Quick Summary
Covering the latest research from top Wall Street investment banks

The inflection in AI security spending has not yet materialized, but platform security leaders remain the primary beneficiaries

Institution
Goldman Sachs
Date
2026-07-21
Authors
Gabriela Borges, CFA; Max Gamperl; Praachi Arora
Company
CrowdStrike; Palo Alto Networks
Ticker
CRWD; PANW
Industry
AI; Information Technology Services; Software - Infrastructure; Cybersecurity
Rating
CRWD Buy; PANW Buy
NeutralLow confidenceGoldman Sachs believes security is becoming a beneficiary of AI spending, but near-term fundamentals have not yet meaningfully inflected while valuations have already moved higher. The report raises 12-month price targets for CRWD and PANW and frames AI Security as a medium-term TAM/growth accelerator.
AuthorsGabriela Borges, CFA; Max Gamperl; Praachi Arora
Target priceCRWD $208; PANW $371
Asset classesEquity
Business segmentsAI Security、Cloud Security、Cybersecurity Platforms、Identity Security、Security Operations Center
Research firm divisions/subsidiariesGoldman Sachs(Other)

AI summary card

The inflection in AI security spending has not yet materialized, but platform security leaders remain the primary beneficiaries

Goldman Sachs believes the incremental security budget driven by AI may begin to show up more clearly in 4Q26 or 1H27, and expects it could lift the security industry's growth rate by about 2-3 percentage points by 2028.

Goldman Sachs maintains Buy ratings on CRWD and PANW, and raises CRWD's 12-month target price to $208 and PANW's 12-month target price to $371.
AI SecurityCloud Security CycleCybersecurity PlatformsCRWDPANWOKTATAM ExpansionValuation Upgrade
  • The security sector's narrative has shifted from being 'threatened by AI' to 'benefiting from AI,' but there has not yet been a clear change in product-budget spending.
  • Enterprise agentic AI remains largely in sandboxed or isolated environments, and current incremental spending is flowing more toward POCs, patches, and hygiene/governance rather than being monetized at scale into revenue for listed security vendors.
  • Using the cloud security cycle as an analogy, Goldman Sachs believes AI security budgets may lag AI infrastructure/inference spending by about 2-3 years.
  • The report estimates AI Security TAM at about $20bn by 2031; under a 7% attach-rate assumption, the blue-sky scenario could rise to about $40bn.
  • CRWD and PANW are more likely to capture incremental AI security budgets due to control points, ML data advantages, M&A capabilities, and platform-based sales motions.

Report interpretation

Overview

This report discusses the time lag between AI capital spending and AI security spending, and uses the cloud security cycle as a reference to assess when AI security budgets may see a more visible inflection. Goldman Sachs believes the security sector has been repriced by the market as an AI beneficiary, but enterprise agentic AI deployment is still at an early stage and listed security vendors have not yet seen a large-scale increase in product budgets. Over the medium term, as inference and agentic workloads move from experimentation and sandboxes into production environments, security budgets may begin to accelerate in 4Q26 or 1H27.

Core views

The core views include: first, the near-term earnings season may be challenging because stock prices have already priced in the medium-term AI security inflection while fundamentals have not yet clearly accelerated; second, it took about five years from the ramp-up of IaaS to the revenue inflection in cloud security, but with a faster AI adoption cycle, AI security may lag by only 2-3 years; third, incremental AI security budgets are more likely to flow to today's platform leaders rather than being fully captured by AI-native companies or frontier model companies; fourth, key product cycles include detection and response for agentic runtime, SOC infrastructure upgrades, identity security, prompt engineering, and data protection; fifth, under blue-sky scenarios, CRWD and PANW could see free cash flow estimates for CY28/FY29 revised upward by as much as about 30%.

Analysis framework

The report uses a combination of historical analogies, company disclosures, industry interviews, and TAM modeling. In the historical analogy section, it uses AWS metrics disclosed in 2015 as the starting point of the cloud cycle and observes how cloud security revenue moved from a low share to a 2-5% attach rate; for AI security, it uses 2025 as the starting point for enterprise inference and agentic experimentation, and combines AI IaaS revenue estimates from Microsoft, Amazon, CoreWeave, Oracle, and others to derive the security revenue opportunity on AI inference workloads.

Methodology notes

  • cycle_comparisonCloud Security Cycle Analogy

    Infer the lag in AI security budgets using the cloud security cycle

    The report believes that it took about five years from the early stage of the IaaS cycle to a clear inflection in cloud security revenue, and maps Y4/Y5 of the 2019/2020 cloud security cycle to 2027E/2028E in the AI cycle to estimate when AI security spending may accelerate.

