The inflection in AI security spending has not yet materialized, but platform security leaders remain the primary beneficiaries
AI summary card
The inflection in AI security spending has not yet materialized, but platform security leaders remain the primary beneficiaries
Goldman Sachs believes the incremental security budget driven by AI may begin to show up more clearly in 4Q26 or 1H27, and expects it could lift the security industry's growth rate by about 2-3 percentage points by 2028.
- The security sector's narrative has shifted from being 'threatened by AI' to 'benefiting from AI,' but there has not yet been a clear change in product-budget spending.
- Enterprise agentic AI remains largely in sandboxed or isolated environments, and current incremental spending is flowing more toward POCs, patches, and hygiene/governance rather than being monetized at scale into revenue for listed security vendors.
- Using the cloud security cycle as an analogy, Goldman Sachs believes AI security budgets may lag AI infrastructure/inference spending by about 2-3 years.
- The report estimates AI Security TAM at about $20bn by 2031; under a 7% attach-rate assumption, the blue-sky scenario could rise to about $40bn.
- CRWD and PANW are more likely to capture incremental AI security budgets due to control points, ML data advantages, M&A capabilities, and platform-based sales motions.
Report interpretation
Overview
This report discusses the time lag between AI capital spending and AI security spending, and uses the cloud security cycle as a reference to assess when AI security budgets may see a more visible inflection. Goldman Sachs believes the security sector has been repriced by the market as an AI beneficiary, but enterprise agentic AI deployment is still at an early stage and listed security vendors have not yet seen a large-scale increase in product budgets. Over the medium term, as inference and agentic workloads move from experimentation and sandboxes into production environments, security budgets may begin to accelerate in 4Q26 or 1H27.
Core views
The core views include: first, the near-term earnings season may be challenging because stock prices have already priced in the medium-term AI security inflection while fundamentals have not yet clearly accelerated; second, it took about five years from the ramp-up of IaaS to the revenue inflection in cloud security, but with a faster AI adoption cycle, AI security may lag by only 2-3 years; third, incremental AI security budgets are more likely to flow to today's platform leaders rather than being fully captured by AI-native companies or frontier model companies; fourth, key product cycles include detection and response for agentic runtime, SOC infrastructure upgrades, identity security, prompt engineering, and data protection; fifth, under blue-sky scenarios, CRWD and PANW could see free cash flow estimates for CY28/FY29 revised upward by as much as about 30%.
Analysis framework
The report uses a combination of historical analogies, company disclosures, industry interviews, and TAM modeling. In the historical analogy section, it uses AWS metrics disclosed in 2015 as the starting point of the cloud cycle and observes how cloud security revenue moved from a low share to a 2-5% attach rate; for AI security, it uses 2025 as the starting point for enterprise inference and agentic experimentation, and combines AI IaaS revenue estimates from Microsoft, Amazon, CoreWeave, Oracle, and others to derive the security revenue opportunity on AI inference workloads.
Methodology notes
Infer the lag in AI security budgets using the cloud security cycle
The report believes that it took about five years from the early stage of the IaaS cycle to a clear inflection in cloud security revenue, and maps Y4/Y5 of the 2019/2020 cloud security cycle to 2027E/2028E in the AI cycle to estimate when AI security spending may accelerate.
Estimate AI Security TAM by multiplying AI IaaS inference revenue by a security attach rate
Goldman Sachs starts with approximately $100mn of AI security revenue and about $17bn of AI IaaS inference TAM in 2025, deriving an initial attach rate of about 0.6%, and then projects a base-case TAM of about $20bn by 2031; if the attach rate reaches 7%, TAM could be about $40bn.
Estimate the upside to free cash flow for CRWD and PANW when they capture a higher share of AI security
The report assumes CRWD and PANW have a higher share of AI security TAM than of total security TAM, and estimates that under a blue-sky scenario, the FCF forecasts for both companies could be revised upward by as much as about 30% by CY28/FY29.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- CrowdStrike (CRWD)One of the core beneficiary names, covering AI detection and response, agentic runtime, and SOC upgrades.
