Closed-Source vs. Open-Source AI Battle Rages On, Three Cybersecurity Stocks Soar 130%! Trillion-Dollar "Security Debt" in the AI Era Ignites an Upgrade Frenzy
In recent months, share prices of cybersecurity companies have soared, with investors betting that threats posed by cutting-edge artificial intelligence models will benefit their businesses. A basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since bottoming out on April 10, shortly after Anthropic restricted the release of its Mythos AI model.
Meta Muse and OpenAI Astra are driving AI from answering questions to autonomously executing tasks, and are also continuously pushing cybersecurity to become a foundational capability that enterprises must invest in simultaneously when expanding AI deployment. This is why a basket of cybersecurity stocks tracked by Wall Street financial giant Goldman Sachs has more than doubled since hitting a low on April 10.
The Australian government disclosed on September 24 that when an OpenAI research team used an internal model on June 18 to study public pharmaceutical spending, the agent, after encountering access blocks multiple times, found alternative paths on its own and entered parts of the Medicare statistical reporting portal without authorization. OpenAI did not notify the Australian side until September 10, and the method and time interval of the notification sparked dissatisfaction from Australian Prime Minister Albanese. There is currently no evidence that personal information was affected, and the statistical portal is independent of patient information and the medical insurance payment system; however, the incident has pushed agent permission boundaries, behavioral auditing, and incident reporting mechanisms to the forefront of regulation.
The industrial significance of this incident lies in the fact that security investment is becoming a supporting condition for the large-scale application of AI. Australia has established an interdepartmental investigative working group to examine government cyber defense, incident response, and legal arrangements; the Minister for Government Services has also requested an assessment of whether the previously budgeted A$160 million cybersecurity infrastructure upgrade can be accelerated, and whether outdated portals can be migrated or decommissioned.
Security vendors have also participated in handling frontier model incidents: OpenAI previously disclosed in its review of the Hugging Face incident that it had cooperated with external advisers such as CrowdStrike to investigate the scope and impact of the activity. From this, one can see a very clear and specific transmission path for the expansion of cybersecurity demand in the AI agent era: the enhancement of the most frontier AI agent capabilities expands the systems and operational scope that need protection; actual incidents expose control gaps, further driving procurement of security assessments, system modifications, and continuous monitoring.
Palo Alto Networks CEO Nikesh Arora previously proposed at the company's earnings call on September 1 an approximately $1 trillion "cybersecurity debt," pointing to potential upgrade demand urgently needed to modernize old security architectures. He noted that about $1 trillion of pre-AI-era cybersecurity technical debt worldwide urgently needs modernization, emphasizing that about $1 trillion of global cybersecurity infrastructure is not yet ready to cope with AI threats, and this gap will bring long-term growth space for the industry.
The capital market has already reacted strongly to this change. The basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since its April 10 low, with CrowdStrike, Palo Alto Networks, and Fortinet all rising more than 130% over the same period; since September 11, the last trading day before Anthropic CEO Amodei called for slowing the development of the most advanced models, the basket has risen another 19%.
Another Wall Street financial giant, Bank of America, regards cybersecurity as an important investment theme and supporting force in the AI era, while Bernstein focuses on whether revenue growth can reach the strong acceleration implied by stock prices. Current pricing divergence centers on the intensity of commercialization: how much of the new security demand can be converted into subscriptions, module purchases, and recurring revenue. CrowdStrike's forward P/E ratio of more than 170 times, Palo Alto Networks' 91 times, and Fortinet's 48 times make order fulfillment and upward earnings forecast revisions important supports for subsequent market performance.
Whether open-source AI wins or closed-source AI wins, cybersecurity boundaries must continue to exist!