  • tam_modelAI Security TAM Attach Rate Model

    Estimate AI Security TAM by multiplying AI IaaS inference revenue by a security attach rate

    Goldman Sachs starts with approximately $100mn of AI security revenue and about $17bn of AI IaaS inference TAM in 2025, deriving an initial attach rate of about 0.6%, and then projects a base-case TAM of about $20bn by 2031; if the attach rate reaches 7%, TAM could be about $40bn.

  • scenario_analysisBlue Sky FCF Scenario

    Estimate the upside to free cash flow for CRWD and PANW when they capture a higher share of AI security

    The report assumes CRWD and PANW have a higher share of AI security TAM than of total security TAM, and estimates that under a blue-sky scenario, the FCF forecasts for both companies could be revised upward by as much as about 30% by CY28/FY29.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • CrowdStrike (CRWD)
    One of the core beneficiary names, covering AI detection and response, agentic runtime, and SOC upgrades.
    Strengths
    Has advantages in endpoint and security operations data; AIDR ARR grew 250%+ quarter over quarter, and Pangea and SGNL enhance capabilities in AI applications and agentic identity.
    Weaknesses
    Valuation is high, the AI technology landscape is changing rapidly, and competition may intensify once endpoint EDR matures.
    Comparison
    The report assumes CRWD's share of AI Security TAM could reach 3x its share of total security TAM.
    Risks
    Changes in AI technology paths, ability to continue expanding into new markets, and maturation of EDR competition.
  • Palo Alto Networks (PANW)
    One of the core beneficiary names, with platform control points spanning network, endpoint, cloud, browser, and identity.
    Strengths
    Prisma AIRS has 300+ customers and is close to $100mn ARR; in some customer scenarios it can achieve an attach rate of 8-10% of AI spending, and the company has strong M&A and platformization capabilities.
    Weaknesses
    Its larger scale may result in lower growth elasticity than CRWD, and the complexity of integrating new technologies is higher.
    Comparison
    The report assumes PANW's share of AI Security TAM could reach 2x its share of total security TAM; CRWD and PANW together could capture about one-third of incremental AI security TAM.
    Risks
    Cloud security competition, SASE competition, and next-generation technology integration risk.
  • Okta (OKTA)
    A potential beneficiary in identity security and agent governance.
    Strengths
    Auth0 for AI Agents and Okta for AI Agents cover governance across the full lifecycle of AI agents; new products accounted for about 25% of 1Q bookings and drove about 40% ACV uplift when included in deals.
    Weaknesses
    Related AI products are still relatively small versus total revenue, and commercialization remains at an early stage.
    Comparison
    The report believes OKTA has significant inflection potential given its lower absolute growth rate and valuation base.
    Risks
    Customer adoption speed, the pace of budget formation for agent identity governance, and competitor platform bundling.
  • Zscaler
    A participant in AI app protection, AI broker, and MCP/agent communication security.
    Strengths
    AI Protect generated bookings above $100mn over the past year, and the company launched AI broker to protect MCP and agent-to-agent workflows.
    Weaknesses
    The report does not provide a separate target price or detailed valuation scenario.
    Comparison
    Compared with CRWD/PANW, disclosures are more focused on bookings and product coverage.
    Risks
    The speed of converting products into ARR, platform competition, and delayed customer budgets.
  • Fortinet
    A potential beneficiary of data center AI demand and firewalls/internal segmentation firewalls.
    Strengths
    Management mentioned improving data center AI demand, partly driven by Middle East sovereign projects.
    Weaknesses
    It has not yet disclosed standalone AI security revenue, and its path is more oriented toward organic R&D.
    Comparison
    Compared with platform vendors pursuing aggressive M&A, Fortinet has fewer commercial disclosures around AI security.
    Risks
    Limited visibility into AI security product revenue and lack of standalone disclosure.
  • Check Point
    Participates in AI runtime protection through Lakera and platform expansion.
    Strengths
    Lakera covers protection against prompt injection, data leakage, and model manipulation, and is combined with platform capabilities such as Infinity AI Copilot.
    Weaknesses
    Management says AI security revenue is still not meaningful.
    Comparison
    Compared with CRWD/PANW, the current revenue contribution is at an earlier stage.
    Risks
    The timing and scale with which pipeline growth converts into revenue are uncertain.
  • SailPoint
    A beneficiary in non-human identity and agentic identity governance.
    Strengths
    AI ARR is expected to exceed $100mn by the end of FY27, and nonhuman identities contributed 40% of identity growth last quarter.
    Weaknesses
    Disclosures are concentrated in the identity niche, and overall AI security platform coverage is less broad than that of large platforms.
    Comparison
    Like OKTA, it benefits from agent identity governance, but with different product boundaries.
    Risks
    The pace of budget formation for agentic identity and the competitive landscape.
  • SentinelOne
    A participant in Prompt Security, agentic SOC, and cloud runtime.
    Strengths
    Prompt Security pipeline rose from about 0% to about 20% within weeks, and ARR nearly doubled over the past two quarters.
    Weaknesses
    The company still has not seen spending patterns materially deviate from steady state.
    Comparison
    Near-term AI attention has increased significantly, but the overall budget inflection remains unconfirmed.
    Risks
    AI security's revenue contribution to public security vendors may still lag.

