Marketing Communication. Capital at risk. For Professional Investors Only. Please read fund legal documentation before making any final investment decisions.
In April 2026, Anthropic offered a glimpse into how AI could transform cyber threats. Its Claude Mythos Preview model could identify software flaws, write code to exploit them and execute a multi-step intrusion with limited human direction.¹ Cybersecurity shares fell in the days that followed, something the Bank for International Settlements (BIS) interpreted as investor concern that AI could make existing security products obsolete.²
Subsequent earnings seasons have challenged that view. Rather than weakening demand for cybersecurity, AI appears to be accelerating it. Across the two quarters since, the largest listed pure-play security vendors have posted accelerating demand and attributed it to AI.³,⁴,⁵,⁶ CrowdStrike generated a record net new annual recurring revenue (ARR) of $332.8 million in its fiscal second quarter of 2027, and 51% growth year on year.⁷ Palo Alto Networks added almost $970 million of net new next-generation security ARR in a single quarter, roughly twice the previous year’s figure.⁸ Zscaler reported that security-for-AI bookings increased by more than 50% sequentially, with the associated pipeline up 75%.⁹ Okta, which launched its agentic identity products in April 2026, reported subscription backlog of $4.86 billion, up 17%.¹⁰
The environment that has emerged appears to be an AI-driven cybersecurity arms race. Frontier models are lowering the cost and complexity of mounting attacks while raising the value organisations place on preventing them. According to IBM and the Ponemon Institute, 85% of breached organisations plan to increase spending on security tools and governance in response to frontier AI models.¹¹
This article examines how offensive AI capabilities are advancing, why the gap between finding flaws and fixing them is widening, and which parts of the security stack may be poised to benefit.
An attack chain is the sequence an intruder works through: survey the target, find a way in, get in, move sideways towards more valuable systems, take the data out. Until recently AI showed up in the first two stages, writing more convincing phishing emails. The World Economic Forum's survey of 804 leaders across 92 countries now has 94% expecting AI to be the most significant driver of change in cybersecurity in the year ahead, and found evidence that AI has moved to cover all five stages.²⁰
Anthropic disclosed a campaign in November 2025, designated GTG-1002 and attributed with high confidence to a Chinese state-sponsored group, in which the model executed 80% to 90% of tactical operations across roughly 30 targets while human operators approved the transitions between phases.²¹ Its follow-up report of 10 September 2026, covering 39 cases over eight months, shows how far that pattern has spread: one Chinese-speaking cluster ran parallel agent swarms that revealed more than a dozen possible zero-day findings (flaws the vendor does not yet know about and so cannot have fixed) in a single month, and a Russian espionage group engaged 24 of 27 targeted institutions over 130 days, with agents watching security products for detections and rebuilding the malware until it slipped past.²² The tooling is the part that has not changed, as GTG-1002 ran on off-the-shelf penetration testing software with almost no custom malware and the intrusion pattern is the one defenders have faced for fifteen years.²³ Rather, the shift is one of speed.²⁴
The cost of an intrusion has reduced as model capability has advanced. A full attack chain consumes around 100 million tokens, which prices an intrusion attempt in the low thousands of dollars on a frontier model and the low hundreds on a cheaper one.²⁵ The BIS draws the asymmetry out plainly: a defender has to hold every system continuously while an attacker needs one route in, so cutting the cost on both sides still moves the balance towards offence.²⁶ Almost every case in Anthropic's September report ran on its general-purpose Haiku, Sonnet and Opus models, with a single case touching the restricted Mythos-class systems, which puts the field a tier below the benchmark frontier.²⁷ What has narrowed is the capability gap between an elite state team and an ordinary criminal one, because both now utilise the same capability by the token.

The measurable effect of frontier models so far sits on the defensive side of the ledger. Monthly security bug fixes in Firefox rose roughly sixfold after the Mythos Preview announcement, and catalogued flaws, published as Common Vulnerabilities and Exposures (CVEs) carrying a severity score out of ten, are now appearing at almost 20 a day at the critical level of nine or above, compared to 10 a day from 2022 to 2025.²⁸ The BIS is careful with its own series: published CVE counts also track the growing size of the software industry and the security research community, so the 2026 step-up cannot be pinned on model capability alone.²⁹

