The AI Layoff Trap: Why No CEO Can Stop It in 2026
The AI layoff trap is what two economists say happens when companies replace workers with AI faster than the economy can reabsorb them, and their finding isn't another headcount prediction. It's that the CEOs driving this can see the cliff, understand it, and still not stop. Brett Hemenway Falk at the University of Pennsylvania and Gerry Tsoukalas at Boston University set it out in a 63-page paper on arXiv, also listed as a Wharton School research paper.
We'll walk through what the trap is, why rational executives race at it anyway, which of six proposed fixes survives the maths, and what it means for your cyber security career. I'll flag where their model stops and my opinion starts.
What the AI Layoff Trap Actually Says
The idea underneath it is old and slightly uncomfortable: the people companies lay off are also the people who buy things.
The paper opens with the evidence that this has stopped being hypothetical. In February 2026 Block cut close to half of its roughly 10,000 staff, with Jack Dorsey saying AI had made many of those roles unnecessary and predicting that "within the next year, the majority of companies will reach the same conclusion." Across 2025, US employers announced over a million job cuts, with AI named explicitly in about 55,000 of them, concentrated in customer support, content moderation and middle management.
Tsoukalas explained it on the BBC's New Normal with Katty Kay with a thought experiment worth borrowing. Imagine one enormous company, a monopoly, making widgets, and everyone in the economy works there. AI arrives. The CEO could automate away 90% of staff. But those staff are the customers. So the monopolist does the sums, sees that firing everyone destroys its own market, and automates some but not all. It self-corrects. Nobody needs to intervene.
Then add competitors, and the whole thing inverts.
Now you're one of a hundred widget companies. You still save the full cost of every worker you replace, and that saving lands entirely on your P&L. But the demand you destroy? Your ex-employees weren't spending all their money with you. They were spreading it across all hundred firms. So you personally absorb roughly a hundredth of the damage you cause. The other ninety-nine percent lands on your rivals.
That asymmetry is the trap. In the paper's notation each firm bears only ℓ/N of the demand loss it creates while capturing 100% of the cost saving. Every firm faces the same maths, every firm automates, and demand erodes for all of them.
Which raises the obvious question, and it's the one the interviewer went straight to.
Why Rational CEOs Drive at the Cliff Anyway
The obvious objection is the one Katty Kay put to Tsoukalas directly: CEOs aren't stupid. If they can see the cliff, why drive at it?
Because seeing it doesn't help. That's the part that makes the paper worth reading rather than just nodding along to.
In game theory terms, once a market is competitive enough to tip into the trap, automating becomes a strictly dominant strategy. That's a precise thing, not a figure of speech. It means automating is your best move regardless of what everyone else does. If your rivals hold back, you automate and win on cost. If your rivals automate, you have to automate or you're carrying a cost base they've shed. In that regime there's no version of the board where restraint pays. Tsoukalas put it plainly: "no matter what you do, no matter what the other companies are doing, your best strategy is to adopt as much of this technology as possible."
Strip out the friction of integrating AI and the model collapses into a textbook Prisoner's Dilemma. Everyone defects, everyone ends up worse off than if they'd all held back, and no amount of understanding changes anyone's move.
Two findings here run against intuition hard enough that I had to re-read them.
More competition makes it worse. We're trained to think competition disciplines firms. Here it does the opposite: the more firms there are, the smaller each one's share of the damage, and the weaker the incentive to restrain. A monopolist internalises the whole externality and behaves. A fragmented market is where the wedge is widest.
Better AI makes it worse too. You'd assume more productive AI grows the pie and eases the problem. The paper finds it widens the gap. Firms chase market share on top of cost savings, so the corrective tax needed actually gets bigger as AI improves.
This is a stylised model
Symmetric firms, one sector, fixed wages in the baseline. The authors relax those assumptions later and the result holds, but it demonstrates a mechanism, not a forecast. It doesn't prove the economy is in this regime right now. Worth saying too: on the "better AI" result, the authors are careful that they've identified a strategic distortion, not a claim that more productive AI reduces total welfare on net.
Why AI Job Displacement Hurts Shareholders Too
There's a comfortable reading of automation that goes: workers lose, capital wins, and that's just how the pie gets re-sliced.
The paper closes that door. Over-automation here isn't a transfer from labour to shareholders. It's a deadweight loss. Workers lose income directly. But firm owners lose as well, because the collective demand destruction pushes every firm's profit below what they'd have made with mutual restraint. The equilibrium is Pareto dominated, which is the technical way of saying both sides could be better off and neither can get there alone.
