HomeArtificial IntelligenceArtificial Intelligence NewsJensen Huang Called It. CrowdStrike and Palo Alto Are Already Racing to...

Jensen Huang Called It. CrowdStrike and Palo Alto Are Already Racing to Win It.


Nvidia CEO Jensen Huang told a Goldman Sachs conference audience on September 10 that cybersecurity was likely to become AI’s next major growth market — and within hours, Anthropic handed him the most uncomfortable possible proof: the company disclosed it had disrupted a Russia-linked operation that used its own Claude models to target more than 20 Ukrainian government and defense entities.

An AI company’s own models were weaponized against a sovereign government’s defense infrastructure. This is the threat that turns Jensen Huang’s conference prediction into a line item on every corporate IT budget.

Huang’s comment made headlines. But the more concrete evidence that the AI cybersecurity market is already real — and already contested — arrived quietly in two earnings reports that preceded his remarks by nearly two weeks. CrowdStrike and Palo Alto Networks, the two largest pure-play cybersecurity incumbents, are each sprinting toward the same destination using almost opposite strategies. Which approach wins will matter more to investors, enterprises, and ultimately to national security than any conference-stage prediction.

The Deal That Tells the Story

Start with CrowdStrike’s most revealing data point from its fiscal second-quarter earnings: CEO George Kurtz disclosed an eight-figure Falcon Flex deal signed with a frontier AI lab. Think about what that means structurally. An AI developer — the very category of company most frequently framed as a potential disruptor of traditional software vendors — is now a paying CrowdStrike customer. The hunter has hired a bodyguard.

That deal didn’t happen in a vacuum. CrowdStrike had just unveiled SafeMind at its Fal.Con conference on September 1, an agentic cybersecurity system developed by its internal Cyber Superintelligence Lab on top of open Nemotron models. SafeMind pairs two competing AI sub-systems: Red Tempest, an offensive model, and Blue Solano, a defensive counterpart, which run continuously against each other inside CrowdStrike’s Falcon platform. The company says it trained the system on 15 years of incident response data and Falcon telemetry — a proprietary dataset that a general-purpose AI lab simply cannot replicate by licensing a frontier model and slapping a security label on it.

According to CrowdStrike’s own internal benchmarks, SafeMind detects threats 29% more accurately and remediates them six times faster than the frontier models it tested against. It’s worth flagging clearly: these are internal evaluations, not independently verified figures. When a company is asking the market to price in a new product category, those caveats carry real weight. That said, the underlying revenue trajectory is harder to argue with. CrowdStrike’s fiscal Q2 revenue rose 26% year-over-year to $1.47 billion, and net new annual recurring revenue jumped 51% to a record $333 million.

The Pattern Across the Market

Palo Alto Networks took the opposite path. Rather than building a flagship AI security model internally, the company has been acquiring its way into agentic security. By the close of its fiscal year, Palo Alto had integrated CyberArk, absorbed Chronosphere, and added Console — an AI-native platform designed for agentic enterprise workflows — to its portfolio. Three acquisitions in a single fiscal year is an aggressive posture that signals urgency, but also introduces real integration risk.

The growth numbers are hard to dismiss. Palo Alto’s Next Generation Security annual recurring revenue reached $9.1 billion, up 63% year-over-year. Total remaining performance obligations crossed $20 billion for the first time, climbing 34% to $21.2 billion. CEO Nikesh Arora said AI advances are “elevating cybersecurity to the top of the CIO priority list” — a sentiment that maps almost perfectly onto Huang’s later Goldman Sachs remarks.

But the profit-and-loss statement tells a more complicated story than the growth headline. Palo Alto swung to a GAAP net loss of $282 million in the quarter, compared with a profit in the same period a year earlier. The loss reflects the cost of digesting three acquisitions simultaneously, and that’s a real tension: you can buy your way into the market, but you have to earn your way back to profitability afterward.

