Wells Fargo, a Wall Street financial giant, recently released a research report stating that cybersecurity super-giants CrowdStrike (CRWD.US) and Palo Alto Networks (PANW.US) are experiencing a surge in order momentum for cybersecurity software products, driven by the rapid expansion of the AI inference market, ahead of their upcoming earnings reports and future outlooks. As AI moves into the massive-scale inference and Agentic AI workflow phase, cybersecurity demand is not simply "accelerating in tandem with frontier AI technology updates," but is likely to see structural incremental expansion far exceeding traditional IT spending.
For investors embroiled in the recent "closed-source AI vs. open-source" endgame debate, regardless of which side wins or if both models develop simultaneously, it represents a significant incremental tailwind for the two major cybersecurity software platform giants, CrowdStrike and Palo Alto Networks. The "closed vs. open" large model contest precisely provides the strongest "cross-scenario benefit" logic for cybersecurity.
AI cybersecurity platforms are also beginning to be defined by some Wall Street strategists as another structural AI investment theme following GPU/HBM, optical interconnects, power, and cloud infrastructure: open-source expands deployment numbers, closed-source expands centralized cloud value, hybrid architectures expand complexity, and Agentic AI massively expands permissions and attack surfaces—regardless of which AI technology path ultimately prevails, in the AI inference era, cybersecurity software platforms are the indispensable Security Control Plane for large-scale AI implementation.
From AI Computing Power to AI Security, the AI Tech Investment Theme Continues to Spill Over! Wells Fargo Bullish on CrowdStrike and Palo Alto Networks' Accelerating Enterprise Orders and New Customer Wins
It is understood that Wells Fargo analysts Richard Poland and Michael Turrin said in a report on Monday based on their cybersecurity distributor survey: "Security demand remains robust, reflected in a net 31% of partners performing above plan, with weighted year-over-year growth of 16%, up from 13% in the prior quarter, while over 50% of respondents expect further acceleration in the second half. Ranked by importance, the primary growth drivers are AI, identity security, endpoint security, data security, and exposure management. Respondents believe that up to approximately 40% of AI-related security spending comes from funding pools outside traditional cybersecurity budgets, including AI spending budgets, other IT budgets, and non-software security budgets."
Poland noted: "Respondents ranked PANW (Palo Alto Networks) as the top contender most likely to consolidate customer security spending, while also ranking first in market share growth in both Secure Access Service Edge (SASE) and security operations, and tied for second in identity security. Furthermore, Palo Alto Networks not only continues to hold the top spot as the most likely AI beneficiary, but its vote share saw the most significant increase, rising by 12 percentage points."
Wells Fargo reiterated its "Overweight" ratings on CrowdStrike and Palo Alto, maintaining price targets of $230 and $475, respectively, significantly above current record-high stock price levels.
Regarding CrowdStrike, Wells Fargo analyst Poland stated: "We tracked 10 deals exceeding $10 million and multiple deals exceeding $20 million, with customers broadly adopting its cloud, security information and event management, identity security, and extended detection and response solutions. Of the large deals we tracked, 22 were renewals and 6 were new customer orders, indicating that the company continues to expand existing customer business while consistently winning new clients."
Meanwhile, Palo Alto is also accumulating large-scale enterprise orders of a similar magnitude.
Poland added: "This quarter, 29 surveyed institutional investors reported business activity related to Palo Alto Networks, including 7 deals exceeding $10 million and another 5 deals ranging between $8 million and $10 million. Of the 29 largest deals we tracked, 15 came from new customers, slightly outpacing the number of renewals and product upgrade-related deals."
Palo Alto plans to report its fiscal Q4 2026 financial results on September 1, Eastern Time. Market consensus estimates show adjusted EPS of $0.98 and revenue of $3.35 billion.
CrowdStrike plans to report its fiscal Q2 2027 results on August 26, Eastern Time. Market consensus expects adjusted EPS of $0.29 and revenue of $1.44 billion.
