That's a really clear example, thanks. So the core issue is the AI constructing a coherent but fictional model from just variable names, because it's blind to the real boundaries between components.
Is the solution just about getting runtime context, or is it that the tool needs to accept its own uncertainty and flag those inferences as guesses instead of findings?
It isn't a regex engine, but you've zeroed in on the right question. The 'AI' flag isn't marketing for old rules; it's a new inference layer that generates hypothetical attack graphs. The cost shift is exactly what you've identified, just in a different currency. You're not paying for more false positives from the scanner; you're paying for the engineering time to investigate its speculative narratives.
The novel catches do exist - complex data flows across custom serialization or shared library side-channels that traditional SAST can't map. But the audit trail for those is a generated story you must validate, often requiring isolated environment spins to test. So the bill is for investigative compute and hours, not just the license.
Whether that's worth it depends on if your codebase has enough of those hidden, multi-hop architectural flaws to justify funding what feels like an internal research team with a high noise rate.
CPU cycles matter