The inflection in AI security spending has not yet materialized, but may emerge in 4Q26 to 1H27
AI summary card
The inflection in AI security spending has not yet materialized, but may emerge in 4Q26 to 1H27
Goldman Sachs believes the security sector has already priced in the medium-term increment from AI, but enterprise AI agents are still largely in sandbox and POC stages, and the true monetizable inflection in security budgets will still require inference and agent workloads to enter production environments.
- The security industry has shifted from being seen as exposed to AI risks to being viewed as an AI beneficiary, but product budgets have not yet changed meaningfully.
- Using the cloud security cycle as a reference, cloud security spend took about five years to rise from below 1% of cloud IaaS spend to 2%-5%; the AI security cycle may be faster, with a lag of about 2-3 years.
- Goldman Sachs estimates AI security TAM could reach about $20 billion by 2031, contributing roughly 2 percentage points to industry growth; if the attach rate reaches 7%, TAM could double to $40 billion.
- Incremental AI security budgets are expected to flow more toward existing platform leaders, because security roadmaps depend on proprietary data, machine-learning feedback loops, and M&A integration capabilities.
- Key product cycles include AI detection and response, agent runtime monitoring, SOC infrastructure upgrades, identity governance, prompt engineering, and data protection.
Report interpretation
Overview
This report discusses the transmission pace from AI spending to AI security spending, and when cybersecurity companies may see a clearer fundamental inflection. Goldman Sachs believes the market already views the security sector as an AI beneficiary, but enterprise agentic AI applications are still largely in testing, sandbox, and isolated environments and have not yet formed large-scale productized security budgets. Using the cloud security cycle as a reference, the report judges that AI security budgets may begin to show up more clearly in 4Q26 or 1H27, and could contribute incremental growth to the security industry around 2028.
Core views
The core views are: first, the medium-term opportunity for AI-related security budgets is real, but a near-term earnings inflection has not yet been validated; second, the AI adoption cycle is faster than earlier technology cycles such as cloud computing, so the lag in AI security spending may be shorter than that of cloud security; third, existing security platform leaders are better positioned than legacy vendors in other software areas to capture incremental AI value; fourth, PANW, CRWD, and OKTA each have strong exposure in platform security, AI detection and response, and identity governance; fifth, valuations are already elevated, and future excess returns will depend on whether leading indicators such as bookings, pipeline, and production deployment improve.
Analysis framework
The report uses a combination of historical analogies and bottom-up TAM estimation. In the historical analogy section, it treats 2015 as an important starting point for the cloud IaaS cycle and observes the process by which cloud security revenue as a share of IaaS revenue rose from low levels to a steady-state range of 2%-5%. In the AI security estimation section, it uses 2025 as the starting point for the enterprise AI inference and agent application cycle, estimates AI IaaS inference revenue, the structure of training and inference workloads, and the attach rate of AI security revenue, and maps these to potential inflection points in 2027E and 2028E.
Methodology notes
Use the lag between the rise of cloud IaaS and the inflection in security budgets to estimate the time gap between broad AI inference adoption and commercial acceleration in AI security budgets.
The report argues that it took about five years from the early cloud IaaS stage to a clear inflection in cloud security revenue, while AI adoption is faster, so AI security budgets may enter a more visible acceleration phase with a 2-3 year lag.
Forecast AI security revenue as an attach rate on AI IaaS inference revenue.
Using about $100 million of AI security revenue and a $17 billion AI IaaS inference TAM in 2025 as the starting point, the report derives an attach rate of about 0.6% and then extrapolates 2031 AI security TAM with reference to the 2%-5% cloud security attach-rate range.
Assess whether AI security value is more likely to flow to existing platform leaders or to new entrants.
