Wells Fargo's latest research indicates that cybersecurity powerhouses CrowdStrike (CRWD.US) and Palo Alto Networks (PANW.US) are seeing a surge in order momentum for their security software products, driven by the explosive expansion of the AI inference market, just ahead of their upcoming earnings reports and forward guidance. As AI transitions into massive-scale inference and agentic AI workflows, the demand for cybersecurity isn't merely accelerating alongside frontier AI advancements; it's poised for structural growth that significantly outpaces traditional IT spending. For investors debating the "closed-source vs. open-source AI" endgame, either outcome—or a parallel development of both models—represents a major tailwind for these two platform giants. This very debate underscores the strongest "cross-scenario beneficiary" logic in cybersecurity, as AI security platforms are increasingly defined by Wall Street strategists as another structural AI investment theme alongside GPUs/HBM, optical interconnects, power, and cloud infrastructure.
Open-source models expand deployment numbers, closed-source models concentrate cloud value, hybrid architectures amplify complexity, and agentic AI massively broadens permissions and attack surfaces. Regardless of which AI path prevails, cybersecurity software platforms in the AI inference era are the indispensable control plane for scalable AI implementation. The investment narrative is spilling over from AI compute to AI security. Wells Fargo analysts Richard Poland and Michael Turrin reported Monday, based on their cybersecurity distributor survey, that security demand remains robust, with a net 31% of partners performing above plan, a 16% weighted year-over-year growth rate (up from 13% last quarter), and over 50% of respondents expecting further acceleration in the second half. The primary growth drivers, in order of importance, are AI, identity security, endpoint security, data security, and exposure management. Notably, respondents attribute roughly 40% of AI-related security spending to budgets outside traditional cybersecurity allocations, including AI budgets, other IT budgets, and non-software security funds.
Poland highlighted that Palo Alto Networks was ranked first as the vendor most likely to consolidate customer security spending, also leading in market share gains for both SASE and security operations, while tying for second in identity security. Furthermore, Palo Alto not only retained its top spot as the most likely AI beneficiary but also saw the most significant increase in vote share, climbing 12 percentage points. Wells Fargo reaffirmed its "Overweight" ratings on both CrowdStrike and Palo Alto, maintaining price targets of $230 and $475 respectively—levels notably above their current record-high stock prices.
Regarding CrowdStrike, Poland noted the tracking of 10 deals exceeding $10 million and several exceeding $20 million, with customers broadly adopting its cloud, SIEM, identity security, and XDR solutions. Of the large deals tracked, 22 were renewals and 6 were new customer wins, demonstrating continued expansion of the existing customer base alongside consistent new client acquisition. Meanwhile, Palo Alto is accumulating similar large-scale enterprise orders, with 29 institutional investors reporting related activity this quarter, including 7 deals over $10 million and 5 more between $8 million and $10 million. Of the 29 largest deals tracked, 15 came from new customers, slightly outpacing renewals and upgrade transactions.
Palo Alto is scheduled to report its fiscal Q4 2026 results on September 1, with consensus estimates of $0.98 adjusted EPS and $3.35 billion in revenue. CrowdStrike is set to announce its fiscal Q2 2027 results on August 26, with consensus expectations of $0.29 adjusted EPS and $1.44 billion in revenue. This demand is beginning to translate into financial fundamentals: Palo Alto's Next-Generation Security ARR surged 60% year-over-year to $8.1 billion last quarter, with RPO growing 36% to $18.4 billion. CrowdStrike's ARR grew 24% to $5.51 billion, with record quarterly net new ARR of approximately $256 million, up 32% year-over-year.
The AI training era focused on building models, while the inference era involves models interacting with enterprise data, APIs, databases, code repositories, identity credentials, and real business tools billions of times daily. As AI agents evolve from answering questions to reading files, calling APIs, executing code, modifying databases, and initiating workflows, the attack surface expands from human users and traditional endpoints to encompass "human + machine identities + agents + models + toolchains." Recent disclosures from OpenAI's evaluations have shown advanced models capable of autonomously discovering and chaining real-world system vulnerabilities. Palo Alto's latest AI security architecture directly addresses agent discovery, model/supply chain risk assessment, AI gateway governance, runtime protection, and AI identity access control.
In essence, the more inference runs and the higher the autonomy of agents, the greater the number of identities, endpoints, APIs, cloud workloads, data, and runtime environments that enterprises must protect. The open-source vs. closed-source battle is an unequivocal tailwind for both cybersecurity giants, representing the strongest "cross-scenario benefit" logic. If closed models prevail, compute concentrates within hyperscalers and public clouds, driving security demand toward cloud security, SASE, security operations, identity, and API layers, with Palo Alto, CrowdStrike, Zscaler, and Okta remaining core beneficiaries. If a hybrid model landscape emerges—which Morgan Stanley views as more realistic—open-weight models handle high-frequency, low-cost tasks while closed models manage complex reasoning and agentic tasks, distributing workloads across public cloud, private cloud, on-premises, and edge environments. This fragmentation would actually expand security demand due to increased architectural complexity, identity proliferation, and governance challenges.
Should the open-weight route ultimately prevail, with inference largely migrating to enterprise private data centers, on-premises, and edge locations, companies would bear direct responsibility for model supply chains, access control, data breach prevention, patching, runtime, and security guardrails. This scenario directly positions security software as one of the "biggest winners." The pertinent question isn't whether open or closed source will weaken cybersecurity, but rather where AI workloads will run—and the security control plane must exist virtually everywhere. Wells Fargo's latest channel survey confirms that cybersecurity product demand in the AI inference era is no longer just theoretical, but is converting into real orders and incremental budgets. Security partners' overall performance exceeded plans by a net 31%, weighted year-over-year growth rose from 13% to 16%, and over 50% of respondents anticipate further acceleration in the second half. AI ranks as the primary growth driver, with approximately 40% of AI-related security spending coming from outside traditional cybersecurity budgets—including AI budgets and other IT budgets—indicating that AI is expanding the security TAM rather than merely reallocating within existing security budgets.
Capital markets are pricing in this incremental cybersecurity value. As of August 10, CrowdStrike's stock has nearly doubled this year, while Palo Alto and Fortinet have both more than doubled. The cybersecurity sector has shifted from concerns about AI displacing traditional SaaS software to trading on the premise that the AI inference era will dramatically expand cybersecurity budgets. However, the critical investment boundary remains: a super-cycle in demand doesn't justify any valuation. CrowdStrike, despite robust demand, previously fell 7% in a single day when growth didn't surpass extremely high expectations. This illustrates that cybersecurity leaders like Palo Alto and CrowdStrike have transitioned from a discount phase questioning whether AI would disrupt their industry to a high-expectation phase where they must continuously prove that frontier AI's large-scale penetration translates into security ARR growth, platform consolidation, and free cash flow expansion.
Comments