For the past two years, Silicon Valley has spent enormous energy trying to make large models smarter.

That priority changes once those models leave the chat window and show up inside the enterprise as agents. From Palantir’s AIP deployments to internal rollouts across major tech companies, the problem facing CTOs is no longer raw intelligence. It is permission sprawl. Give an agent an account and it can read SharePoint, run SQL, modify code, or even click through a payment approval inside an ERP system. It is not an employee, yet it holds system credentials. It is not traditional software, yet it can call tools, access data and execute tasks on its own.
For roughly two decades, enterprise security was built around a simple premise: control people and devices, and defend the corporate estate. That premise is under strain. A legitimate agent carrying a legitimate token inside a legitimate workflow can still perform an unexpected privileged action because of logic drift or a poisoned prompt.
This is what makes the current security reset different from earlier cycles. AI lowers the barrier for attackers, but it also creates entirely new security objects: models, agents, MCP, machine identities, enterprise data and runtime. In practical terms, the control plane is moving away from the network edge and endpoints toward identity, data and runtime.
Why cybersecurity has moved back to the center of the AI story
Over the past decade, enterprise security settled into a fairly stable division of labor. Firewalls protected the network entry point. EDR watched endpoints. IAM handled identity and login. Data security focused on sensitive information. SOC teams dealt with alerts after the fact.
The logic underneath that stack was straightforward. Operators were assumed to be either employees or intruders. If a company could determine who the user was, whether the device was trusted and whether the connection was safe, most problems could be handled with mature tools and processes.
Agents break that model. An agent can be fully authenticated and still act outside the intent of its authorization because it has too much access, calls the wrong tool, or is influenced by malicious prompts or external content.
That leaves enterprises with a question they did not have to answer before: is the action being taken still consistent with the purpose for which the agent was originally authorized?

Viewed through the path an agent takes once it enters the enterprise, the companies discussed in the article fall into three broad groups: platform builders, identity-and-data control vendors, and firms that still guard the network and access layer.
Platform vendors: PANW, CRWD and S have the shortest path to monetization
Palo Alto Networks is trying to cover the full chain
Palo Alto Networks (PANW) remains the most fully platformized of the group. It no longer relies only on the traditional firewall business. Instead, it has been pulling Network Security, Cloud Security, SOC, Identity and AI Security into a single platform.
Its Prisma AIRS offering now covers models, data, AI applications and agents, while adding capabilities such as an AI Runtime Firewall and red teaming. The company is trying to address the entire chain: which model AI uses, what data it can access, which tools it can call, and whether abnormal behavior appears once the system is live.
The article cites quarterly revenue of $3.41 billion, up 34% year over year. That figure includes acquisition-related contribution, but the point stands: when new security budgets emerge, large platforms usually have the shortest route to monetization because the customers are already there, the contracts are already there, and new products can be cross-sold into an existing stack.
CrowdStrike sits where the action actually happens
CrowdStrike (CRWD) comes at the problem from a different angle, one closer to execution. An agent may reason in the cloud, but the actual action—running a script, writing a temporary file, invoking a system process—still happens on a server, in a container or on an employee endpoint. That is the natural territory of the Falcon platform.
By extending endpoint telemetry into runtime, CrowdStrike is positioned at the point where actions occur. Its core asset remains Falcon and the telemetry it has accumulated across endpoints and cloud workloads. The article says quarterly revenue rose 26% year over year, ARR increased 25%, and net new ARR was even stronger, suggesting the company is expanding from endpoint security into identity, cloud, runtime and SOC.
SentinelOne is pushing harder on autonomous security workflows
SentinelOne (S) is moving in a similar direction, though at a smaller scale. Its Purple AI strategy is more aggressive. Rather than stopping at an assistive tool, it aims to let a security agent take over the workflow of a junior analyst and move toward automated investigation, event correlation and triggered response.
If that model works, AI would not just change product features. It would change how security software is used and how it is priced.

Identity and data: the first native demand shock lands on OKTA, SAIL and VRNS
Okta and SailPoint are extending into agent identity
If platform vendors benefit from scale, the most direct native demand created by agents first shows up in identity and data.
Okta (OKTA) and SailPoint (SAIL) are both moving into agent identity, but from different starting points. Okta is closer to authentication and access management: who you are, whether you can log in, and which applications you can access. SailPoint is more focused on identity governance: why a permission exists, who approved it, how long it should remain in place, and whether it should be revoked once a task is complete.
That governance problem is already complex for human users. It becomes harder with agents, whose lifecycles may be short or persistent, which may call multiple tools, inherit user permissions, or even create new agents.
This is why SailPoint’s latest numbers stand out in the article. ARR rose 25% year over year, SaaS ARR grew 36%, and AI-driven ARR exceeded $70 million. AI products accounted for more than 30% of net new ARR, which the article treats as evidence that identity has moved beyond product narrative and into signed contracts.
Okta, by contrast, posted revenue growth of about 11% in its latest quarter, while cash flow and margins continued to improve. Its overall growth rate still trails the leading security platforms, so the next test is whether these newer products can begin to reshape the company’s broader growth curve.
Varonis is built around a simple question: what can the agent actually see?
Varonis (VRNS) sits on a more direct agent thesis centered on data. The company has long focused on sensitive data discovery, permission analysis, data classification and threat detection. It is now adding AI governance and AI runtime into the same system.
As agents become more capable, enterprises first need to answer a basic question: what exactly can this agent see?
The article says Varonis posted total revenue growth of about 18% year over year and SaaS ARR growth of 52%. It also notes that the 52% figure includes a large effect from traditional customers migrating to SaaS. Excluding conversion, SaaS ARR growth was about 25%.

