Register and share your invite link to earn from video plays and referrals.

Nikesh Arora
@nikesharora
Palo Alto Networks
1.7K Following    111.8K Followers
In March I warned about weaponzied intelligence. AI will provide attackers an assymmetric advantage, and threats now move at the speed of AI. I had hoped for the industry to respond together. Today we all take one more stop towards that direction. Glad that @PaloAltoNtwks Is a founding partner of the Open Secure Alliance. Industry Leaders Join Open Secure AI Alliance for AI Safety and Security | NVIDIA Blog
Show more
Am not a good bat. Bowled 4 overs, over 3 games, Gave away 26 odd runs, one wicket. With @Uz_Khawaja hitting me for 6 in the 7/8th over lazily, and toying with me to let others play :)
@nikesharora @Barclays ummmmmm, excuse me?!?! Your debut was meant to be with me!!!!
We had Shantanu and Venkat and Raj. In addition to Zaheer Khan and Stuart Broad.
Welcome to the next level of cyber incidents. Lots to dissect here. 1. Dear frontier model friends - please direct the models to your infrastructure, code, and configurations to evaluate and understand if there are any zero days or misconfigurations before you attempt more testing. Had you done so, it would have possibly avoided the agent obviating your sandbox. (Another data point why offense is easier and more fun) 2. While testing build both offensive and defensive agents and have them act as a counter balance to ensure some degree of awareness and control, do not let agents run riot. Keep track of inference consumption to get a sense of activity. 3. Unfortunately this does continue to validate the power of these models. They can build complex attack paths and with ample compute will attempt to attack infrastructure and morph their intent and approach. Guardrailing will continue to be a challenge. 4. These attacks continue to maintain the urgency on enterprises need to test, validate and improve both their security posture and infrastructure. The born in the cloud players have a better chance to get this done soon versus the traditional enterprise which has existed for long and has complex network and IT infrastructure. 5. The red herring will continue to be open source and SMB. It will be hard to discover and remediate vulnerabilites in those environments, we underestimate the impact of those vulnerabilites getting exploited.
Show more
0
71
1.1K
151
Forward to community
In the presence of legends! This is not an AI post :). But for those who know, they know.
0
158
3.3K
94
Forward to community
Interesting take. The challenges today: 1. Most enterprises don't know how to make AI game changingly effective. As they embark on the journey, the use cases being addressed are "80%" single shot, semi deterministic use cases with multiple guardrails or humans in the middle. We are a little ways away from mass adoption of custom models. 2. More complex cases which require any multi agent orchestration and context retention are beginning to be conceived and tested. These cases will make model portability harder, requiring new evals and harnesses. One will have to commit to one structure and also commit to constantly updating and retraining your model.. 3. CIOs and CEOs aren't sure if the ultimate architecture is single stack, multi model - interoperable orchestration and context/harness/eval, or a custom model. Uncertainty causes slowdown on longer term decisions, which in this case is perhaps right. 4. Custom and Opensource come with the need to deploy on either your own GPUs or public cloud. "Interesting fact - if token prices fall as I hope - it will be cheaper to run frontier LLMs than open source on your own GPUs" 5. Generally horizontal solutions that can serve tens of thousands of customers make more money than vertical custom solutions, but maybe this time it's different? Even if we solve the model conondrum, the enterprises need to redefine workflows, collect more training data on each use case and rebuild the application in a simple UI flow, not everything will be done in a conversational window. But time will tell, this will continue to be a space to watch, lots of minds at work to solve this.
Show more
My bet: @thinkymachines will soon make more money than @AnthropicAI. Not by winning the race to build one standardized frontier model. By becoming the Palantir FDE for enterprise custom models. The playbook: 1. Release the best American open-weight model. 2. Drive widespread enterprise adoption. 3. Charge the largest companies 7–9 figures to post-train and run custom models behind their own firewall. The model rests on three bets: 1. Large enterprises will increasingly demand their own models with their own data, and this is how they differentiate and win. 2. Enterprises won’t need just one model. They’ll continuously need new models for different workflows, departments, and proprietary datasets. That creates extremely sticky, recurring revenue. 3. Autoresearch will make custom model development increasingly scalable. Tinker can become the interface enterprises use to post-train their own models—with @thinkymachines providing the expertise and infrastructure behind it. FDE, infra, everything, huge contracts. 4. Eventually, maybe everyone wants their OWN model, and autoresearch and training inside tinker on top of @thinkymachines's base model will make it happen. Meanwhile, Henry-ford-styled, standardized models will makes no margins. OpenAI and Anthropic will have their API margins squeezed by Deepseek/GLM/Grok/Meta etc, and their consumer subscriptions are loss centers. The fat margin will move to customization: proprietary data, post-training, evals, deployment, and infrastructure. If this thesis is right, @thinkymachines isn’t building just another frontier lab. It’s building the highest-value layer between frontier research and enterprise model ownership. Turns out, the best business model for enterprise is NOT to sell commodity API access. Sell them their own models. I’m extremely bullish on this approach. @miramurati may be the most commercially savvy frontier-lab leader. I have to admit it.