The report argues that security roadmaps are primarily driven by machine learning, proprietary labeled data, human feedback loops, and network/endpoint control points rather than purely by general-purpose generative AI, making existing security platforms harder to replicate.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- CrowdStrike (CRWD)Beneficiary in AI detection and response, endpoint security, cloud security, and agentic identity-related areas
- Strengths
- AIDR ARR is growing 250%+ quarter over quarter, with pipeline above $50M; the report believes its pace of innovation and successful M&A could give it a larger share of AI TAM than its share of total security TAM.
- Weaknesses
- Valuation already reflects the medium-term AI inflection in advance, while near-term fundamentals have not yet benefited meaningfully.
- Comparison
- Under the blue-sky scenario, the report believes FY29 free cash flow estimates could be revised up by as much as about 30%.
- Risks
- Rapid changes in the AI technology landscape, continued ability to expand into new markets, and endpoint competition after EDR category maturation.
- Palo Alto Networks (PANW)Platform security leader spanning network, cloud, browser, identity, and AI application security
- Strengths
- Prisma AIRS has 300+ customers and is close to $100M ARR; in some customer use cases it can reach 8%-10% of AI spend.
- Weaknesses
- Its larger scale may reduce relative growth elasticity, and it must continue integrating next-generation technology assets.
- Comparison
- Under the blue-sky scenario, PANW and CRWD together could capture about one-third of incremental AI security TAM, and PANW CY28 free cash flow estimates could be revised up by as much as about 30%.
- Risks
- Cloud security competition, SASE competition, and next-generation technology integration risk.
- Okta (OKTA)Beneficiary in identity security and AI agent governance
- Strengths
- Strong cloud-native backend and developer mindshare through Auth0; new products accounted for about 25% of 1Q bookings, and ACV in deals including new products rose about 40%.
- Weaknesses
- AI agent-related products are still relatively small versus total revenue, and revenue conversion remains at an early stage.
- Comparison
- The report believes OKTA, relative to CRWD and PANW, has potential for an inflection from a lower absolute growth rate and valuation base.
- Risks
- Slower-than-expected conversion of agentic identity demand, competitor platform bundling, and delayed customer budgets.
- ZscalerBeneficiary in AI application protection, model/data security, AI-SPM, and agent communication security
- Strengths
- AI Protect generated more than $100M in bookings over the past year, and the company launched an AI broker to protect MCP and agent-to-agent workflows.
- Weaknesses
- The report does not provide a standalone target price revision, and the investment conclusion is less specific than for PANW and CRWD.
- Comparison
- Compared with platform leaders in endpoint and network security, Zscaler’s disclosures are more concentrated on bookings for AI protection products and controls over agent communications.
- Risks
- Pace of AI security budget deployment, sustainability of product differentiation, and SASE and cloud security competition.
- SailPointBeneficiary in non-human identity and AI agent governance
- Strengths
- The company expects AI ARR to exceed $100mn by the end of FY27; non-human identity drove 40% of identity growth last quarter.
- Weaknesses
- AI revenue is still in a buildout phase, and its overall financial contribution still needs validation.
- Comparison
- Similar to OKTA, the benefit is concentrated in agent identity, access governance, and non-human identity expansion.
- Risks
- Delayed scaling of AI identity governance budgets and uncertainty in the customer adoption curve.
- SentinelOneBeneficiary in Prompt Security, agentic SOC, and cloud runtime security
- Strengths
- Prompt Security pipeline rose from about 0% to about 20% within weeks, and ARR nearly doubled over the past two quarters.
- Weaknesses
- The company still has not seen a major deviation in overall spending patterns relative to the steady state.
- Comparison
- Compared with CRWD and PANW, the report describes its AI security tailwind more as an early pipeline signal.
- Risks
- Strong AI security negotiation interest may fail to convert into large-scale budgets, and the commercialization pace of agentic SOC demand is uncertain.
Key data
- Lag to cloud security spending inflectionabout 5 yearsThe report estimates it took about five years from the start of the IaaS cloud cycle to a clear inflection in cloud security revenue.