And redistribution alone doesn't fix it, because moving money between the two groups doesn't change the decision that shrank the pie in the first place. Correcting that takes an instrument aimed at the automation decision itself, which is where the paper goes next.
That's why I don't think this is a "labour versus capital" story. The authors make the point sharply: their planner would want to reduce automation even with zero weight on workers, purely because over-automation hurts profits.
So if everyone loses, something ought to be able to fix it. The authors tested six candidates.
Six Fixes Tested, and Why Only an Automation Tax Works
Falk and Tsoukalas run six proposed remedies through the model. Only one corrects the problem.
Universal basic income doesn't work here, and not because it's a bad idea. The authors are careful that this is a verdict on the specific version they model, an unconditional payment funded from general revenue, rather than on every UBI design. It fails because it operates in the wrong place. UBI adds a constant to demand. The automation decision is driven by the marginal cost and benefit of each replaced task, and a constant cancels out. In their words, it "raises the floor on living standards but leaves the automation incentive unchanged." Same for a capital income tax: scaling profits by (1−t) cancels from the first-order condition entirely.
Worker equity helps but can't close the gap, and worse, no firm will do it voluntarily. Sharing profits costs a firm a pound for every pound shared, while returning only a fraction of a pound in recovered demand. Not sharing is dominant. It has to be mandated.
Coasean bargaining fails for the reason the whole paper exists: automation is dominant, so no voluntary agreement is self-enforcing. Tsoukalas illustrated this with Odysseus and the sirens. The crew tie him to the mast precisely because he knows he'll want to steer for the rocks. His version of the corporate case: get Anthropic, OpenAI, Microsoft and Google in a room, agree to slow down, and "as soon as you walk out of that room… you immediately look at the gains you can get from adopting AI now that you know that no one else will." Not cynicism. Fiduciary duty.
Upskilling and retraining are the sixth, and they do more than cushion the losers. They raise the share of displaced income that comes back into the economy, which shrinks the damage directly. But they only close the gap completely at the point where displacement stops costing anyone income at all, which is the edge of the problem rather than a fix inside it. A real lever, not a cure.
What does work is a Pigouvian automation tax: a per-task charge equal to the damage a firm imposes on everyone else. Charge each firm for the demand loss it exports, and private incentives line up with the collective interest.
Tsoukalas added a design detail in the BBC interview that I keep thinking about. This is his framing in the interview, not a formal result in the paper: the tax would make it costly to fully replace a worker, but not costly to augment one with AI. The closest existing analogue, he suggested, is a carbon tax.
Whether any of that is politically survivable is a different question. He knows it: "because the word tax is pretty toxic, it might not be directly implementable this way."
He's not saying nothing can be done. He floats subsidies for firms that keep staff, and the paper finds that retraining, wage insurance and worker equity all narrow the gap even where they can't close it. But none of that arrives on a timescale you control. So alongside the policy question, there's a more immediate one: what determines who the trap actually catches.
Job Displacement Due to AI: The Reabsorption Channel
The paper gets more interesting than its headline at this point, and this is where I'd point anyone whose first reaction to all of the above is despair. Job displacement due to AI isn't modelled here as a one-way street.
The severity of the trap is governed by a parameter the authors call η: the income-replacement ratio, measuring recovered income against displaced wage income across a whole sector, through re-employment, retraining, or transfers. Low η means displaced income vanishes and the trap bites. And there's a threshold. If η rises above 1, meaning reabsorption puts people into work that pays more than what they lost, the entire distortion flips sign. Firms would then be automating too slowly.
The authors name the AI buildout itself as a live channel for this: data centres, energy infrastructure, AI-adjacent skilled work that can pay better than the roles being automated.
Two limits on that
η is a sector-wide parameter, not something an individual can choose. It describes an economy, not a career. And every past displacement episode has landed η below 1: displaced workers historically suffer large, persistent earnings losses, and there's no evidence yet that AI is different. The authors' own table marks retraining as only a partial fix.
So no, this isn't a hidden escape hatch, and I want to be careful not to smuggle a career conclusion out of a macroeconomic parameter. η describes whether an economy reabsorbs displaced income. It says nothing about which individual ends up where, and a durable job is not evidence that η has risen.
What the paper does establish is that reabsorption runs through work that pays better than what it replaced. Whether such work exists in cyber security, and which roles it covers, is a separate question the paper never asks. It's one our own data can.