Show more
The CIO mindset - CIOs are busy nowadays. CEOs want progress on AI, their C-Suite peers want AI transformation resources, and everyone wants to move fast. On the other hand the AI landscape is far from static, coding is a real use case, but costs are rising and headcount savings are being overwhelmed by increased demand. Other POCs on AI are still being figured out and ROI isn't fully realized. CIOs need to determine long term architectures, choose partners and technologies which will likely change a few times before we stabilize. On the day job, (non AI side), CIOs need to decide which SaaS contracts to commit to where to retain flexibility, how to deliver the promises already made with projects mid stream, and what to redirect to pay for the AI landslide. They need to find budget dollars to work on all of the following: Priorities 1. Figure out AI, evaluate, commit to clear ROI and keep your powder dry. 2. Deal with Mythos and prepare for a new world of Cyber, rethink point solves vs platforms. 3. Create capacity in budget for increasing AI usage. 4. Evaluate the vendor landscape and evaluate how the vendors will evolve and determine strategic redirection where needed. 5. Prioritize hardware purchases where compute and memory prices are going to be on the rise for the foreseeable future. This is normal in a technology super cycle. The CIOs will have to power through these dynamics. We are definitely seeing this in the equity markets with everyone trying to pick winners and losers. I think it's too early to draw long term conclusions. Customers are still adjusting to the economic realities of AI and reallocating spend, this reset is being reflected in the equity markets.
Show more
Of course I do remember. I promised to do it then! I will keep my word. Not a word from @patrickc on the cheeky pint podcast, must be running out of beer.
@nikesharora @HarryStebbings Yes. And you should do more podcasts too. You’re good on them. Open invite to come on my show. (We met at Dell’s house with Travis in April)
The move to understand AI, it's global implications and the ability to keep the AI lights on around the world without reliance on particular global companies or nations has come back to the forefront with the recent activity around allowing models or phasing their rollouts. "Sovereignity" is again a key topic. 1. Layer 0 - Sovereignity of location, easy to achieve. 2. Layer 1 - Hardware (has to be bought by global companies but can be deployed and managed locally. 3. Layer 2 - Staffing - can use locals to staff. 4. Layer 3 - Services and in the future AI models (usually delivered by global cloud and AI players) - this is where the challenges begin, what tradeoffs do you need to make, can you run services independently of the mother ship? Or can you build them locally - usually creates a technological delta in innovation, usually local companies are scarce at this layer and some tradeoffs are needed for innovation and scalability. 5. Layer 4 - Applications - Can usually be built and maintained locally, as long as they are needed only in the local context. 6. Layer 5 - Data - This can also be segregated and held locally and can be restricted from global movement. The risks arrive in the services layer and associated tradeoffs, application isolation, especially if companies are global in nature originating out of the sovereign state. Ultimate sovereignity also causes a resilience issue - requires a backup outside the country. But there is a strong use case for nation state services, classified data and local services with citizen data. Looking forward to @ValarianHQ and Max taking on the problem.
Show more
Sovereign infrastructure, deployed across four continents. Built in Britain. Let’s get back to building hard things. @NEA @joinsequel @lightbank @litcapital XTX Ventures @nikesharora @gokulr
Show more
I love @satyanadella his ability to put technology transformations in simple terms is par none. In this instance I think it's important to understand the distinction in consumer, horizontal multi-tenant AIaaS and Enterprise which tends to be deep and vertical. 1. Consumer - this is not new news, the consumer has always been part of the product. Be it search (Bing or Google), social media (think TikTok, Snap, and of course FB), even unassuming products like Maps have always retained the knowledge learnt from customers, customers suspecting or unsuspecting have always had the choice. Use the product and share your prompts, location or preferences and that will be used to build a better product. So why is that surprising if it happens in AI, the model complex will continue to use consumer usage to train fundamental multiple modalities. This is the biggest technological event of our lifetime :). 2. Horizontal AIaaS (AI capability that doesn't need to be too enterprise specific - can be tuned, but is a 80% common use case) - Think coding, legal, many current SaaS categories - most likely agentic development for prosumers. All of this behavior is being used to train the model complex to get better at all these. The large swath of small medium size businesses will be fertile training grounds for such applications. They cannot deal with isolated apps and custom deployments. 3. Enterprise deployments - this is where I am not sure the reverse information paradox applies. There is an existing model of isolated single tenant public cloud deployments, deployments where our data, code and connectivity are both isolated and in the hands of the enterprise. This is the deployment we have for our development from all frontier models. All our grounding data, prompts, internal tribal knowledge is sequestered. This is important because this is where enterprise IP will reside. It will be a large task to capture, collate, interpret this data. Equally complex to maintain, evolve and make effective an enterprise AI architecture. But that is what we all will need to sign up for. This is not a cloud vs on prem debate, they can both be equally secured. On prem is probably more unwieldy at the moment given the fast pace of development.
Show more
Any company can take on an effort to replace software. I am more inclined to be supportive if it's custom software. If so, one will need to rethink the workflow, train the model for user and enterprise context, agentify it. If done right it will have the property of increasing data integrity and also providing an ability to create enterprise context and intelligence over time which can significantly improve outcomes. The tools to do so are still nascent and evolving, mostly because models are expanding their capabilities and remit across memory, eval et al. Also, there is no backward compatibility on model embedding, a new model appears and the entire exercise on eval etc needs to be repeated. If enterprises are attempting to replace packaged software, I would caution against that, packaged software will get reimagined as an AI application by new startups as technology stabilizes. The challenge is as always the availability of competent resources who can architect an agile, AI first backend infrastructure. If you don't try though, you won't learn and be ready.
Show more
Can anyone blame $SBUX? Honestly $IBM and $MSFT should be embarrassed with their AI ecosystems and strategy 1) more dollars shift from seats to compute 2) honestly another bullish datapoint for the cyber secular thesis … what do you think @nikesharora (my fav CEO in tech who has been dropping truth bombs lately)
Show more
We have PRISMA AIRS that can help do that with real time inspection and persistent red teaming.
@nikesharora will Palo Alto Networks make a secure sandbox product to deploy Chinese models for enterprises? feels like this is unsolved given regulatory complexity being too high
The AI Gateway is critical to driving security outcomes for our customers. We will shortly announce full integration which is currently underway and the team is working furiously on new capability. We are big, we might be slower than a startup, but we try to make up with quick decision making, more resources and GTM scale.
Show more
.@nikesharora my team is thinking of alternatives to Portkey / building on our own because they aren’t sure if PANW is going to keep investing. I think it’s a bad idea and wanted to hear from you directly.
Show more
Summary: I spent time trying to figure out this orchestration layer problem, can we design a multi model architecture in the long term. The more I dug in the more I understand that trying to build an abstracted layer is hard. As agentic activities increase and agent chaining and complex tasks get assigned to AI it will become harder to move between models. There is a reasonable probability that 75% of the enterprises will build their implementation of the solution to their core problem around one model "stack". Token price reduction by 90% is the solve and mobility between models from the same frontier lab! Evals, harnesses, cache memory are the moats and I don't see models providing simple abstraction to those. I know there are efforts to do this out there, the long term solve for orchestration if it works will need to be "Claude code" level of design genius. Here's a chat with Fable @HamzaFodderwala had. **Why abstraction looks easy.** Models are stateless — every API call is weights + a prompt assembled at runtime. Everything the model "knows" about you — memory, documents, history, tools — is injected into the context window by software outside the model. So in principle, all your state already lives outside the weights. The catch is what "state" includes. **Layer 1 — Data (fully portable).** Enterprise documents, tickets, logs. Retrieved via RAG: text is chunked, embedded, stored in a vector database (Pinecone, pgvector), and relevant pieces are fetched into the prompt per query. The embedding model is separate from the LLM, so this layer is genuinely model-agnostic. Already solved. **Layer 2 — Memory (portable in principle).** Systems like Mem0 and Zep sit between the app and the model: after each interaction they extract salient facts ("user prefers X"), store them as plain text, and inject the relevant ones into future prompts. Because the artifact is natural language, it reads into any model. Facts port. **Layer 3 — Orchestration/routing (works, but only for shallow tasks).** Gateways like OpenRouter and LiteLLM normalize API differences and route each request to the cheapest capable model. This is the fungibility layer being furiously built. It genuinely works for one-shot, verifiable tasks — classification, extraction, summarization — which conveniently are the tasks where cheap models suffice anyway. **Where it breaks — the non-portable state.** Four things stay behind when you switch: - **The harness.** Prompts, tool schemas, and guardrails are tuned to one model's quirks. An agent must get every step right, so reliability compounds: a model that's 98% reliable per step completes a 50-step task about a third of the time; at 90% per step, it almost never finishes. Swapping models costs you a few points per step — the difference between an agent that works and one that doesn't. - **The evals.** Swapping means re-testing everything and re-fixing every regression. The real switching cost isn't data migration — it's re-verification. Nobody has abstracted that. - **Procedural memory.** Facts port; skills don't. Cached successful workflows and learned workarounds are conditional on the model that produced them. - **Cache pricing.** Provider-specific, worth 75–90% of input costs on agentic workloads. Quiet lock-in. **The labs' angle.** They offer hosted memory, hosted file stores, caching, fine-tuning — every one pulls state from your side onto theirs. The labs will crack memory first, but as lock-in, not portability. Nobody standardizes their own exit door. MCP is the partial exception: it standardizes tool and data access across models, but doesn't touch harness tuning or evals. **Where 3P vendors fit.** Routers are thin-margin commodity plumbing; vector DBs and memory infra are real but small. The two structurally interesting positions: **eval platforms** (LangSmith, Braintrust) — since switching cost equals re-verification cost, whoever industrializes cross-model testing actually enables fungibility.