That leaves a clear point to watch. Once the SaaS transition effect fades, can AI data security take over as the next growth driver? If agents truly move into production environments, data permissions may stop being an optional security module and become a prerequisite for deployment.
Network and infrastructure: the actors are changing, but the pipes still matter
Zscaler is moving from employee-to-app toward agent-to-app
The rise of agents does not make traditional network security irrelevant. It changes who is accessing enterprise applications and the internet.
Zscaler’s (ZS) zero-trust model historically managed Employee → Application. The article argues that this will gradually expand to Employee + Workload + Agent → Application. As the number of agents rises, so does the volume of machine access that needs authentication, authorization and isolation.
As long as machine-generated access traffic grows exponentially, the billing point for zero-trust gateways remains intact. Zscaler’s latest quarter showed revenue and ARR growth of about 25%, but both figures were closer to 20% after excluding the impact of the Red Canary acquisition. The next question is whether agent-to-app demand can reaccelerate net new ARR.
Fortinet is tied to private deployment and infrastructure demand
Fortinet (FTNT) has a more infrastructure-heavy AI thesis and has benefited from private deployment trends. It is not a classic agent security company. But if more financial institutions, healthcare groups, large enterprises and government projects build their own GPU clusters, private clouds and AI factories, demand should rise for network isolation, east-west traffic controls, firewalls, SASE and security operations.
Those are all areas where Fortinet has long-standing strength. In that sense, the company is betting that traditional infrastructure remains essential in the new compute cycle, and that private AI could open a fresh enterprise network and security procurement cycle.
Cloudflare is aiming at the entry point of an agent internet
Cloudflare is the outlier in the group. The article describes it as the most ambitious and the most expensive on valuation. NET is not easily classified as just a cybersecurity company. Its mix of CDN, WAF, DDoS, Zero Trust, Workers and a global edge network places it across internet infrastructure, cloud and security at the same time.
As agents spread, the structure of internet traffic itself may change. The old pattern was more human-to-web. The next one could include much more agent-to-API and agent-to-agent traffic. Agents may visit websites, call models, execute code and even complete machine payments on their own.

That means Cloudflare is not only betting on AI security. It is betting on a broader shift: if a growing share of internet traffic is generated proactively by machines, can NET become a key gateway for that agent internet layer? The article says this is what sets Cloudflare apart from other security names. The upside narrative is larger, but more of that expectation is already reflected in valuation.
The valuation divide comes down to who can put agents into ARR first
When the industry thesis is brought back to fundamentals and valuation, the market has already started to sort the field.
- High-premium group: CRWD and NET. These companies still carry growth expectations of 20% or more, and investors are pricing in the idea that AI can keep expanding their total addressable market. Their EV/Sales multiples remain at the top end.
- Quality-defensive group: PANW and FTNT. Their growth is less explosive, but they are supported by platform depth, infrastructure positioning and strong free cash flow.
- Optionality-still-unproven group: SAIL, VRNS, ZS and OKTA. Their valuation centers are more restrained, which also leaves room for upside. If any one of them can show that agent products are materially lifting net new ARR, a rerating becomes easier to imagine.
The article argues that the AI narrative in cybersecurity has already moved beyond the broad claim that hackers use AI too, so the whole sector benefits. That logic was too diffuse. Almost every security company could tell that story, launch a copilot, an agent, runtime security or agent identity, and explain why AI expands its TAM.
The real split is emerging because enterprises themselves are now using AI at scale, which forces a redesign of the security architecture. The next stage is about who can show these new demands clearly in reported numbers and use them to reaccelerate overall revenue.
That is why PANW, CRWD, SAIL, VRNS, ZS, FTNT and NET belong in the same discussion. Platform companies are competing on distribution efficiency. Identity and data vendors are competing on how quickly they can monetize new control points. Network and infrastructure firms need to prove that agents and private AI will create new traffic and a new procurement cycle.
The article closes on a simple test: who can prove first that agents are changing the company’s growth curve? That is also why SailPoint’s disclosure of AI-driven ARR matters more than the mere launch of an agent product. If customers are actually buying AI products, if net new ARR starts to show up, if overall growth turns higher again, and if that revenue converts into profit and cash flow, the market will respond accordingly.
From that perspective, cybersecurity is not a side story that suddenly appeared outside the AI theme. The more capable AI becomes, the deeper the enterprise fear of losing control. The winners in this cycle will be the companies that can convert that fear into real cash flow in quarterly results.