From the perspective of underlying system architecture, an agent's capabilities come from the collaboration between large models and the execution environment: the model generates plans, the execution framework calls browsers, code tools, databases, and business interfaces, the CPU handles task orchestration and tool operation, and memory and storage retain context, files, and operational state. As systems such as Muse and Astra can handle longer and more complex tasks, the objects enterprises need to protect also expand to agent identities, access credentials, tool connections, runtime environments, and cross-system data flows. Therefore, security controls must run through the execution process: who initiates the operation, what permissions are used, which data is accessed, whether human approval is required, and whether abnormal behavior can be interrupted in time.
The technical guidance of the Australian Signals Directorate clearly points out that the execution framework connecting tools and business systems outside the large model/AI agent system is an important place where organizations can directly implement permissions, monitoring, and governance. Based on this, cybersecurity belongs to a core beneficiary layer in the AI industry chain with strong "model-route neutrality." Whether enterprises adopt closed-source model APIs, self-deploy open-weight models, or call multiple models at the same time, they all need to manage identity, permissions, data access, and execution behavior.
Model upgrades or supplier switches will not eliminate these control needs; cross-cloud and cross-model deployment instead increases the value of unified governance. The Australian Signals Directorate also emphasizes that models can be replaced over time, while the execution framework and its security governance ecosystem may become more enduring organizational capabilities. Specific products have already developed along this direction: Okta manages agents as independent non-human identities, providing short-term credentials, authorization and auditing for each tool call; SailPoint, through cross-cloud and cross-application connectors, governs agent owners, permissions, and lifecycles.
Frontier model capabilities are also enhancing security vendors' own service capabilities. Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense on September 22, combining Anthropic's Claude Mythos 5, OpenAI's GPT-5.6-Cyber, and open-weight models, selecting models according to different tasks, continuously conducting security testing on web applications, APIs, cloud infrastructure, code repositories, and network assets, and providing remediation recommendations; this service is already offered through annual subscriptions. The same round of model progress both increases enterprise defense demand and helps security platforms expand detection coverage, shorten response times, and convert capability upgrades into chargeable continuous services. These developments provide concrete commercial cases for the view that "no matter which model route leads, security platforms have an opportunity to participate in value distribution."
On the performance side, CrowdStrike's revenue for the second quarter of fiscal 2027, ended July 31, was about $1.471 billion, up 26% year over year; annual recurring revenue (ARR) reached $5.84 billion, up 25% year over year, with net new ARR of $332.8 million for the quarter, up 51% year over year. These figures show that security demand has already been realized in some vendors' new business, but that quarter was earlier than the new round of market enthusiasm brought by Muse and Astra in September. The growth mechanism more worth tracking in the future is the expansion of non-human identities, cloud workloads, and AI application protection scope, driving customers to add security modules, expand subscription contracts, and increase platform usage depth. The investment value of security vendors will increasingly depend on whether they can convert the enterprise demand that "AI must run securely" into continuously growing recurring revenue and cash flow.
Cybersecurity stocks are red-hot, but some investors are beginning to question whether the rally can last long term.
In recent months, cybersecurity company stock prices have risen sharply, with investors betting that threats brought by the most frontier AI models will benefit these companies' businesses. However, some stocks have risen so much that investors are beginning to question whether they have overshot.
As shown in the chart above, consumer inertia is gradually being broken, and concept stocks related to agentic AI have risen sharply recently. A basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since hitting a low on April 10. Previously, Anthropic restricted the release of its Mythos AI model out of concern that it might be used to launch cyberattacks. Since then, shares of CrowdStrike Holdings, Palo Alto Networks, and Fortinet have all risen more than 130%, ranking among the ten best-performing S&P 500 constituents over the same period.
The rapid rise has made these stocks among the most highly valued in the market. According to data compiled by Bloomberg, CrowdStrike's forward P/E ratio exceeds 170 times, second only to Tesla in the S&P 500. Palo Alto Networks' stock trades at 91 times expected profit over the next 12 months, making it the fifth-most-expensive stock in the index. Fortinet's P/E ratio is 48 times, ranking 16th.
