U.S. markets showed a striking divergence overnight. As investors worried that calls to slow frontier AI development could eventually cool spending on GPUs, HBM and data centers, semiconductor names came under pressure. At the same time, cybersecurity stocks surged. CrowdStrike, Palo Alto Networks, Zscaler and Fortinet all moved sharply higher. The same “AI risk” narrative was hitting chips while pushing security software into the spotlight.
The more important takeaway is not simply that money rotated from hardware into software. The bigger question is whether cybersecurity is becoming a mandatory layer of AI CapEx. Once AI agents start connecting to email, code repositories, databases, CRM systems and payment tools, AI is no longer just reading information. It can call tools, modify files and execute real actions. That creates a much larger attack surface. A bad actor may not need to break into an entire corporate network if they can instead manipulate an agent that already has broad internal permissions.
That helps explain why enterprises are becoming more cautious about how AI models interact with sensitive data. Companies are increasingly asking where proprietary code, customer information and internal documents go once employees feed them into external models, what gets retained, and how those model interactions are audited. The concern is shifting from “what if the model gives a wrong answer?” to “what if the model has access to the wrong data or the wrong permissions?”
That creates a broader opportunity for the cybersecurity industry. AI does not only give attackers more powerful tools. Enterprise AI deployment itself creates new security requirements. Companies now need to control which models employees can access, what data those models can read, what actions agents are allowed to perform, and whether every AI interaction leaves a traceable audit trail. Identity security, data protection, Zero Trust and runtime monitoring may all become more important as AI moves deeper into enterprise workflows.
This is also starting to show up in actual business demand. Zscaler, for example, has been highlighting Agentic AI-related security products across areas such as data security, Agentic SecOps and protection for AI workloads. That matters because it suggests the market may be looking at more than just a short-term “AI fear” trade. A portion of enterprise security budgets may already be shifting toward new products built specifically around AI deployment.
Still, a one-day double-digit rally should not automatically be interpreted as the start of a new secular bull market for cybersecurity. Stocks such as CRWD, PANW and ZS already trade at demanding valuations, and the market has quickly priced in part of the AI-security narrative. The real test is whether enterprises add incremental security budgets because of AI agents and model deployment, rather than simply reallocating existing cybersecurity spending. If AI security starts contributing meaningfully to ARR, large enterprise contracts and net-new spending, then the theme becomes much more durable.
Tiger View
Tiger thinks the biggest shift is not simply “chips down, software up.” The market is starting to recognize that the more companies spend on AI, the more they may also need to spend protecting AI.
We have already seen AI infrastructure spending spread from GPUs into HBM, networking, power and cooling. Cybersecurity may be the next layer.
As agents move into enterprise workflows, security also changes. Companies are no longer only protecting people accessing systems. They increasingly need to protect AI acting on behalf of people. Who owns the account? What permissions does the agent have? Can sensitive data leave the company through the model? Can an agent execute the wrong action? Those questions create an entirely new set of risks.
Tiger would watch three things next: whether AI-security products begin generating standalone revenue, whether large enterprises explicitly increase security budgets because of AI, and whether identity and data protection become standard requirements for agent deployment.
If those signals keep appearing, cybersecurity may turn out to be more than a temporary software rotation. It could become one of the unavoidable costs of putting AI into production.
Related Stocks
Endpoint / Cloud Security: $CrowdStrike Holdings, Inc.(CRWD)$
Watch: whether AI-driven threats increase demand for endpoint protection, threat intelligence and automated response.
Security Platform: $Palo Alto Networks(PANW)$
Watch: whether enterprises continue consolidating security tools onto broader platforms, with AI security becoming an incremental growth driver.
Zero Trust / AI Data Security: $Zscaler Inc.(ZS)$
Watch: whether Zero Trust and data protection become default requirements as agents connect more deeply with enterprise systems.
Identity Security: $Okta Inc.(OKTA)$
Watch: in an agent-driven world, identity management may expand from “who can log in?” to “which agent can access what, and with which permissions?”
Network Security Infrastructure: $Fortinet(FTNT)$
Watch: whether rising AI traffic and a larger attack surface continue to support enterprise security infrastructure spending.
Today’s Poll
As AI moves into the agent era, which cybersecurity demand grows first?
① Data security — companies fear sensitive information leaking through models
② Identity security — agent permissions become a new attack surface
③ AI defense — using AI to fight AI-powered attacks
④ Too much, too fast — this is mostly a rotation from chips into software
For market discussion only. This is not investment advice. Markets involve risk, and investment decisions should be made carefully.
Comments
I still like the broader cybersecurity story because AI deployment creates new security needs. CRWD, PANW and ZS could benefit if AI security becomes a bigger budget item, but I would not chase a double-digit rally. I want to see actual ARR growth and enterprise spending first.
For me, the key question is whether AI security becomes a standard part of enterprise AI. If companies increase spending on identity, data protection and agent monitoring, cybersecurity could become another essential layer of the AI infrastructure stack.
@Tiger_comments @TigerClub @TigerStars
An AI agent can access databases, execute code, move data and trigger workflows at machine speed. That makes traditional “user login” security increasingly inadequate. CrowdStrike is already building dedicated agent identities and continuous authorization, while Zscaler is developing Zero Trust controls specifically for AI agents.
The interesting part is the economics: every new AI agent deployed into an enterprise could create another identity, permission set and attack surface that needs protection.
So cybersecurity may become an unavoidable AI infrastructure tax. The winners won’t simply be companies selling “AI security” — they’ll be those that turn identity, permissions and runtime control into recurring, mission-critical spending.
@Tiger_comments [龇牙]