- Steady-state cloud security attach rate2%-5% of IaaS spendThe report uses this range as a reasonable benchmark for the share of security budgets within cloud IaaS budgets.
- Potential AI security budget inflection4Q26 or 1H27Based on 2025 as the starting point for the enterprise AI inference and agent application cycle, as well as industry interviews.
- Estimated 2025 AI security revenue$100mn-$200mnBased on company disclosures and rough assumptions about the share of public and private vendors.
- 2025 AI IaaS inference TAM$17bnDerived from disclosures or estimates for Microsoft, Amazon, CoreWeave, Oracle, and others.
- 2025 AI security attach rateabout 0.6%Calculated from about $100 million of AI security revenue relative to a $17 billion AI IaaS inference TAM.
- 2031 AI security TAM base caseabout $20bnEquivalent to roughly a 2 percentage point uplift to industry growth.
- 2031 AI security TAM upside caseabout $40bnIf the attach rate reaches 7%, the report says the forecast could double, bringing roughly a 4 percentage point uplift to industry growth.
- Palo Alto Prisma AIRS300+ customers, close to $100M ARRThe report says Prisma AIRS can reach 8%-10% of AI spend in some customer use cases.
- CrowdStrike AIDR250%+ quarter-over-quarter ARR growth, pipeline above $50MAIDR covers model, data, and agentic security, and expands capabilities through Pangea and SGNL.
- Zscaler AI ProtectMore than $100M in bookings over the past yearCovers AI application protection, model/data security, AI-SPM, LLM discovery, and MCP servers.
- CRWD target price$208The 12-month target price is raised from $182, based on a 75x EV/FCF multiple on 5Q-8Q estimates.
- PANW target price$371The 12-month target price is raised from $330, based on a 45x Q5-Q8 FCF multiple.
Impact & implications
The investment implication is that the security sector has already reflected a substantial portion of expected AI benefits, leaving near-term earnings seasons exposed to the risk that fundamentals have not yet materialized; however, if enterprise AI inference and agent workloads move from test environments into production, AI security budgets could become an incremental driver of bookings and revenue growth over the next 12-24 months. Goldman Sachs is more constructive on existing leaders with platform control points, proprietary data, machine-learning capabilities, and M&A integration capacity, while also noting that elevated valuations make validation through leading indicators especially important.
Risks
- The near-term risk is that security stocks have already priced in the medium-term AI inflection, while product budgets and fundamentals have not yet changed materially.
- Enterprise agentic AI applications are still largely in sandbox, POC, or temporary isolated environments, which may delay monetization of security budgets.
- AI value may be captured by AI-native companies, frontier model companies, or private new entrants, rather than flowing entirely to existing security platforms.
- Some areas such as code security, penetration testing, SOAR, and NDR may face competitive pressure from expanding LLM capabilities and changing partnership models.
- PANW and CRWD valuations are high relative to growth profiles and historical levels; if orders or pipeline do not improve, valuation pullback risk will be significant.
- There are risks in M&A integration and in making early bets on technology paths; if architectural change favors alternative approaches, platform companies may face investment missteps.
What to watch
- Whether AI security-related bookings, pipeline, and ARR disclosures improve from 2H26 through 1H27.
- Whether enterprise inference and agentic workloads move from testing, sandbox, and isolated environments into production.
- The speed of customer adoption across product cycles including SOC upgrades, AI detection and response, agent runtime monitoring, identity governance, prompt engineering, and data protection.
- Standalone revenue or bookings disclosures for products such as PANW Prisma AIRS, CRWD AIDR, Zscaler AI Protect, and OKTA AI Agents.
- Whether the AI security attach rate rises from about 0.6% toward the 2%-5% benchmark range seen in cloud security.
- The pace of AI security M&A by security platform leaders, the effectiveness of integration, and cross-sell capability.
- Market reaction during earnings season for high-valuation security stocks to the gap between the medium-term AI narrative and short-term fundamentals.