Palo Alto was ranked first as most likely to consolidate customer security spending and ranked first in SASE and Security Operations share growth, with its "most likely AI beneficiary" vote share increasing by 12 percentage points; CrowdStrike saw numerous deals in the tens of millions and even over $20 million. This demand may begin to translate into fundamental financials: Palo Alto's Next-Generation Security ARR grew substantially by 60% year-over-year to $8.1 billion, with RPO up 36% to $18.4 billion; CrowdStrike's ARR grew 24% to $5.51 billion, with record quarterly net new ARR of approximately $256 million, up 32% year-over-year.
Open-Source and Closed-Source "Converge"—Palo Alto and CrowdStrike Aim to Become the "Mandatory Security Tax" of the AI Inference Era
The AI training era primarily addressed "building the model," while the inference era involves models interacting with enterprise data, APIs, databases, code repositories, identity credentials, and even real business tools billions of times daily; when AI Agents evolve from "answering questions" to being able to read files, call APIs, execute code, modify databases, and initiate workflows, the Attack Surface expands from human users and traditional endpoints to "humans + machine identities + Agents + models + toolchains."
OpenAI's recently disclosed real-world evaluation incidents have shown that advanced models can autonomously discover and chain vulnerabilities in real systems; Palo Alto's latest AI security architecture therefore directly covers Agent discovery, model/supply chain risk assessment, AI Gateway governance, runtime protection, and AI identity permission control. In other words, the more inference runs and the higher the Agent autonomy, the more identities, endpoints, APIs, cloud workloads, data, and runtimes enterprises need to protect.
The battle around open-source vs. closed-source is a persistent tailwind for the two cybersecurity giants, and this is also the strongest "cross-scenario benefit" logic for cybersecurity.
If closed models prevail, computing power concentrates in Hyperscalers and public clouds, with security demand centered on cloud security, SASE, security operations, identity, and API layers—leaders like Palo Alto, CrowdStrike, Zscaler, and OKTA remain core beneficiaries; if the more realistic hybrid model landscape emerges, as Morgan Stanley suggests, open-weight models handle high-frequency, low-cost tasks while closed models handle complex reasoning and Agent tasks, with workloads distributed across public cloud, private cloud, on-premises, and edge—security software demand actually expands further due to architectural fragmentation, increased identity counts, and higher governance complexity.
Additionally, if the open-weight path ultimately wins, with model inference largely migrating to enterprise private data centers, on-premises, and edge environments, enterprises themselves must bear responsibility for model supply chain, access control, data leakage, patching, runtime, and security guardrails—hence the article directly lists security software as one of the "biggest winners" in this scenario. This is why the real question is not "whether open-source or closed-source will weaken cybersecurity," but rather—where AI workloads ultimately run, and the security control plane must exist almost everywhere regardless.
Wells Fargo's latest channel survey indicates that cybersecurity product demand in the AI inference era is no longer just technical extrapolation but is translating into real orders and incremental budgets. The net ratio of security partners performing above plan reached 31%, weighted year-over-year growth rose from 13% last quarter to 16%, with over 50% of respondents expecting further acceleration in the second half; AI ranks first as the growth driver, and notably, respondents estimate that approximately 40% of AI-related security spending comes from outside traditional cybersecurity budgets—including AI budgets and other IT budgets—meaning AI is expanding the Security TAM, not merely reallocating within the existing security wallet.
Capital markets are also pricing in the incremental value of cybersecurity with real money. As of August 10, CrowdStrike's stock has nearly doubled year-to-date, while Palo Alto and Fortinet have both more than doubled, with the cybersecurity sector shifting from previous concerns about "AI replacing traditional SaaS software players" to trading on "the AI inference era actually massively expanding cybersecurity budgets."
image.png
But the most important boundary in investing is: a super-cycle in demand does not mean any price is worth paying. CrowdStrike, despite strong demand, once fell 7% in a single day because growth did not exceed extremely high expectations, illustrating that cybersecurity leaders like Palo Alto and CrowdStrike have transitioned from the valuation discount phase of "will AI disrupt our entire industry" to a high-expectation phase of "must continuously prove that large-scale frontier AI penetration translates into cybersecurity ARR, platform consolidation, and free cash flow growth."
Comments