- Strengths
- Has advantages in endpoint and security operations data; AIDR ARR grew 250%+ quarter over quarter, and Pangea and SGNL enhance capabilities in AI applications and agentic identity.
- Weaknesses
- Valuation is high, the AI technology landscape is changing rapidly, and competition may intensify once endpoint EDR matures.
- Comparison
- The report assumes CRWD's share of AI Security TAM could reach 3x its share of total security TAM.
- Risks
- Changes in AI technology paths, ability to continue expanding into new markets, and maturation of EDR competition.
- Palo Alto Networks (PANW)One of the core beneficiary names, with platform control points spanning network, endpoint, cloud, browser, and identity.
- Strengths
- Prisma AIRS has 300+ customers and is close to $100mn ARR; in some customer scenarios it can achieve an attach rate of 8-10% of AI spending, and the company has strong M&A and platformization capabilities.
- Weaknesses
- Its larger scale may result in lower growth elasticity than CRWD, and the complexity of integrating new technologies is higher.
- Comparison
- The report assumes PANW's share of AI Security TAM could reach 2x its share of total security TAM; CRWD and PANW together could capture about one-third of incremental AI security TAM.
- Risks
- Cloud security competition, SASE competition, and next-generation technology integration risk.
- Okta (OKTA)A potential beneficiary in identity security and agent governance.
- Strengths
- Auth0 for AI Agents and Okta for AI Agents cover governance across the full lifecycle of AI agents; new products accounted for about 25% of 1Q bookings and drove about 40% ACV uplift when included in deals.
- Weaknesses
- Related AI products are still relatively small versus total revenue, and commercialization remains at an early stage.
- Comparison
- The report believes OKTA has significant inflection potential given its lower absolute growth rate and valuation base.
- Risks
- Customer adoption speed, the pace of budget formation for agent identity governance, and competitor platform bundling.
- ZscalerA participant in AI app protection, AI broker, and MCP/agent communication security.
- Strengths
- AI Protect generated bookings above $100mn over the past year, and the company launched AI broker to protect MCP and agent-to-agent workflows.
- Weaknesses
- The report does not provide a separate target price or detailed valuation scenario.
- Comparison
- Compared with CRWD/PANW, disclosures are more focused on bookings and product coverage.
- Risks
- The speed of converting products into ARR, platform competition, and delayed customer budgets.
- FortinetA potential beneficiary of data center AI demand and firewalls/internal segmentation firewalls.
- Strengths
- Management mentioned improving data center AI demand, partly driven by Middle East sovereign projects.
- Weaknesses
- It has not yet disclosed standalone AI security revenue, and its path is more oriented toward organic R&D.
- Comparison
- Compared with platform vendors pursuing aggressive M&A, Fortinet has fewer commercial disclosures around AI security.
- Risks
- Limited visibility into AI security product revenue and lack of standalone disclosure.
- Check PointParticipates in AI runtime protection through Lakera and platform expansion.
- Strengths
- Lakera covers protection against prompt injection, data leakage, and model manipulation, and is combined with platform capabilities such as Infinity AI Copilot.
- Weaknesses
- Management says AI security revenue is still not meaningful.
- Comparison
- Compared with CRWD/PANW, the current revenue contribution is at an earlier stage.
- Risks
- The timing and scale with which pipeline growth converts into revenue are uncertain.
- SailPointA beneficiary in non-human identity and agentic identity governance.
- Strengths
- AI ARR is expected to exceed $100mn by the end of FY27, and nonhuman identities contributed 40% of identity growth last quarter.
- Weaknesses
- Disclosures are concentrated in the identity niche, and overall AI security platform coverage is less broad than that of large platforms.
- Comparison
- Like OKTA, it benefits from agent identity governance, but with different product boundaries.
- Risks
- The pace of budget formation for agentic identity and the competitive landscape.
- SentinelOneA participant in Prompt Security, agentic SOC, and cloud runtime.