As shown in the chart above, AI security concerns have driven a surge in cybersecurity software stocks; the chart above shows changes since December 31, 2025.
"If you are considering entering now, you must realize that the price you pay already reflects expectations that everything will be perfect in the future," said Brad Long, chief investment officer of Wealthspire, which manages about $593 billion in assets. "The favorable factors facing cybersecurity are obvious, but if any signs of weakness appearif the AI capital expenditure cycle slows, or even if we simply stop seeing so many sophisticated AI attackstheir revenue growth could slow, and the stocks could fall sharply."
This rally contrasts sharply with the beginning of the year, when concerns about AI disrupting existing business models triggered indiscriminate selling across the software industry. As the industry's financial performance has been strong, such concerns facing many software companies have eased, and a recent string of warnings from within the AI industry about the technology's potentially serious threats has given investors another reason to buy cybersecurity stocks.
Since September 11, Goldman Sachs' basket of cybersecurity stocks has risen 19%. September 11 was the last trading day before Anthropic CEO Dario Amodei called for slowing the development of the most advanced models.
Today, the need to strengthen cybersecurity defenses is widely recognized. The question is whether these companies can achieve enough revenue and profit growth to meet the expectations implied by their eye-popping valuations.
"The cybersecurity sector may have overshot," Bernstein analyst Peter Weed recently warned when downgrading Palo Alto Networks, Okta, and SentinelOne.
In a September 17 report, he wrote that although real demand does exist in the sector, "the sector's stock prices appear to imply expectations that growth will accelerate enough to rival usage-based software businesses such as hyperscale cloud services or databases." However, Weed said growth in the cybersecurity business may be constrained by real-world factors such as customers' employee headcount.
Still, fundamentals appear to be moving in the right direction. At the end of August, CrowdStrike issued a better-than-expected revenue forecast, driving the stock up more than 20% the day after the earnings release, its largest one-day gain since 2019.
"The 'Mythos moment' prompted broad acceptance of the view that adopting AI requires security safeguards," CEO George Kurtz said in the earnings statement. "Every enterprise will run on AI, and securing AI is our largest market opportunity ever."
Several hacker attacks carried out with the help of AI this year, as well as intrusions carried out by AI agents, have alarmed cybersecurity experts and AI developers.
On Thursday, Australian Prime Minister Anthony Albanese said that an OpenAI model hacked a government website earlier this year, gaining unauthorized access to files on a website used to report medical statistics.
In July, OpenAI said its AI model accidentally hacked Hugging Face. Last week, Google disclosed that its Gemini AI model had similarly broken into three companies' systems during security testing.
"We believe the market is increasingly pricing in a step-change rise in cyber risk, which supports both higher security spending and a more aggressive valuation framework for the entire sector," Bank of America analyst Tal Liani wrote in a September 18 report. In raising target prices for CrowdStrike, Okta, and SailPoint, he called cybersecurity "a major investment theme in the AI era and a key force supporting the AI era."
Josh Taves, managing director of Post Oak Group, said that although cybersecurity stocks have already risen sharply, valuation signals can also be misleading if growth exceeds expectations.
"Given how much the cybersecurity sector has risen this year, I understand why people may view it more cautiously. But although I expect other types of software budgets to shrink as AI models take over work, security spending should remain strong, or even increase," he said. "In such an environment, traditional valuation metrics are less applicable than before. Because the demand backdrop is so strong, investors are willing to pay higher prices."
Related Articles

Hong Kong SFC's Dai Lin: Hong Kong Stock Exchange IPO volume rises but quality declines; enforcement values speed and efficiency.

Oil prices and yields surge alongside cooling AI expectations, U.S. industrial stocks drop nearly 10% and flash a technical red flag.

Ministry of Commerce: In the first eight months, China's outbound direct investment across all industries reached US$113.39 billion, up 3.9%.
Hong Kong SFC's Dai Lin: Hong Kong Stock Exchange IPO volume rises but quality declines; enforcement values speed and efficiency.

Oil prices and yields surge alongside cooling AI expectations, U.S. industrial stocks drop nearly 10% and flash a technical red flag.

Ministry of Commerce: In the first eight months, China's outbound direct investment across all industries reached US$113.39 billion, up 3.9%.