Here’s the synthesis worth pausing on: both CrowdStrike and Palo Alto are posting genuinely strong top-line metrics, yet the market responded to their earnings reports in opposite directions. CrowdStrike’s beat sent shares up roughly 20% on August 27 — its best single trading day on record, per CNBC. Palo Alto’s beat, which included 34% revenue growth to $3.41 billion in its fiscal fourth quarter, produced a more than 5% share decline as investors fixated on margin pressure. That divergence isn’t random noise — it suggests the market is making a specific judgment: that a proprietary, organically built AI security model produces a cleaner, more defensible growth story than an acquisition-heavy platform play, at least right now. That could change as integrations mature, but the current valuation premium on internal development is a meaningful signal for how capital is being allocated across the sector.

The threat backdrop driving both companies’ urgency isn’t hypothetical. Anthropic’s disclosure about AI agents operating with reduced transparency is directly relevant here: the company’s own report covering December through August found that a group whose tradecraft matched Russia-linked Midnight Blizzard used AI to assist phishing campaigns, compromise hotel Wi-Fi networks, and hijack WhatsApp accounts to target Ukrainian officials and people connected to the country’s drone supply chain. Crucially, Anthropic noted that humans mostly supervised while AI carried out large portions of the actual operation — a capability shift, not just a tool upgrade.

The cost economics make this even starker. A joint study by cloud security firm Wiz and AI lab Irregular found that AI agents completed sophisticated offensive security challenges for under $50 in computing costs, versus close to $100,000 for the equivalent work done by paid human researchers, according to Fortune. When the price of a sophisticated cyberattack drops by roughly three orders of magnitude, the entire threat model changes — and so does the addressable market for whoever is selling the defense.

How CrowdStrike’s Build Strategy Compares to Palo Alto’s Buy Strategy

Attribute CrowdStrike (Build) Palo Alto Networks (Buy)
AI security approach Internally developed SafeMind, trained on 15 years of proprietary Falcon telemetry Acquired Console (AI-native agentic platform), CyberArk, Chronosphere in one fiscal year
Core AI architecture Dual adversarial models (Red Tempest offensive + Blue Solano defensive), continuous internal red-teaming Integrated third-party AI-native platforms unified under Palo Alto’s broader security stack
Proprietary data moat Strong — 15 years of IR data and Falcon telemetry, not replicable by licensing a frontier model Moderate — data advantage depends on how tightly acquired products are integrated
Key ARR metric Net new ARR: $333M (record, +51% YoY) in fiscal Q2 Next Gen Security ARR: $9.1B (+63% YoY); RPO crossed $20B
Profitability posture Profitable; clean earnings story GAAP net loss of $282M in the quarter; acquisition digestion underway
Market reaction to latest earnings +~20% single-day gain (best trading day in company history, per CNBC) –5%+ despite 34% revenue growth; investors focused on margin pressure
Strategic risk Benchmark claims are self-reported; independent validation pending Integration complexity; three acquisitions simultaneously creates execution risk

Neither approach is obviously wrong. CrowdStrike’s proprietary data moat is a genuine competitive advantage, but it concentrates risk on a single platform’s ability to keep outperforming as the threat landscape evolves. Palo Alto’s acquisition strategy buys speed-to-market and diversity of capability, but the tab is visible in the income statement, and investors are clearly impatient about when that investment pays back.

Where Capital Is Going

Huang’s framing — that cybersecurity is AI’s next growth frontier — is useful shorthand, but the earnings data suggests the market is already past the “will this be a real category?” phase. The question now is which architecture wins, and over what time horizon.

For enterprise buyers, the near-term signal from CrowdStrike is notable: an eight-figure deal with a frontier AI lab means AI companies themselves are treating security as an operational priority, not just a compliance checkbox. The debate among cybersecurity leaders about AI model access policy reflects the same tension — the tools that defend infrastructure are now also the tools that can attack it, and procurement decisions have to account for both vectors simultaneously.

The demand driver isn’t going away. Nation-state AI espionage is increasingly targeting people and institutions, not just networks, which means the perimeter that security vendors have to protect is expanding faster than traditional product roadmaps can follow. That structural dynamic benefits whichever vendor can most credibly claim it understands the evolving threat — and right now, internal training data is CrowdStrike’s strongest argument for that credibility.