Key data

  • Timing of the AI security budget inflectionAs early as 4Q26 or 1H27Based on 2025 as the starting point for enterprise inference and agentic use cases, with reference to the lag in the cloud security cycle.
  • Industry growth rate upliftAbout 2-3 percentage points by 2028Derived from the incremental contribution of AI Security TAM estimates to the security industry's growth rate.
  • 2031 AI Security TAM base-case scenarioAbout $20bnBased on AI IaaS inference revenue and reference cloud security attach rates.
  • 2031 AI Security TAM blue-sky scenarioAbout $40bnAssumes the attach rate reaches 7%; the report says Palo Alto's Prisma AIRS can reach 8-10% of AI spending in some customer scenarios.
  • Estimated 2025 AI security revenueAbout $100-200mnDerived from company disclosures and rough assumptions about the share of public and private vendors.
  • 2025 AI IaaS inference TAMAbout $17bnUsed to derive an initial AI security attach rate of about 0.6%.
  • Palo Alto Prisma AIRS300+ customers, close to $100mn ARRThe product covers runtime threat defense, model vulnerability scanning, security posture management, and red teaming tools.
  • CrowdStrike AIDRApril quarter ARR up 250%+ quarter over quarter, pipeline above $50mnCovers model, data, and agentic security, and expands into AI applications and agentic identity through Pangea and SGNL.
  • Zscaler AI ProtectBookings above $100mn over the past yearIncludes AI app protection, model/data security, AI-SPM, and LLM and MCP server discovery.
  • CRWD target price$208, prior $182Based on a 75x EV/FCF multiple on 5Q-8Q estimates, and reflects blue-sky potential.
  • PANW target price$371, prior $330Based on a 45x Q5-Q8 FCF multiple, and reflects blue-sky potential.

Impact & implications

The investment implication is that security stocks may face near-term earnings-season risk from 'valuation leading fundamentals,' but if the medium-term inflection in AI security spending materializes, it will support continued premium valuations for platform security leaders. CRWD and PANW have strong platform, data, ML, and M&A advantages; OKTA may also offer greater elasticity in identity and agent governance due to its lower growth base and valuation. Key points to verify are whether enterprise inference and agentic workloads are migrating from sandboxes to production environments, and whether bookings, pipeline, and ARR disclosures are beginning to reflect budget changes.

Risks

  • Near-term fundamentals have not yet improved meaningfully, while security stocks have already priced in the medium-term AI security inflection.
  • Enterprise agentic AI still largely remains in sandboxed or isolated environments, delaying the conversion into security product budgets.
  • Incremental AI value may still be diverted to AI-native vendors, frontier model companies, or private security firms.
  • CRWD and PANW valuations are high relative to history and growth profile, and implied upside is limited after the target-price increases.
  • Competition may intensify across cloud security, SASE, endpoint, code security, penetration testing, and SOC.
  • There are execution risks around M&A integration and technology-path bets.

What to watch

  • Whether enterprises are moving inference and agentic workloads from experimentation into production in 3Q industry interviews.
  • Whether bookings, pipeline, ARR, and customer counts at security vendors show leading-indicator improvement.
  • Whether disclosures on products such as Palo Alto Prisma AIRS, CrowdStrike AIDR, and Zscaler AI Protect continue to accelerate.
  • Whether AI security attach rates move from about 0.6% in 2025 toward the 2-5% range seen in mature cloud security.
  • Commercialization progress among identity security vendors such as OKTA and SailPoint in AI agents and nonhuman identities.
  • Whether AI-native security companies and large LLM vendors create pressure in subsegments such as code security, penetration testing, SOAR, and NDR.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins