THE NEXT BIG AI TRADE MAY BE CYBERSECURITY
The next major leg of the AI economy may be security because the same agents that make enterprises more productive also create a completely new attack surface. $CRWD CEO George Kurtz says the unit of threat is no longer the hacker but the autonomous campaign, where coordinated agents can execute attacks at machine speed.
That changes more than attack volume. Kurtz argues that “sophistication is dead as an attribution signal” because AI can give a lone actor execution that once required nation state resources, which means defenders have to rely more heavily on identity, infrastructure and intent to understand who is behind an attack.
The commercial implication is even bigger with every AI agent effectively becomes a privileged identity with access to data, applications and eventually payment rails, so enterprises will need least privilege access, short lived credentials, traceable actions and a kill switch built into the architecture from day one.
That pushes security closer to runtime where endpoints, cloud workloads, SaaS and identity become the actual control points. Governance documents cannot stop an agent moving at machine speed, which is why I think security increasingly becomes embedded infrastructure rather than something companies layer on after deployment.
This is where $CRWD, $PANW, $ZS and the broader identity stack start becoming more important to the AI economy. CrowdStrike has SafeMind with NVIDIA, Cloudflare is working around OpenAI models, Zscaler is working with OpenAI and Anthropic and Palo Alto is building its own AI security stack, so the market is already moving from theory into an infrastructure land grab.
CrowdStrike’s advantage is that partnerships can be copied but fifteen years of deployed telemetry cannot. If every blocked attack feeds back into detection and makes the next defense better, the Threat Graph becomes more valuable as agent activity scales and security starts to look like a network effect.
There is also a regulatory angle that could become meaningful. Kurtz wants AI weights, training clusters and APIs treated as critical infrastructure, which could eventually bring tighter standards, incident reporting and procurement requirements around the entire AI stack and create another durable spending layer around compliance and protection.
The unresolved problem is speed. If attacks happen in milliseconds but humans still own the highest consequence decisions, the defender remains the bottleneck at exactly the moments that matter most. That is why autonomous defense will likely become one of the most important software categories of the next several years.
So while the market is debating whether frontier AI should slow down, enterprises still have to secure the AI already being deployed today. That is why I think AI security becomes one of the clearest second order beneficiaries of the AI economy regardless of how quickly the next model arrives.
Show more