Will AI Take My Job? Same Profession, 74-Point Gap
At JobZone we score how resistant a role is to AI displacement, 0 to 100, higher is safer. The score comes from task analysis, market evidence, structural barriers, and whether AI growth increases or decreases demand for that role.
Inside cyber security, the spread is stark:
| Role | JobZone Score | Zone |
|---|---|---|
| CISO (Executive) | 83.0 | 🟢 Green (Accelerated) |
| AI Security Engineer (Mid) | 79.3 | 🟢 Green (Accelerated) |
| OT/ICS Security Engineer (Mid) | 73.3 | 🟢 Green |
| Cyber Security Analyst (Mid) | 22.9 | 🔴 Red |
| Junior Penetration Tester | 6.4 | 🔴 Red |
| SOC Analyst Tier 1 | 5.4 | 🔴 Red (Imminent) |
| Vulnerability Tester | 2.7 | 🔴 Red (Imminent) |
AI Security Engineer sits at 79.3. SOC Analyst Tier 1 sits at 5.4. That's a 74-point gap inside one profession, which is why "will AI take my job" has no single answer for cyber security. It depends entirely on which row you're standing in. And the pay tracks the durability: the scarce end of the field commands a real premium, with Glassdoor reporting AI Security Engineer salaries around $180k in the US.
If you're in one of those red rows, I'm not going to pretend otherwise, and I'm also not going to leave you there. The assessments carry exit routes, and they're adjacent rungs rather than leaps:
SOC Analyst Tier 1 → Detection Engineer. Your alert and triage knowledge is the raw material for writing detections. Tier 2 also has an AI-driven future in a way Tier 1 doesn't.
Vulnerability Tester → Application Security Engineer. Finding vulnerabilities converts directly into securing applications and building the tooling, the same skills that underpin penetration testing work. Or → Security Architect, where the design judgement lives.
What these scores are and aren't
They're our assessment of durability, not observed survival data, and the AI Security Engineer number carries three caveats we publish alongside it: the salary premium partly reflects a genuine shortage of people who can do both AI and security, so if supply catches up the premium compresses even with demand intact; the job title may get absorbed into plain "Security Engineer" the way Cloud Security did; and the tooling is improving fast enough to shift the task mix over three to five years. Worth separating those two things, though: a compressing salary premium isn't the same as the work drying up. On our own assessments the demand signal for the scarce end of AI security is still rising, even where the wage premium might ease.
Being AI-Driven Is the Durable Thing, and Agentic Engineering Is How
There's a distinction here that's easy to get backwards, and getting it right is the whole point.
The durable thing isn't a job title. It's a way of working. My view, from watching it across our own cyber and engineering work, is that directing AI to build and run solutions, instead of operating the tools by hand, is the force multiplier, and it lowers your odds of being displaced in any role that still has scarce human judgement to own. An AI-driven engineer or analyst is harder to replace than their by-hand equivalent, because the AI does the doing while the human does the deciding.
One honest caveat, because it matters. The method multiplies a core; it doesn't conjure one. If a role is pure repeatable middle with nothing scarce underneath, directing AI at it doesn't save the role, it just means you've become a different, more senior one. A Tier 1 SOC analyst who learns to direct AI hasn't secured the Tier 1 job. They've become a detection engineer. The method moves you up; it doesn't freeze you in place.
Agentic engineering is the name for the method. It's Andrej Karpathy's term for coordinating AI agents to do professional work without dropping the quality bar. You build tooling that runs thousands of tasks while you sleep, then spend your own time on the part no tool reaches: the judgement, the design, the sign-off. I've written up how the four tiers of it actually work separately, so I won't repeat it here.
Point that method at a scarce, high-stakes domain and it compounds. Security is the sharpest one I know. It's where a mistake costs the most, where "fast but broken" isn't a bug but a breach, and where the underlying judgement was already scarce before AI arrived. The AI Security Engineer score of 79.3 measures that domain scarcity, the role as it's done today, by hand or otherwise. It scores high because securing systems nobody fully understands yet is genuinely hard to automate, not because the work happens to involve AI. What being AI-driven adds is separate and on top: the person who directs AI across that scarce work does what a team used to, which is the difference between riding the domain and being left on its commoditising floor.
My read, and I'll own this as opinion rather than dress it up as a finding: the trap is unstoppable at the level of firms, but the individual answer is to become the one directing the AI rather than the one it replaces. The economists supply the first part. The second is mine.