Show more
Send me one first :)
@nikesharora Honored. Consider giving my book out at your company!
Todays tweet substituted by a CNBC clip. 1. Don't over index on picking winners. Focus on how to deliver value to the enterprise. 2. Different horses for different courses I still want frontier LLM for drug discovery and cures. Maybe a task model to deflect customer service calls. 3. There is a constant funding gap till cash from ebitda and capex cross over, how much capacity does the market have, and who will it fund will be the uncertainty ahead, but winners and hyperscalers will continue to be funded. 4. There is infinite demand for AI. Which is always the holy grail, with infinite demand "if you build it they will come". 5. The orchestration layer will be built, there are many efforts out there - don't fall into the DIY trap, see how the market evolves, in the meantime focus on building your tribal knowledge and context which are specific to your business.
Show more
CNBC EXCLUSIVE: @PaloAltoNtwks CEO @nikesharora joins us to talk cybersecurity demand as enterprises adopt AI. Need to see pricing for AI come down, he told us:
Guess CNBC wants me on right now to dissect my tweets?
Lol let's go @Jason
@nikesharora @HarryStebbings @grok please rewrite nikesh's tweet above and make it more chud based and unhinged
Welcome to the second half of the year. The actions of hyperscalers in terms of their capital commitments will be key as the year proceeds, expect an uptick across the board, the demand is real. The flip side - the funding sources will need to be from the capital markets. The largest companies will flip to negative cash flow except for one or two. Hyperscalers have balance sheet capacity to do so (for 1-3 years), however new Frontier labs will need to go public, not sure there's more private market capital available to support their Capex needs. Of course, there's the chip guys, NVIDIA is at the party, will MU join the investment party to keep spending going? We still need visibility for when AI revenues will start to fund much of this cash need. Expect more advertising plays from LLMs, Token prices have to decline to drive Enterprise adoption. Expect LLMs to chase more vertical profit pools, legal, life science, expecting physical AI companies. Pure models will continue to see arbitrage with open source touching 30% usage, depth will create a better moat, breadth will commoditize. It's not a demand problem - "it's a monetization problem". Silicon valley has always built product with intensity and the market has funded adoption years. This time it might just be too big and the market may not have capacity to fund everyone. "Darwinian moment for AI providers?" If you are a founder, or a CEO - don't be distracted, focus on your product, how it gets better with AI. Eventually product and customer adoption will bring us to the other side, but expect a bit of a wild ride. We are still early in many PMF categories. Speed could create waste, but waiting and watching could leave us behind.
Show more
Just finished north of 200 meetings in Europe with customers and technologists. The conversations were primarily around AI, common questions include: 1. Are there examples of organizations who have been able to demonstrate production level systems and do those developments show a return in lower cost, efficiency or better top line? 2. What do you think about agents? How will we discover, govern and stop agents if need be. Perhaps the biggest security concern ATM. 3. The frontier AI models are expensive, what's the business case at these token prices to embed AI in our customer facing products? Where will token prices be in the future. 4. What are the longer term implications of Mythos like models? Do we need to update cyber infrastructure or all IT infrastructure? 5. What do you think of Chinese opensource models? Are they secure and what is the downside of using them if they can be secured and they are cheaper? The parts that surprised me were: 1. The pausing of Mythos and Fable 5 caused more consternation and concern in Europe both short term and raised longer term concerns on single model reliance or reliance or models not in ones control. I hadn't seen it from their POV. 2. Sovereignity which was always a topic and still is, is getting more nuanced - they want data residency, data localization and local resources, but there seems to be more willingness to accept global services on clouds. Classified systems continue to be an issue. Net net - we need to ensure we continue to build trust both on our Frontier models and their consistent availability, we need to get the right economics in place and spend more time in Europe communicating and building presence if we want AI adoption to keep pace with the US.
Show more
0
71
1.9K
177
Forward to community