Could Security Be AI’s Biggest “Second-Order” Trade?

Tiger_comments
17:48

U.S. markets showed a striking divergence overnight. As investors worried that calls to slow frontier AI development could eventually cool spending on GPUs, HBM and data centers, semiconductor names came under pressure. At the same time, cybersecurity stocks surged. CrowdStrike, Palo Alto Networks, Zscaler and Fortinet all moved sharply higher. The same “AI risk” narrative was hitting chips while pushing security software into the spotlight.

The more important takeaway is not simply that money rotated from hardware into software. The bigger question is whether cybersecurity is becoming a mandatory layer of AI CapEx. Once AI agents start connecting to email, code repositories, databases, CRM systems and payment tools, AI is no longer just reading information. It can call tools, modify files and execute real actions. That creates a much larger attack surface. A bad actor may not need to break into an entire corporate network if they can instead manipulate an agent that already has broad internal permissions.

That helps explain why enterprises are becoming more cautious about how AI models interact with sensitive data. Companies are increasingly asking where proprietary code, customer information and internal documents go once employees feed them into external models, what gets retained, and how those model interactions are audited. The concern is shifting from “what if the model gives a wrong answer?” to “what if the model has access to the wrong data or the wrong permissions?”

That creates a broader opportunity for the cybersecurity industry. AI does not only give attackers more powerful tools. Enterprise AI deployment itself creates new security requirements. Companies now need to control which models employees can access, what data those models can read, what actions agents are allowed to perform, and whether every AI interaction leaves a traceable audit trail. Identity security, data protection, Zero Trust and runtime monitoring may all become more important as AI moves deeper into enterprise workflows.

This is also starting to show up in actual business demand. Zscaler, for example, has been highlighting Agentic AI-related security products across areas such as data security, Agentic SecOps and protection for AI workloads. That matters because it suggests the market may be looking at more than just a short-term “AI fear” trade. A portion of enterprise security budgets may already be shifting toward new products built specifically around AI deployment.

Still, a one-day double-digit rally should not automatically be interpreted as the start of a new secular bull market for cybersecurity. Stocks such as CRWD, PANW and ZS already trade at demanding valuations, and the market has quickly priced in part of the AI-security narrative. The real test is whether enterprises add incremental security budgets because of AI agents and model deployment, rather than simply reallocating existing cybersecurity spending. If AI security starts contributing meaningfully to ARR, large enterprise contracts and net-new spending, then the theme becomes much more durable.

Tiger View

Tiger thinks the biggest shift is not simply “chips down, software up.” The market is starting to recognize that the more companies spend on AI, the more they may also need to spend protecting AI.

We have already seen AI infrastructure spending spread from GPUs into HBM, networking, power and cooling. Cybersecurity may be the next layer.

As agents move into enterprise workflows, security also changes. Companies are no longer only protecting people accessing systems. They increasingly need to protect AI acting on behalf of people. Who owns the account? What permissions does the agent have? Can sensitive data leave the company through the model? Can an agent execute the wrong action? Those questions create an entirely new set of risks.

Tiger would watch three things next: whether AI-security products begin generating standalone revenue, whether large enterprises explicitly increase security budgets because of AI, and whether identity and data protection become standard requirements for agent deployment.

If those signals keep appearing, cybersecurity may turn out to be more than a temporary software rotation. It could become one of the unavoidable costs of putting AI into production.

Related Stocks

Endpoint / Cloud Security: $CrowdStrike Holdings, Inc.(CRWD)$
Watch: whether AI-driven threats increase demand for endpoint protection, threat intelligence and automated response.

Security Platform: $Palo Alto Networks(PANW)$
Watch: whether enterprises continue consolidating security tools onto broader platforms, with AI security becoming an incremental growth driver.

Zero Trust / AI Data Security: $Zscaler Inc.(ZS)$
Watch: whether Zero Trust and data protection become default requirements as agents connect more deeply with enterprise systems.

Identity Security: $Okta Inc.(OKTA)$
Watch: in an agent-driven world, identity management may expand from “who can log in?” to “which agent can access what, and with which permissions?”

Network Security Infrastructure: $Fortinet(FTNT)$
Watch: whether rising AI traffic and a larger attack surface continue to support enterprise security infrastructure spending.

Today’s Poll

As AI moves into the agent era, which cybersecurity demand grows first?

① Data security — companies fear sensitive information leaking through models
② Identity security — agent permissions become a new attack surface
③ AI defense — using AI to fight AI-powered attacks
④ Too much, too fast — this is mostly a rotation from chips into software

For market discussion only. This is not investment advice. Markets involve risk, and investment decisions should be made carefully.

Where do you think the first demand for cybersecurity will emerge?(Maximum1 votes)
  • Data security: Enterprises are most afraid of confidential information being taken away by models(4 votes)
  • Identity security: Agent privileges will become a new attack surface(4 votes)
  • AI Defense: Using AI to Counter AI Attacks(1 votes)
  • The price has risen too fast; currently, more funds are rotating from chips to software.(0 votes)
Cybersecurity Stocks Surge — Can AI Security Become the Next Major Theme?
Cybersecurity took the rotation: CrowdStrike closed +13.85% at a record $235.38, Palo Alto over +13%, the Global X cyber ETF +10%, the group +6.52%. The trigger: two days of AI risk warnings from Anthropic, OpenAI and Microsoft. Budgets decide whether it lasts — monitoring, identity, cloud security and automated defense are where the AI trade moves from GPUs into software. The labs named the risk themselves, so that spend goes first. But security is a far smaller market than compute; it cannot absorb what rotates out of chips. The more dangerous AI gets, the better security does — buy that?
Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

  • Shyon
    18:37
    Shyon
    I would choose ②. As AI agents become more connected to enterprise systems, identity and permissions could become a major security challenge. Companies will need to know which AI agent is acting, what it can access, and what actions it can take.

    I still like the broader cybersecurity story because AI deployment creates new security needs. CRWD, PANW and ZS could benefit if AI security becomes a bigger budget item, but I would not chase a double-digit rally. I want to see actual ARR growth and enterprise spending first.

    For me, the key question is whether AI security becomes a standard part of enterprise AI. If companies increase spending on identity, data protection and agent monitoring, cybersecurity could become another essential layer of the AI infrastructure stack.

    @Tiger_comments @TigerClub @TigerStars

  • 苏36
    18:04
    苏36
    I’d pick ② Identity security. The biggest AI-security shift is not just protecting models—it’s controlling what autonomous agents are allowed to do.

    An AI agent can access databases, execute code, move data and trigger workflows at machine speed. That makes traditional “user login” security increasingly inadequate. CrowdStrike is already building dedicated agent identities and continuous authorization, while Zscaler is developing Zero Trust controls specifically for AI agents.

    The interesting part is the economics: every new AI agent deployed into an enterprise could create another identity, permission set and attack surface that needs protection.

    So cybersecurity may become an unavoidable AI infrastructure tax. The winners won’t simply be companies selling “AI security” — they’ll be those that turn identity, permissions and runtime control into recurring, mission-critical spending.

    @Tiger_comments [龇牙]

  • blimpy
    18:02
    blimpy
    Feels early to price this as mandatory AI spend when plenty of enterprises still have not finished basic zero trust. Rotation can run, but deployment reality is slower
  • DonnaMay
    18:02
    DonnaMay
    Identity security probably hits first. Every agent needs scoped permissions before data controls really matter, and that access sprawl shows up fast lol
Leave a comment
4
5