Palo Alto Networks CEO Nikesh Arora has put a number on one of the most significant structural shifts in enterprise technology: approximately $1 trillion of global cybersecurity infrastructure, built for a pre-AI world, is no longer adequate to defend against the automated, machine-speed threats that AI has made possible. Speaking on CNBC's Mad Money on Tuesday — the same day Palo Alto beat fiscal fourth-quarter estimates and issued a strong full-year outlook — Arora argued that AI has not disrupted the cybersecurity industry so much as fundamentally expanded it.
Key Points
- Arora estimates approximately $1 trillion of global cybersecurity infrastructure must be modernised to defend against AI-enabled automated threats
- "Nothing that was deployed seven or 10 years ago is prepared or ready to handle AI at machine speed," Arora told CNBC
- Palo Alto shares have surged 113% since April 7 — the day Anthropic launched Mythos — reversing a year-to-date decline and marking what Arora called a turning point in how the market views AI's impact on cybersecurity
- Arora said Mythos did in one product launch what he had spent eight years trying to tell customers: that they are not ready for the threat
- Palo Alto has held conversations with approximately 2,000 companies about its Frontier AI Critical Defense Program, which uses advanced AI models to test defences and identify vulnerabilities
- Arora cautioned the spending won't arrive all at once but said AI has permanently expanded the long-term growth rate and duration of the cybersecurity opportunity
The $1 Trillion Infrastructure Problem
Arora's core argument is structural rather than cyclical. The cybersecurity tools that enterprises deployed over the past seven to ten years were designed for a threat environment in which attacks were conducted by human operators working at human speed — scanning for vulnerabilities methodically, crafting exploits manually and moving through networks at a pace that gave defenders time to detect, respond and contain.
AI has eliminated that time advantage. Automated systems can now scan entire network environments for vulnerabilities, identify attack paths, develop exploits and execute multi-stage intrusions in timeframes that compress what previously took days into minutes. Security architecture built around human-paced threat actors does not hold against machine-speed adversaries.
"Nothing that was deployed seven or 10 years ago is prepared or ready to handle AI at machine speed," Arora told CNBC's Jim Cramer. "You have to rethink your cyber architecture."
The $1 trillion figure Arora cited on Palo Alto's earnings call represents the accumulated cybersecurity investment that he argues must now be revisited — not because the original technology was poor, but because the threat environment it was designed for no longer exists.
The Mythos Moment
Arora identified a specific inflection point in how the market and enterprise customers began to understand the urgency: the launch of Anthropic's Claude Mythos model in April 2026.
Mythos demonstrated, in a way that earlier AI systems had not publicly established, that a frontier AI model could be readily applied to identifying and exploiting software vulnerabilities — effectively lowering the barrier to sophisticated cyberattacks for any actor with access to the model. That demonstration changed the conversation with customers in a way that years of industry warnings had not.
"I've been trying for eight years to tell customers they're not ready, and Dario Amodei did it in one event, just by launching Mythos," Arora said on CNBC.
The market response reflected the shift in sentiment. Palo Alto shares were in negative territory for 2026 as of April 7. Since then, they have surged 113% — one of the most dramatic reratings of a major cybersecurity company in recent memory — as investors recognised that AI's impact on the sector was not the existential threat to incumbent security vendors it had initially been framed as, but a structural growth driver.
"Nine months ago, we were guilty and convicted of near death because AI was going to eat our lunch, breakfast, and dinner," Arora told Cramer. "It seems like that's not the case. It seems like we're going to have to have the feast with them."
The Frontier AI Critical Defense Program
Palo Alto has moved beyond commentary on the AI threat landscape into a specific product response. The company formally introduced its Frontier AI Critical Defense Program in August, and Arora said on Tuesday that Palo Alto has already held conversations about the initiative with approximately 2,000 companies.
The programme uses advanced AI models to test customers' defensive posture — identifying vulnerabilities, simulating attack scenarios and helping organisations understand where their existing infrastructure fails against automated threats. The goal is to bridge the gap between the security architecture companies currently operate and what they need to withstand AI-enabled attacks.
The scale of early customer engagement — 2,000 conversations in the weeks since the formal launch — suggests that Arora's reading of customer urgency is accurate. The Mythos launch and the subsequent stream of AI model incidents at OpenAI, Anthropic and Meta have accelerated the willingness of enterprise security buyers to have substantive conversations about architecture modernisation that might previously have been deferred.
AI as Growth Driver, Not Disruptor
The narrative around AI's impact on cybersecurity has completed a significant reversal over the course of 2026. Earlier in the year, Palo Alto and other cybersecurity companies faced investor pressure on concerns that AI would disrupt traditional security software — that sufficiently capable AI models would replace the need for specialised security vendors, or that the efficiency gains AI brought to security operations would compress the market rather than expand it.
That thesis has not held. As AI has demonstrated its capacity to dramatically accelerate attacks — and as enterprises have recognised that their existing defences were not designed for that reality — the demand signal for cybersecurity modernisation has strengthened rather than weakened.
"You cannot deploy AI successfully if you don't get cybersecurity right," Arora said. The statement frames AI adoption and cybersecurity investment not as competing priorities but as prerequisites for each other — an argument that resonates with enterprise technology buyers who recognise that AI deployment without adequate security is a liability rather than an advantage.
The Long View
Arora was careful to manage expectations about the pace at which the $1 trillion modernisation opportunity will translate into revenue. "Not everything's going to happen next quarter," he told Cramer. Enterprise infrastructure transitions at the scale he is describing move over years rather than quarters, and the urgency created by AI does not eliminate the procurement cycles, budget approvals and implementation timelines that govern large enterprise technology decisions.
But the duration and structural nature of the opportunity is what Arora emphasised as the more important point. AI has not created a one-cycle spending event — it has raised the baseline of what enterprises must invest in security permanently. The threat environment that made existing infrastructure inadequate is not going away. It is getting more capable with each new model generation.
"All I say is this changes the long-term growth rate and duration of cybersecurity, not just for Palo Alto, but as an industry," Arora said. For investors and enterprise technology buyers alike, that framing positions the current moment not as a spike in cybersecurity spending but as the beginning of a sustained structural expansion of what the industry is and what it must deliver.
Sources
Nikesh Arora interview on CNBC Mad Money with Jim Cramer, Tuesday September 2, 2026. Palo Alto Networks fiscal fourth-quarter 2026 earnings call, September 2, 2026. CNBC reporting on Palo Alto earnings results and full-year outlook, September 2026. Anthropic Claude Mythos launch, April 7, 2026. Palo Alto Frontier AI Critical Defense Program announcement, August 2026. CNBC reporting on cybersecurity stock pressure from AI concerns, February 2026.