for itself. A defender’s automation carries the opposite. A good patch only preserves the status quo, while a bad one breaks the software or opens a fresh hole. So offence automates completely, defence keeps a human in the loop, and no human in the loop keeps pace with an agent. Thompson then applies the same asymmetry to incumbents and startups. An established company judges AI by the mistake it might make, so AI stays a productivity tool. A startup, whose base case is failure already, has nothing to lose by automating everything. Same tools, different incentives, very different outcomes.
What this means for IP strategy
The durable lesson is that this risk calculus is quietly setting your filing decisions as well as your deployment decisions. Three things follow.
– The defender’s advantage is ownable. Only the defender holds the code, the dependency map and the operational telemetry. That advantage compounds only if it is captured – patents over the closed remediation loop of detect, propose, deploy and roll back, and controlled trade secrets over the pipelines and data that make the loop work. It is the same pattern as in When Everyone Can Run the Model: What Open-Weight AI Means for Your IP Strategy – once the capability commoditises, what is left to own is the machinery around it.
– The human you remove from the loop was also doing IP work. They knew what was confidential, what was privileged and where a draft came from. Take them out without rebuilding the controls and the reasonable steps your trade secret protection rests on leave with them, which is the exposure in Your AI Agent Won’t Keep a Secret.
– The incentive gap shows up on the register. Companies treating AI as a productivity gain file nothing new. AI-native entrants file around workflows that did not exist two years ago, which is the ownership question in When Anyone Can Build It in an Afternoon, What’s Left to Own?.
The useful question for your next board paper is not how much AI you have deployed. It is what you filed, and what you locked down. Caution about deploying is defensible. Caution about owning is a slower way to lose the same position.
Read the article: Autonomy and Innovation, Ben Thompson, Stratechery, 24 August 2026.

