HomeBenchmarksIT Security / SecOps › Alert Triage
IT Security / SecOps

How much does an AI agent cost to run Alert Triage?

Token cost benchmark for an autonomous Alert Triage agent, across 13 models. Prices as of 14 Jun 2026.

An agent for Alert Triage on the clean path costs about $0.0377 to $2.60 per outcome depending on the model, around 33x the cost of a single chat message. At 10,000 outcomes a month that is roughly $377 to $25,980.
Estimate your own numbers →

Cost per outcome by model

Model$/1M in$/1M outCost / outcomeCost / month*
GPT-4o mini$0.15$0.60$0.0377$377
Llama 4 Maverick$0.27$0.85$0.0659$659
Gemini 2.5 Flash$0.30$2.50$0.0863$863
GPT-4.1 mini$0.40$1.60$0.101$1,006
DeepSeek V4$0.44$0.87$0.103$1,031
Claude Haiku 4.5$1.00$5.00$0.260$2,598
Gemini 2.5 Pro$1.25$10.00$0.356$3,562
Mistral Large 3$2.00$6.00$0.486$4,860
GPT-4.1$2.00$8.00$0.503$5,028
GPT-4o$2.50$10.00$0.628$6,285
Claude Sonnet 4.6$3.00$15.00$0.779$7,794
Claude Opus 4.8$5.00$25.00$1.30$12,990
Claude Fable 5$10.00$50.00$2.60$25,980

*At 10,000 outcomes per month. Cheapest model highlighted.

What this agent does

The clean-path steps this benchmark prices:

  1. Deduplicate & Group
  2. Enrich (asset, user, IOC)
  3. Known false positive?
  4. Correlate Events
  5. Score Severity
  6. Malicious?
  7. Critical / active?
  8. Auto- containable?
  9. Auto- Contain
  10. Confidence high?

What drives the cost

This path runs 10 steps: 4 tool calls, 1 reasoning step, 5 decision points and 0 human checkpoints. Tool steps make two model calls each, and the agent re-reads its growing context on every call. That compounding is why one Alert Triage outcome costs about 33x a single chat message ($0.779 on Claude Sonnet 4.6), not the price of one message.

Why these numbers matter.

Frequently asked questions

How much does an AI agent cost to run Alert Triage?

On the clean path with default assumptions, an agent for Alert Triage costs about $0.0377 to $2.60 per outcome depending on the model, or roughly $377 to $25,980 per month at 10,000 outcomes. The cheapest model here is GPT-4o mini at $0.0377; the most expensive is Claude Fable 5 at $2.60.

Why does an AI agent cost more than a single chatbot message?

An agent does not make one model call. It plans, calls tools, retrieves context and re-reads its growing working context on every step. For Alert Triage that adds up to about 33x the cost of a single chat message.

Which model is cheapest for Alert Triage?

Across the 13 models benchmarked, GPT-4o mini is cheapest at $0.0377 per outcome and Claude Fable 5 is the most expensive at $2.60. A cheaper model is not always the right choice, but it sets the floor for this workflow.

How can I reduce the cost of an agent for Alert Triage?

The biggest levers are prompt caching on the base context, fewer planning loops, smaller tool results, less retrieval, and choosing a cheaper model where quality allows. You can test each lever in the live estimator.

More IT Security / SecOps benchmarks

Open Alert Triage in the live estimator →