Amdahl's law comes from high-performance computing, but it is also a useful way to think about what AI may do to jobs. It points to a more optimistic outcome than the usual story about automation.
The Law
Gene Amdahl was an IBM engineer who pointed out in 1967 that when you speed up part of a system, your total gain is capped by the part you didn't speed up.
Say a job takes ten hours and nine of them can be automated. If you automate those nine hours completely, the job now takes one hour, so it is 10x faster. That's also as good as it can get. You can throw infinite compute at those nine hours and you still won't beat 10x, because the tenth hour is still there. The part you can't speed up sets the limit for everything else.
Amdahl was talking about processors, but the same idea works for any job made up of a chain of steps where some can be sped up and others can't. That describes a lot of modern work.
The Tenth Hour
Every real workflow has steps a model can take over and steps it can't. Drafting, searching, summarizing, and doing the first pass of almost anything are the hours that are on their way out. A smaller set of steps will remain, and while they may look minor on a timesheet, they usually involve the things that matter most: approving something, making a judgment call, talking to the client, or putting your name on the final decision.
A model can draft a contract in seconds, but someone still has to decide which terms the company can live with. It can write a campaign in an afternoon, while a person still has to choose which bet to fund. It can finish the analysis before the meeting starts, and the meeting will still happen because its real purpose was to get people to agree.
This puts a limit on what AI can change, but it also gives some sense of where people may end up. As the automatable hours shrink, the human hour gradually becomes most of the job. That hour often contains the judgment, the call, and the ownership, while the other nine hours were the work required to get there.
Predictions that AI will automate a profession away tend to focus on those nine hours. But removing them doesn't necessarily leave less work for the person. It can let them take on more projects, cover more areas, and spend more of the day on the decisions that have the most leverage. The job continues, but its center of gravity changes.
Where Jevons Walks In
Jevons Paradox offers the other half of the argument: when work gets cheaper, people tend to do more of it. Efficiency can grow a market rather than shrink it.
Amdahl gives nine of your ten hours back to you, which raises the question of what happens to all that time. Jevons suggests it will fill up because there is suddenly much more work worth doing. Things that were too expensive last year become affordable. Projects that never made the cut now do, and the backlog you quietly gave up on comes back.
The person who has been freed from those nine hours can now participate in many more workflows. Instead of spending most of the week preparing for one decision, they might make several well-informed decisions across different projects. Their judgment can be applied more widely, while agents carry much of the work needed to reach each decision. One person may cover areas that previously needed a much larger team, and the total amount of work being done grows substantially.
This creates more work in turn. Once a project becomes cheap enough to do, it gets done, and that new project brings its own decisions, tradeoffs, and responsibilities. People don't simply do less work because parts of the process became automated. They do more work across more areas, with a larger share of their time going toward the parts where their judgment has the most leverage.
Put together, Amdahl pushes people toward the most valuable part of the job, while Jevons increases the number of times that part needs to be done. This creates a fairly optimistic model for AI adoption.
It applies especially well to security.
Security's Tenth Hour
Security engineers today still spend a great deal of time on repetitive work, possibly more than ever. Alert queues and noise keep growing, every new tool adds findings to triage, and the cognitive load is brutal. Even where AI helps, running models at the scale a real SOC needs is still expensive. This is still an early and incomplete transition.
The direction is still fairly clear. Triaging alerts, reproducing bugs, reviewing code, writing detections, pulling audit evidence, and digging through logs are exactly the kinds of work agents are getting good at. They account for much of the nine hours. Over the next few years, more of that work will move to agents, although it won't happen all at once.
Consider what happens during an incident. An agent triages the alert, maps the attack path, and drafts the timeline. Someone then has to decide whether the incident must be disclosed, whether production should be shut down, and what customers should be told. The agent can draft the messages, but a person makes those calls. That person may now have a full picture within minutes instead of a partial one after two days of digging, which should lead to better judgment.
The same applies elsewhere. An agent might find 400 real bugs and fix most of them before they reach a pull request, while someone still decides which of the remaining bugs justify delaying a launch. An agent can assemble the SOC 2 evidence, but the auditor may still want a call, and now the person taking it can arrive prepared.
Jevons then comes into play within security. Many companies outside the largest enterprises have not been able to build the security programs they want, often because they couldn't afford all the work around them. If agents make that work affordable, thousands of companies could expand their security efforts. Existing teams could investigate more incidents, review more code, test more systems, and cover parts of the environment that rarely received attention before. Each of those efforts still brings decisions about risk, priorities, disclosure, and ownership. The total amount of security work being done could become much larger than anything the field has staffed for so far.
The Team That Gets There First
Eventually, everyone will have capable agents. The teams that get the most out of them will probably be the ones that redesign their work around this idea. They will hand work to agents as quickly as trust allows while preparing people to handle the decisions that remain. That means approving response plans in advance, assigning decision authority before an incident, and writing disclosure criteria while nobody is panicking. Agents can then act within agreed limits, while people spend their time on the calls that actually matter instead of supervising every step.
A team built this way can do several times as much work and cover areas it never had time to examine. The people on the team still have plenty to do, but more of that time goes toward deciding what matters, choosing where to act, and taking responsibility for the outcome. A security engineer's day may start to look more like a CISO's, with more time spent on direction, decisions, and accountability. The work changes, and in many ways it becomes more useful and more interesting.
Two Laws, One Picture
Together, the two ideas give us a fairly simple picture. Jevons suggests that cheaper security work will lead to much more security work: more companies expanding their programs, old backlogs being worked, and more of the long tail being defended. Amdahl suggests that the people inside those programs will become concentrated in the parts where their judgment matters most.
That means more programs built around human decisions that can't easily be automated and may be worth more than they used to be. Two laws that had nothing to do with security end up describing a strong demand curve for security people.
The same pattern applies to work in general. When agents handle more of the research, preparation, and routine execution, people can take on more projects and cover areas that previously received little attention. More of their time can go toward choosing priorities, making decisions, and taking responsibility for the results. The amount of work grows because many things that were once too expensive or time-consuming become practical to do.
Security makes this especially easy to see. A team can investigate more incidents, review more code, test more systems, and understand more of its environment. Every new area it covers creates more decisions about risk and what to do next. The work does not disappear, but spreads across a wider surface and moves toward the places where human judgment has the most leverage. That is what the tenth hour becomes.