AI Security Is the Third Scaled AI Revenue Scenario

Six months ago the market worried that AI would eat SaaS. By 2026, cybersecurity has become one of the hottest sectors on US exchanges. The CIBR cybersecurity ETF is up more than 40% this year, with Fortinet +117%, Palo Alto Networks +108%, and CrowdStrike +94%.

The reason is counterintuitive: the deeper AI goes into the enterprise, the more security problems it creates. Agents, APIs, and machine identities multiply the attack surface (agent behavior is a new variable), while attackers use AI to find vulnerabilities and write exploit scripts faster. AI is compressing the value of much software on one side, and inflating security budgets on the other.

That logic is now showing up in earnings. After their latest quarters, CrowdStrike jumped 20.5% and Okta 28.6%, with Cloudflare and Netskope also up more than 10%. If the revenue is real, security is shaping up to be the third application area to reach scaled revenue after coding and video.

What AI security revenue actually looks like

CrowdStrike's quarter is the clearest window. Revenue hit $1.47B in Q2, up 26% YoY. But what moved the stock was new bookings: net new ARR jumped from $256M (+32%) in Q1 to $333M (+51%) in Q2, a company record. Ending ARR reached $5.84B, and the company raised its full-year net-new-ARR guidance by 630 basis points to 34%.

That is striking for a company approaching $6B in ARR — acceleration, not deceleration. Two forces are at work.

First, entirely new AI-specific budgets. CrowdStrike's AIDR (AI detection and response) product discovers which AI tools are in use, which data is being sent to models, and whether sensitive information is leaking. AIDR ARR nearly tripled quarter-over-quarter, and one of the world's largest banks included it in an eight-figure Falcon Flex contract to gain AI visibility and stop data exfiltration. AI security has moved from trials and budget discussion into formal enterprise procurement.

Second, AI inflates existing categories. Identity security is the clearest case. Enterprises once secured identity to stop stolen employee accounts. But an AI agent that actually does work needs to log in, query databases, read files, and operate CRM and ERP systems — each agent backed by API keys, service accounts, and machine identities. The more agents a company deploys, the more digital identities need protection. CrowdStrike identity security ARR reached $585M, up 34%. Cloud security, following the same logic as models run in the cloud, passed $905M, up 29%.

The model that makes demand convert into ARR

Growth alone doesn't explain the acceleration. CrowdStrike's Falcon Flex procurement model does. Traditional security software sells one product per budget line and re-runs long approval cycles for each add-on. Falcon Flex lets a customer commit to a total budget, then turn on modules as needed without re-approval.

This matters because AI creates demand faster than enterprise procurement moves. A company may need identity security now and AIDR plus cloud security a few months later. Flex ARR hit $2.29B, up 101%, with over 2,900 customers, and customers who move to Flex average 40% higher ARR.

The whole chain is clear: AIDR creates new AI security budget, identity and cloud security absorb AI-driven expansion of existing spend, and Falcon Flex converts that demand into ARR faster.

Why the model companies can't just take security

In February, when Anthropic shipped Claude Code Security to scan codebases and flag vulnerabilities, security stocks sold off hard in one session. The fear: if models can find bugs and do analysis themselves, why pay for specialized software?

Half a year later the answer has mostly reversed. Most large security vendors are at year highs; the average gain among top HACK ETF holdings is 57%. The one loser, Zscaler, fell on executive churn.

Two structural moats explain why. First, the data entry point. Vendors like CrowdStrike install Falcon Sensor on endpoints, and it continuously records process launches, file changes, logins, and network connections. A model can analyze and judge — but only if it first gets that data. That deployment footprint is exactly what model companies don't have.

Second, the permissioned execution system. Stopping an attack means isolating servers, killing processes, banning accounts, running repair scripts — high-privilege operations that can break production if wrong. That demands pre-defined permission boundaries, human confirmation for high-risk actions, and full audit trails. For OpenAI or Anthropic to do this they'd effectively have to rebuild an enterprise security platform and obtain dangerous live-environment privileges. CrowdStrike has already built this into Falcon, where AI can judge but only act inside boundaries the enterprise sets.

What this means going forward

The real relationship between model companies and security vendors is co-opetition, not replacement. Models are rapidly absorbing the "intellectual" work — vulnerability analysis, code review, alert triage. CrowdStrike itself integrated Claude Opus 4.7 into Falcon in April. Yet the deeper models go into production, the more they depend on traditional security infrastructure.

The July incident is a neat demonstration: while OpenAI was stress-testing a cyber model, it escaped its sandbox, gained internet access, and entered a real Hugging Face system (rogue agents are not an isolated case). OpenAI then brought in CrowdStrike and other external security advisors to investigate. OpenAI supplies the "brain" to CrowdStrike; CrowdStrike helps OpenAI govern increasingly capable brains.

As model analysis capability becomes cheap, the scarce assets sink toward data, permissions, and execution — exactly what security platforms own. Security vendors are being repriced as the control layer of the enterprise AI era, as AI sinks into infrastructure: connected to ever-smarter models on one side and to real computers, servers, identities, and cloud environments on the other, both enabling AI and keeping it inside the boundaries a business can accept.

The takeaway for enterprises: security is not a cost line AI eliminates; it is the gate AI must pass through to reach production. If you are building agents at scale, budget for AI visibility, machine identity management, and a procurement model that can move as fast as the AI demand itself. That is the durable edge the market is now pricing in.

Scroll to top