- Strengths
- Prompt Security pipeline rose from about 0% to about 20% within weeks, and ARR nearly doubled over the past two quarters.
- Weaknesses
- The company still has not seen spending patterns materially deviate from steady state.
- Comparison
- Near-term AI attention has increased significantly, but the overall budget inflection remains unconfirmed.
- Risks
- AI security's revenue contribution to public security vendors may still lag.
Key data
- Timing of the AI security budget inflectionAs early as 4Q26 or 1H27Based on 2025 as the starting point for enterprise inference and agentic use cases, with reference to the lag in the cloud security cycle.
- Industry growth rate upliftAbout 2-3 percentage points by 2028Derived from the incremental contribution of AI Security TAM estimates to the security industry's growth rate.
- 2031 AI Security TAM base-case scenarioAbout $20bnBased on AI IaaS inference revenue and reference cloud security attach rates.
- 2031 AI Security TAM blue-sky scenarioAbout $40bnAssumes the attach rate reaches 7%; the report says Palo Alto's Prisma AIRS can reach 8-10% of AI spending in some customer scenarios.
- Estimated 2025 AI security revenueAbout $100-200mnDerived from company disclosures and rough assumptions about the share of public and private vendors.
- 2025 AI IaaS inference TAMAbout $17bnUsed to derive an initial AI security attach rate of about 0.6%.
- Palo Alto Prisma AIRS300+ customers, close to $100mn ARRThe product covers runtime threat defense, model vulnerability scanning, security posture management, and red teaming tools.
- CrowdStrike AIDRApril quarter ARR up 250%+ quarter over quarter, pipeline above $50mnCovers model, data, and agentic security, and expands into AI applications and agentic identity through Pangea and SGNL.
- Zscaler AI ProtectBookings above $100mn over the past yearIncludes AI app protection, model/data security, AI-SPM, and LLM and MCP server discovery.
- CRWD target price$208, prior $182Based on a 75x EV/FCF multiple on 5Q-8Q estimates, and reflects blue-sky potential.
- PANW target price$371, prior $330Based on a 45x Q5-Q8 FCF multiple, and reflects blue-sky potential.
Impact & implications
The investment implication is that security stocks may face near-term earnings-season risk from 'valuation leading fundamentals,' but if the medium-term inflection in AI security spending materializes, it will support continued premium valuations for platform security leaders. CRWD and PANW have strong platform, data, ML, and M&A advantages; OKTA may also offer greater elasticity in identity and agent governance due to its lower growth base and valuation. Key points to verify are whether enterprise inference and agentic workloads are migrating from sandboxes to production environments, and whether bookings, pipeline, and ARR disclosures are beginning to reflect budget changes.
Risks
- Near-term fundamentals have not yet improved meaningfully, while security stocks have already priced in the medium-term AI security inflection.
- Enterprise agentic AI still largely remains in sandboxed or isolated environments, delaying the conversion into security product budgets.
- Incremental AI value may still be diverted to AI-native vendors, frontier model companies, or private security firms.
- CRWD and PANW valuations are high relative to history and growth profile, and implied upside is limited after the target-price increases.
- Competition may intensify across cloud security, SASE, endpoint, code security, penetration testing, and SOC.
- There are execution risks around M&A integration and technology-path bets.
What to watch
- Whether enterprises are moving inference and agentic workloads from experimentation into production in 3Q industry interviews.
- Whether bookings, pipeline, ARR, and customer counts at security vendors show leading-indicator improvement.
- Whether disclosures on products such as Palo Alto Prisma AIRS, CrowdStrike AIDR, and Zscaler AI Protect continue to accelerate.
- Whether AI security attach rates move from about 0.6% in 2025 toward the 2-5% range seen in mature cloud security.
- Commercialization progress among identity security vendors such as OKTA and SailPoint in AI agents and nonhuman identities.
- Whether AI-native security companies and large LLM vendors create pressure in subsegments such as code security, penetration testing, SOAR, and NDR.