AIM Media House

Palo Alto Networks Sees AI Turning Cybersecurity Into A Race Against Machine Speed

Palo Alto Networks Sees AI Turning Cybersecurity Into A Race Against Machine Speed

Palo Alto Networks closes FY2026 with record growth as AI agents, identity risks and platformization reshape enterprise cybersecurity.

Palo Alto Networks is entering fiscal 2027 with a cybersecurity business increasingly shaped by the same technology it is trying to secure. The company closed fiscal 2026 with $11.5 billion in revenue, up 24% year over year, while Next-Generation Security annual recurring revenue (ARR) reached $9.1 billion, up 63%. In the fourth quarter alone, it added nearly $1 billion in net new Next-Generation Security ARR.

The results come as enterprises move from experimenting with generative AI toward deploying systems that can act with greater autonomy. That shift is changing the security problem. AI systems can access applications, retrieve information and execute tasks, creating a new layer of risk around machine identities, permissions, data and runtime behavior.

Palo Alto Networks Chairman and CEO Nikesh Arora argues that this is also accelerating a strategy the company has pursued for years: bringing more security functions onto a unified platform. The company reported approximately 220 net new platformizations in the fourth quarter, more than twice the volume recorded when it began tracking the metric two years ago.

AI Is Expanding The Security Perimeter

The change in enterprise AI is making the boundary that security teams have to protect increasingly difficult to define. A conventional enterprise environment largely revolves around employees, devices, applications and network traffic. Autonomous agents add software entities that can interact with those systems without continuous human intervention.

This creates security requirements around credentials, permissions and monitoring. An agent that can access a database or call an application programming interface (API) effectively needs an identity and a defined scope of authority.

That problem is already becoming a distinct enterprise security concern. An emerging AI security budget is increasingly covering runtime monitoring, model access and non-human identities alongside traditional security spending. 

AI-enabled cyber risks are also appearing in current security research. OpenAI describes prompt injection as a security problem in which malicious instructions embedded in external content can manipulate an AI system into taking actions its user did not request. Its guidance emphasizes limiting an agent's access and constraining the consequences of an attack even when manipulation succeeds.

Palo Alto Networks sees the same shift in its customer conversations. Arora says the company is seeing enterprises ask how they can secure AI deployments before putting them into production, particularly as models become better at finding vulnerabilities.

Anthropic's Mythos models have added evidence to that concern. Anthropic's research on Mythos Preview found that the model showed strong capabilities in computer security tasks and led the company to launch Project Glasswing, an effort focused on using AI for defensive cybersecurity. Anthropic introduced Mythos 5.1 on 09/01/2026 and said access remains limited to vetted organizations. 

The development has also pushed financial institutions and technology companies to examine defensive applications of frontier models. Project Glasswing's cybersecurity effort brought together organizations to use Mythos Preview for vulnerability detection, testing and other defensive work.

Palo Alto Is Building Around Agents And Identity

Palo Alto Networks is responding by extending its security architecture beyond conventional network and endpoint protection. Its Prisma AIRS platform is focused on securing AI applications and agents, while the company's CyberArk acquisition, now integrated into the Idira platform, adds identity security and privilege controls.

Prisma AIRS surpassed $100 million in ARR within four quarters of general availability, according to the company. It also ended the fourth quarter with more than 800 customers.

The company says its approach is intended to cover the lifecycle of an agent, from identity and credentials through its interactions with applications and the behavior that follows. That puts identity at the center of the emerging security model.

Other cybersecurity companies are also developing products to secure AI-agent identities. Okta's work on AI-agent identity focuses on discovering agents, governing their permissions and controlling the systems they can access.

For Palo Alto Networks, the CyberArk acquisition gives that problem a direct place within its platform. Arora says Idira is intended to extend identity and privilege controls to AI agents, where every machine action needs to be authorized, scoped and auditable.

The company's security operations business is also being reshaped around this model. XSIAM, part of the Cortex platform, finished fiscal 2026 with more than $700 million in ARR, up 70%, and passed 1,000 customers.

Palo Alto Networks says customers using XSIAM can reduce response times substantially because security telemetry is already available within the platform's data architecture. The company's objective is to reduce human intervention in detection, prevention and remediation.

That ambition is also behind its acquisition of Console, which Palo Alto Networks announced it had completed on September 1. The company says Console will expand Cortex's ability to support agentic workflows across enterprise operations.

Platformization Becomes Central To The Strategy

The AI shift is reinforcing Palo Alto Networks' view that enterprises will increasingly consolidate security technology on unified platforms.

The company reported that its platformized customer cohort generated net revenue retention above 120% in the fourth quarter. It also reported approximately 220 net new platformizations during the period, with large deals spanning multiple parts of its portfolio.

One fourth-quarter agreement was a $126 million contract with a global telecommunications company that expanded its network security deployment and adopted Prisma Access for secure access service edge (SASE). Another $72 million transaction with an IT service provider covered Network and AI Security, Cortex and Idira.

SASE itself is becoming an important example of the strategy. Palo Alto Networks says its fiscal 2026 SASE bookings grew 40%, while it displaced incumbent providers in nearly 100 accounts representing more than $400 million in total contract value.

The company is now forecasting $14.1 billion to $14.2 billion in fiscal 2027 revenue, representing 23% to 24% growth. It expects Next-Generation Security ARR to reach between $11.075 billion and $11.175 billion, while adjusted free cash flow margin is expected to remain at 38%.

Those targets depend in part on continued AI-driven demand for cybersecurity. Palo Alto Networks is also expecting its Cortex revenue to grow approximately 30% in fiscal 2027, while Idira revenue is expected to reach approximately $1.5 billion on a pro forma basis.

The challenge is whether enterprises can modernize quickly enough to keep pace with AI-enabled threats. Palo Alto Networks estimates that there is approximately $1 trillion of cybersecurity technical debt globally, while its customers are still balancing security modernization against other AI transformation projects.

Palo Alto Networks is betting that enterprises will favor security architectures capable of collecting data across environments, controlling machine identities and responding through increasingly automated systems.

The company's fiscal 2026 results show that customers are already paying for more of that architecture. The next phase will test whether platformization can scale as quickly as the AI systems it is designed to secure.

Key Takeaways

  • Palo Alto Networks reports $11.5 billion revenue, a 24% increase year-over-year.
  • Next-Generation Security ARR surged to $9.1 billion, up 63% in fiscal 2026.
  • AI's rise shifts cybersecurity risks toward machine identities and autonomous systems.
  • CEO Nikesh Arora emphasizes unifying security functions on a single platform.
  • Company achieved over 220 new platformizations in Q4, doubling previous metrics.