Palo Alto Networks: Arora Says Anthropic's Mythos Did More for Cybersecurity Sales Than His Own 8-Year Pitch, While Warning Frontier Models Won't Replace Point Products on Economics
Comments from Goldman Sachs Communacopia + Technology Conference, September 10, 2026
Palo Alto Networks Chairman and CEO Nikesh Arora used a fireside chat at the Goldman Sachs Communacopia + Technology Conference to lay out how Anthropic's "Mythos" model has reshaped customer conversations, why he believes frontier large language models are structurally disadvantaged in core enforcement markets, and why he remains skeptical that neocloud infrastructure represents a durable business for security vendors. The session, held just after Arora's return from Geneva, offered unusually candid detail on how AI is reshuffling the competitive map in cybersecurity and where Palo Alto is placing its own bets.
Mythos Triggered a Demand Shock, But the Real Product Is the Multi-Model Harness
Arora said Anthropic's Mythos tool has done more to sell cybersecurity budgets than his own eight years of evangelism. "I spent 8 years trying to convince people cybersecurity is important. Dario did it in 1 week. He's better than me, clearly. Mythos has been more useful for me as a marketing tool than anything I did for 8 years," he said. Since Mythos launched, Palo Alto has fielded inbound interest from roughly 2,000 companies across CEO, CIO and CISO levels, all asking what the tool means for their own vulnerability exposure.
The company ran its own infrastructure through the tool and surfaced 1,200 potential vulnerabilities, which took three to four months to triage down to a steady-state cadence of a handful of genuine findings per month, in line with pre-Mythos levels. Critically, Arora disclosed that no single model captured the full vulnerability surface: roughly 60% of findings came through Mythos, 30% through OpenAI's models, and 10% through other models, forcing Palo Alto to build a multi-model harness rather than rely on any one frontier lab. That discovery-and-remediation cycle is now becoming a packaged service Palo Alto sells to enterprise customers, and it is the entry point into the platform and SIEM conversation that follows.
Why Frontier LLMs Won't Displace Point Security Products, According to Arora
Arora pushed back hard on the notion, reportedly floated on stage earlier by Nvidia's Jensen Huang, that frontier models represent a major commercial opportunity inside security enforcement points. His argument centers on unit economics rather than capability. Endpoint security is priced around $30 to $40 per seat annually, while a typical laptop generates roughly 160 megabytes of daily traffic. "If you put a frontier LLM to inspect 160 megabytes a day at the edge of your laptop, I suspect it's going to cost you more than $40 a year," he said, adding that unless customers are willing to pay $4,000 rather than $40 per endpoint, frontier models are priced out of that layer entirely.
He also drew a sharper technical distinction: LLMs are trained on the mainstream case, not the edge case, comparing the gap to Waymo needing explicit training for scenarios outside its default distribution. Because vulnerability detection models have effectively been trained on the industry's investment in coding assistants, they are very good at spotting bad code but cannot distinguish malicious intent from legitimate testing, citing Palo Alto's own internal code designed to simulate attacks as an example a model would flag incorrectly. His conclusion is not that AI is irrelevant to security, but that "average intelligence will become free" over time while compute remains the scarce, priced input, meaning cybersecurity vendors will become consumers of frontier tokens embedded into their own products rather than being disintermediated by them.
The Platform Thesis: AI Advantages Incumbents With Consolidated Data
Arora's central strategic argument is that AI capability requires stitched, cross-domain data to be useful for defense, which structurally favors vendors who already sit across multiple enforcement points. He walked through a hypothetical attack traversing laptop, data center firewall and cloud database, each defended by a different vendor, arguing that none of them can reconstruct the full attack chain without a shared data layer. "Somebody has to collect all the data, then go make sense of it," he said, arguing that single-vendor stacks solve this natively while multi-vendor environments require agents to coordinate with other vendors' agents, "which is just a complicated solve." His framing: "AI is advantaged incumbents with platform stacks."
This is already showing up in renewal cycles. Arora described email traffic where customers are consolidating a third network vendor onto Palo Alto simply because the company already holds two of three pieces of the stack, absent any active rip-and-replace campaign. SOC transformations, by contrast, tend to be one-shot six-month engagements rather than gradual evolutions.