For investors assessing where capital flows next, the platform consolidation thesis matters. Both companies are betting that CIOs will rationalize their vendor lists and concentrate spend with fewer, more capable platforms. Palo Alto’s $21.2 billion in remaining performance obligations suggests buyers are making long-term commitments; CrowdStrike’s Falcon Flex deal structure suggests buyers want flexible, bundled consumption models rather than point solutions. Those are compatible trends, not contradictory ones — and together they point toward a market that rewards platform breadth and AI-native capability simultaneously.

There’s also a supply-side angle worth watching. Supply chain attacks targeting AI infrastructure directly create a recursive demand loop: the more critical AI systems become to enterprise operations, the more valuable — and vulnerable — they are, and the more budget flows toward protecting them. That loop accelerates both the threat and the market opportunity on the defense side.

Risks

The bull case for AI cybersecurity is coherent, but several things could meaningfully slow or complicate it.

First, the benchmark problem. CrowdStrike’s SafeMind performance claims — 29% better detection, six times faster remediation — are compelling if true, but they come from the company’s own testing. Independent verification is standard for credibility in security research, and until third parties replicate those results, enterprises are making procurement decisions partly on faith. If SafeMind underperforms in production environments against novel threat types, the growth story could stall faster than the ARR trajectory implies.

Second, acquisition integration is genuinely hard. Palo Alto’s decision to close three acquisitions in a single fiscal year is bold, but history is littered with security vendors that bought their way into complexity they couldn’t unify. If the Console, CyberArk, and Chronosphere integrations produce customer friction rather than seamless capability expansion, churn could erode the Next Generation Security ARR figures that currently look so impressive.

Third, the threat itself could evolve faster than either company’s product roadmap. AI-assisted attacks are already costing under $50 per sophisticated operation. If that cost floor drops further, or if adversaries develop techniques that specifically probe AI-native defense systems, neither an internally built model nor an acquired platform is guaranteed to keep pace. The adversarial red-teaming approach embedded in SafeMind’s architecture is a thoughtful response to this risk — but it’s a dynamic problem, not a solved one.

Fourth, regulatory and policy environments remain unsettled. Governments in the US, EU, and elsewhere are still working out how to treat AI-generated threats and AI-assisted defenses under existing legal frameworks. Ambiguity on liability, disclosure requirements, and cross-border data flows could add friction to enterprise procurement cycles precisely when both CrowdStrike and Palo Alto need those cycles to accelerate.

How Serious Players Should Respond

For enterprise security leaders and CIOs, the strategic implication of what’s happening right now is fairly clear: the window for treating AI security as a future concern is closed. Anthropic’s disruption of a Midnight Blizzard-linked AI-assisted campaign against Ukrainian targets is a live case study, not a theoretical scenario. If AI models can be directed at 20 government and defense targets simultaneously — with humans supervising rather than doing the work — the scale of coordinated threat activity has changed structurally. That warrants revisiting security architecture assumptions made even 18 months ago, before agentic AI became operationally viable for adversaries.

For executives evaluating vendor strategy, the build-versus-buy question that CrowdStrike and Palo Alto embody at scale is one that internal security teams will increasingly face at smaller scope. The data moat argument — that proprietary telemetry produces materially better AI models than anything built on licensed frontier APIs — deserves serious scrutiny before committing to either path. CrowdStrike’s 15-year incident response dataset is a genuine differentiator, but organizations with narrower threat profiles may find that a well-integrated acquired capability serves them better than building from scratch.

For regulators and policymakers, the Anthropic disclosure is a prompt for a harder conversation: if AI labs can detect and disrupt nation-state operations using their own models as the attack surface, what mandatory disclosure and coordination frameworks need to exist? The gap between the speed at which AI-assisted threats are evolving and the speed at which institutional frameworks are adapting is exactly where the next serious incident is likely to emerge. The next few quarters of earnings from CrowdStrike and Palo Alto will tell us which private-sector strategy is compounding fastest — but the public-sector response to AI-native threats is still being written.

Most Popular