Around 80% of StationX now runs on AI infrastructure I built this way. Not prototypes. The security scanning across our servers and repositories, the vulnerability triage, the multi-agent code reviews that have to come back clean before anything ships.
Two things guard the code, and neither trusts the AI to behave. A Lefthook gate fires on every push and blocks it unless the full test suite, a Semgrep security scan and the dependency check all pass. Separately, when I want real scrutiny, a review runs the diff past three different model families at once, Claude, OpenAI's and Google's, because the thing you don't want is one AI marking its own homework. It flags real problems regularly, the kind that used to take two or three people reading by hand. And honestly it's stopped feeling remarkable, which is sort of the point. This is just how the work happens now.
And this answers the objection I'd expect you to raise about everything above. If the ladder from SOC Tier 1 to something durable takes years, and the tooling keeps improving, aren't you climbing toward a target that's moving away from you?
Yes. Which is exactly why the title matters less than the capability. Job titles rotate. "AI Security Engineer" may well get absorbed into something else by 2030. What transfers is being the person who builds the tooling and owns the judgement it can't replace. That's portable across whatever the role ends up being called.
If you want to build that, it's what our AI Master's Program teaches — it turns you into an AI-driven security engineer who directs AI to build real, secure solutions.
Earlier in the journey? The free web-book Become the Cyber Security Expert the AI Era Demands is where to start.
Where This Leaves Us
The paper's contribution isn't the warning. We've had plenty of those. It's the proof, inside a model and with stated assumptions, that understanding the danger isn't sufficient to avoid it. Every firm can see the cliff. Every firm drives at it anyway. That's not a failure of intelligence or ethics; it's what the incentives produce.
Tsoukalas is honest that economists are split: "no one agrees about this very question. Half people are on one side, half the people on the other." I'd rather hand you that than pretend the case is closed.
But his closing line is the one I'd underline. "Waiting for the firms to figure it out for themselves, I think is the worst possible thing we can do."
That's addressed to policymakers. I'd say it applies to careers too.
Frequently Asked Questions
What is the AI layoff trap?
The AI layoff trap is a market failure identified by Brett Hemenway Falk (University of Pennsylvania) and Gerry Tsoukalas (Boston University) in a 2026 paper. Each firm that replaces workers with AI captures the full cost saving but absorbs only a fraction of the resulting consumer-demand loss, because the workers it lays off spent money across the whole market. The rest of the damage falls on rivals. That asymmetry makes over-automation individually rational and collectively destructive.
Who wrote The AI Layoff Trap paper?
Brett Hemenway Falk of the University of Pennsylvania and Gerry Tsoukalas of Boston University. The paper is 63 pages, published on arXiv (2603.20617) with the current version dated 3 June 2026, and also listed as a Wharton School Research Paper on SSRN. Tsoukalas discussed it on the BBC's New Normal with Katty Kay on 20 July 2026.
Why can't CEOs just agree to slow down AI layoffs?
Because automating is what game theorists call a strictly dominant strategy once a market is competitive enough to tip into the trap — it's each firm's best move regardless of what rivals do. That means no voluntary agreement is self-enforcing. As Tsoukalas put it, the moment executives leave the room having agreed to restraint, each one faces an immediate incentive to defect, and a duty to shareholders that points the same way.
Does universal basic income solve AI job displacement?
Not according to this model. UBI adds a constant to overall demand, which raises living standards but doesn't change the marginal calculation a firm makes when deciding whether to replace one more worker. The paper finds the same structural problem with capital income taxes. Only a Pigouvian automation tax corrects the incentive itself, by charging firms for the demand loss they impose on others.
Which cyber security jobs are most at risk from AI?
On our JobZone assessments, entry-level and highly repeatable roles score lowest: Vulnerability Tester (2.7/100), SOC Analyst Tier 1 (5.4), and Junior Penetration Tester (6.4) all sit in the red zone. Roles built on scarce judgement score far higher — AI Security Engineer at 79.3 and CISO at 83.0. These are assessments of durability rather than observed outcomes, and the higher scores carry caveats about current market shortages and task mixes that will shift over the next few years.
What is an AI-driven security engineer?
Start with what's durable: being AI-driven, directing AI to build and run solutions instead of operating tools by hand. That's a way of working, not a job title, and it lowers your odds of being displaced in any field that still has scarce human judgement to own. A security engineer who works that way is an AI-driven security engineer, and security is simply the highest-value place to apply the method, because the judgement is scarce and the stakes are high. The method is what's durable; the domain is where it pays most.
About the Author
Nathan House, Founder & CEO of StationX
Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.