Imagine you're playing whack-a-mole, but with a twist: every mole you whack stays down permanently, and new moles only pop up at a known rate. The question isn't whether you'll eventually clear the board — it's whether buying a faster mallet is worth it given that moles keep appearing. That's the core mechanism of this paper, applied to AI security. Majumdar and Chavan formalize something the AI safety community has been doing by intuition: the red-team-patch-deploy cycle. Their committed claim is that a finite attack surface is defended with probability 1 if three conditions hold simultaneously — every unpatched vulnerability has a persistent chance of discovery, repairs actually work, and new patches don't break old ones. That sounds obvious stated plainly, but the value is in the formalization: they derive completion-time bounds, meaning you can estimate how long full coverage takes, not just whether it happens. The paper then escalates to the harder, more realistic case: growing attack surfaces. When new vulnerabilities appear faster than old ones get patched, eventual per-attack coverage diverges from complete simultaneous coverage. This is the key distinction. You might eventually find and fix every individual bug, but there's never a single moment when everything is patched at once. For practitioners, this maps directly to the lived experience of maintaining production AI systems — you're always secure against yesterday's attacks, never against tomorrow's. The Stackelberg game formulation is where this gets economically interesting. The defender moves first, choosing investment levels in proactive discovery (red teaming) and reactive repair. The attacker then observes the defender's posture and chooses search effort accordingly. The paper characterizes four equilibrium regimes: invest in neither, proactive only, reactive only, or both. The least-cost deterrence allocation — the minimum spend that makes attacking not worthwhile — falls out of the equilibrium analysis. A notable finding from the numerical experiments: faster repair reduces how long a compromise lasts but doesn't reduce the probability of being compromised in the first place. Speed of patch ≠ probability of breach. Architecturally, this is classical game theory and stochastic process analysis, not ML. The attack surface is modeled as a finite (or countably growing) set of inputs; discovery follows persistent stochastic processes; repairs are modeled as absorbing events. The Stackelberg structure imposes a sequential move order that avoids the simultaneity assumptions of Nash equilibrium, which is more realistic for defender-attacker dynamics where security investments are observable. On integrity, the validation is mathematical proof plus numerical illustration — no empirical experiments on real AI systems. The numerical experiments in the paper are the authors grading their own homework: they parameterize their own model and show it behaves as the theorems predict. This is appropriate for a theory paper but means the real test comes when someone maps these regimes onto actual red-teaming budgets and breach data. The paper is honest about this scope. The biggest gap is empirical calibration. The model assumes you can parameterize discovery rates, repair effectiveness, and attack costs with known values. In practice, nobody has clean estimates of these quantities for production AI systems. The paper gives you the optimization framework but not the inputs. That's not a flaw in a 27-page theory paper — but it's the load-bearing assumption that will determine whether this framework gets used or stays on the shelf.