Network Traffic Tailwind Tied to the Broader AI Buildout
Asked about the firewall cycle implications of rising agentic traffic, Arora reiterated the data point from Palo Alto's last earnings call that agentic traffic on its SASE platform is up ninefold, but framed it within a larger thesis: if $5 trillion is spent building AI compute over the next five years, traffic volumes should rise commensurately, and virtually all enterprise traffic today is subject to some form of inspection, whether through SASE, software or hardware firewalls. The exception, he said, is coding traffic. "If $100-plus billion of ARR is being generated in coding, most coding instances are not secured. We have to go fix that first. That hasn't been fixed."
No Vendor, Including Palo Alto, Has Built the AI Security Stack Yet
Arora was unusually direct in stating that the value-added software layer for AI security does not yet exist across the industry. "No vendor, including us, has the full stack," he said, pointing to Meta's newly announced Muse architecture as an example of how quickly agentic security architectures are shifting underneath vendors' feet, requiring three to six months just to understand new integration hooks, and noting that neither Anthropic's Claude Code nor OpenAI's Codex currently expose the hooks needed for third-party inline security. He drew an analogy to aviation security: "They didn't invent TSA when they invented planes. TSA took a long time to torture us. So it will take a while to get to torture the AI guys." Palo Alto currently generates roughly $100 million from Prisma AIRS, its real-time AI security product covering prompt injection and model manipulation, but Arora characterized the broader agentic security TAM as still being built out, warning that of roughly 3,000 AI-security startups funded last year, around 2,000 will not survive.
Neocloud Security Opportunity Is Smaller Than the Narrative Suggests
Arora offered a notably bearish carve-out on the neocloud infrastructure buildout as a security opportunity. Multi-tenant data centers require firewalls for segmentation, but he estimated that only 10% to 15% of new data center capacity being built is multi-tenant, with the vast majority single-purpose and single-tenant, citing Anthropic's practice of buying entire data center capacity outright and managing its own inter-facility connectivity without third-party firewalls. He was similarly skeptical on enterprise-run sovereign AI data centers, arguing the talent required to operate them well sits overwhelmingly at frontier labs, "I think 92% of people will not get a—it's like the teacher will have to rework their homework right now," and cautioned that DIY infrastructure bets are premature given how unsettled the underlying technology remains. His broader public commentary on neocloud economics has been pointed enough to draw backlash on social media, referencing pushback from what he called "Nebius lovers" after he argued that funding capital-intensive data center buildouts with equity is poor economics even if it is working for now.
M&A Framework: Getting Into the "Token Flow"
Arora provided his clearest articulation yet of the logic behind Palo Alto's acquisition strategy, including the Chronosphere observability deal. Security typically attaches at 2% to 5% of underlying IT spend, so if enterprise AI spend scales toward $1 trillion in annual recurring revenue, capturing even a small attach rate is highly valuable, "I just need to find something to get in token flow," he said, using data volume as his proxy for token exposure. He named observability, SOC, and endpoint inspection as the three largest data businesses and said Palo Alto's acquisitions are deliberately built around owning data collection once and monetizing it across multiple use cases, including internal IT data via its Cortex-adjacent Console product. Since 2018, Palo Alto has completed 47 acquisitions and now ships roughly 70 product releases annually, compared with no meaningful product innovation between 2015 and Arora's arrival in 2018.
Moat Metrics and Industry Consolidation
Pressed on what protects Palo Alto from disruption in a market in flux, Arora pointed to scale metrics rather than software alone: 180 million deployed sensors globally and 19 petabytes of daily data processed through Google Cloud, both of which he argued would require a competitor to physically displace before gaining share. He noted the cybersecurity industry's market capitalization has grown from $40 billion in 2012, when Symantec held roughly 30% share, to $670 billion today, with Palo Alto now accounting for close to $300 billion of that figure, supporting his view that the industry continues to concentrate around platform vendors rather than fragment. He also flagged an operating efficiency argument, estimating Palo Alto can run its business 500 to 600 basis points more efficiently than smaller competitors due to AI-driven productivity gains, framing profitable scale itself as a competitive advantage.