HomeBenchmarksIT Security / SecOps › Incident Response
IT Security / SecOps

How much does an AI agent cost to run Incident Response?

Token cost benchmark for an autonomous Incident Response agent, across 26 models. Prices as of 26 Jul 2026.

An agent for Incident Response on the clean path costs about $0.0433 to $2.97 per outcome depending on the model, around 38x the cost of a single chat message. At 10,000 outcomes a month that is roughly $433 to $29,750.
Estimate your own numbers →

Cost per outcome by model

Model$/1M in$/1M outCost / outcomeCost / month*
GPT-4o mini$0.15$0.60$0.0433$433
Llama 4 Maverick$0.27$0.85$0.0758$758
Gemini 2.5 Flash$0.30$2.50$0.0983$982
GPT-4.1 mini$0.40$1.60$0.115$1,154
DeepSeek V4$0.43$0.87$0.118$1,177
Mistral Large 3$0.50$1.50$0.140$1,397
Qwen3.5 397B$0.60$3.60$0.184$1,839
Kimi K2.6$0.95$4.00$0.276$2,759
Claude Haiku 4.5$1.00$5.00$0.297$2,975
Grok 4.3$1.25$2.50$0.338$3,381
Qwen3.7 Max$1.25$3.75$0.349$3,494
GLM-5.2$1.40$4.40$0.393$3,931
Gemini 2.5 Pro$1.25$10.00$0.406$4,056
Mistral Medium 3.5$1.50$7.50$0.446$4,462
Gemini 3.5 Flash$1.50$9.00$0.460$4,598
GPT-4.1$2.00$8.00$0.577$5,770
Claude Sonnet 5$2.00$10.00$0.595$5,950
GPT-4o$2.50$10.00$0.721$7,212
GPT-5.4$2.50$15.00$0.766$7,662
GPT-5.6 Terra$2.50$15.00$0.766$7,662
Claude Sonnet 4.6$3.00$15.00$0.892$8,925
Kimi K3$3.00$15.00$0.892$8,925
Claude Opus 4.8$5.00$25.00$1.49$14,875
GPT-5.5$5.00$30.00$1.53$15,325
GPT-5.6 Sol$5.00$30.00$1.53$15,325
Claude Fable 5$10.00$50.00$2.97$29,750

*At 10,000 outcomes per month. Cheapest model highlighted.

What this agent does

The clean-path steps this benchmark prices:

  1. Gather Telemetry
  2. Scope Blast Radius
  3. Major severity?
  4. Auto- containable?
  5. Contain & Isolate
  6. Collect Forensics
  7. Threat eradicated?
  8. Restore & Validate
  9. Generate Report

What drives the cost

This path runs 9 steps: 6 tool calls and 3 decision points. Tool steps make two model calls each, and the agent re-reads its growing context on every call. That compounding is why one Incident Response outcome costs about 38x a single chat message ($0.892 on Claude Sonnet 4.6), not the price of one message.

Why these numbers matter.

How this benchmark is calculated

These figures are modeled estimates, not metered bills. We price a generic, representative Incident Response workflow across 26 models using the same cost engine as the live estimator, at each model’s published list price (checked 26 Jul 2026), under documented default assumptions for planning loops, tool calls, memory retrieval, sub-agents and context size. Your own process will differ, so use these as starting points, tune the assumptions in the estimator, and validate against your real usage. Illustrative estimates, not financial advice.

Frequently asked questions

How much does an AI agent cost to run Incident Response?

On the clean path with default assumptions, an agent for Incident Response costs about $0.0433 to $2.97 per outcome depending on the model, or roughly $433 to $29,750 per month at 10,000 outcomes. The cheapest model here is GPT-4o mini at $0.0433; the most expensive is Claude Fable 5 at $2.97.

Why does an AI agent cost more than a single chatbot message?

An agent does not make one model call. It plans, calls tools, retrieves context and re-reads its growing working context on every step. For Incident Response that adds up to about 38x the cost of a single chat message.

Which model is cheapest for Incident Response?

Across the 26 models benchmarked, GPT-4o mini is cheapest at $0.0433 per outcome and Claude Fable 5 is the most expensive at $2.97. A cheaper model is not always the right choice, but it sets the floor for this workflow.

How can I reduce the cost of an agent for Incident Response?

The biggest levers are prompt caching on the base context, fewer planning loops, smaller tool results, less retrieval, and choosing a cheaper model where quality allows. You can test each lever in the live estimator.

What is this Incident Response benchmark based on?

These are modeled estimates, not metered bills. Each figure prices a generic, representative Incident Response workflow across 26 models with the same cost engine as the live estimator, at each model's published list price (checked 26 Jul 2026), under documented default assumptions for planning loops, tool calls, memory retrieval, sub-agents and context size. Your own process will differ, so treat these as starting points, tune them in the estimator, and validate against your own usage.

More IT Security / SecOps benchmarks

Beyond cost: is it ready, and can you govern it?

Cost is one axis. Before you build, check the process is ready for AI and that you can prove you govern it. See how governed AI process animations work →

Open Incident Response in the live estimator →