The programmes behind the jump are deliberate. Anthropic released Mythos Preview under Project Glasswing to 12 partners including Amazon, Apple, Cisco, CrowdStrike, Microsoft and Palo Alto Networks alongside roughly 40 further organisations, reporting thousands of high-severity flaws in weeks, some more than a decade old.³⁰ OpenAI followed in June 2026 with Patch the Planet, founded with Trail of Bits and covering more than 30 open-source projects including cURL, Python and the Go project. Its Codex Security tool has scanned over 30 million commits across 30,000 codebases, and one flaw it surfaced in the Squid web proxy had been present for 29 years.³¹ Access to these tools is itself a policy variable: U.S. export controls suspended access to Mythos and its safeguarded form on 12 June 2026, with the controls lifted on 30 June and access restored the following day.³²
Institutions have converged on the same operational read. The Five Eyes agencies asked organisations to limit unnecessary external connectivity, retire unsupported systems, review access permissions and prioritise the installation of fixes against a shortening window between discovery and exploitation.³³ ENISA's threat landscape, built on 4,875 curated EU incidents, already put vulnerability exploitation at 21% of cases before frontier models arrived.³⁴ The consequence for cybersecurity is that some attack stages that once took days can now be completed in just minutes.³⁵
Patching is the unglamorous work of installing a fix once one exists, and it is where the next budget line sits, because the gap is widest there. Half of breached organisations now run AI agents somewhere in security operations, but only 18% utilise them at vulnerability management, the job of finding and fixing flaws before anyone reaches them.³⁶ Mean time to identify and contain a breach ran to 247 days, six days longer than the year before, even as attack timelines compressed from weeks to hours.³⁷ As a consequence, organisations are now recommended to allocate agents to vulnerability management precisely because frontier models have made it a soft target.³⁸
Cybersecurity spending can be viewed across four principal layers, each of which captures value differently.
1. Identity answers a simple question: who or what is allowed to do this? This layer has evolved because software agents now need credentials of their own, called non-human identities, which tend to carry high privileges while being hard to inventory.³⁹ IBM found that fewer than half of organisations actively secure them, that only 40% control access to their own AI models and data, and that 92% of the firms suffering an AI-related breach had no proper access controls on their AI systems at all.⁴⁰ Identity vendors monetise through recurring platform, user or identity licences. Microsoft’s Agent 365, for example, is priced at $15 per user per month, although its management platform governs agents as well as users.⁴¹ That makes agent security an add-on sale into an existing workforce-identity base. Okta and SailPoint are pure-play examples while Palo Alto now markets CyberArk capabilities through Idira. Palo Alto says the identity security opportunity could reach $67 billion by 2030 and reported a ninefold increase in agentic traffic over nine months.⁴² Commercially, this puts access control near the front of the stack: vendors that control credentials can attach new controls before an alert reaches security operations.⁴³
2. Security operations are the people and systems that decide which alerts deserve action. Alert volumes have outgrown human triage, so the vendors are adding agents for first-pass investigation and response. CrowdStrike has launched Agentic MDR and an agent-building ecosystem with AWS, NVIDIA and OpenAI, while Microsoft processes more than 100 trillion security signals daily across 1.6 million customers.⁴⁴ Commercial models are adapting. CrowdStrike's Falcon Flex lets customers commit a pool of spend and draw it down across modules, a useful structure when demand by workload is hard to forecast.⁴⁵ Flex ARR exceeded $2.29 billion, up 101% year-on-year, and added 935 new accounts in the quarter.⁴⁶ Palo Alto's Cortex XSIAM reached $700 million of ARR, up 70%, across 1,000 customers. SentinelOne and Microsoft Defender competing for the same operations budget.⁴⁷ Scale supports the category; renewals, expansion and margin leverage will determine whether agent-led products become durable businesses.
3. AI application and data security is the newest layer. It sits between users, models and data, with gateways controlling which models and tools can be used, runtime controls inspecting prompts and outputs, and data controls limiting what models can see and expose. Zscaler and Netskope sell gateway controls, while Varonis and Qualys address data exposure.⁴⁸ This is mainly an attach product sold into an installed base, often priced by workload, traffic or usage instead of headcount. Despite the different model, AI application and data security has shown it can scale quickly. Palo Alto's Prisma AIRS passed $100 million of ARR within four quarters of general availability, making it the fastest-scaling product in the company's history.⁴⁹ The cost data supports the category’s growth: IBM prices a model inversion incident at $6.07 million and a prompt injection at $5.89 million, compared to $4.99 million for the average breach.⁵⁰

4. Recovery monetises the cost of downtime. The 2025 Jaguar Land Rover cybersecurity incident halted production for five weeks and disrupted more than 5,000 businesses in its supply chain. JLR initially reported £196 million of direct cyber costs and a revenue fall of nearly 25% to £4.9 billion.⁵¹ The broader UK economic impact was estimated at £1.9 billion, requiring a £1.5 billion government loan guarantee to hold the supply chain together.⁵² Prevention and recovery are separate purchases: even strong controls cannot eliminate restoration risk, so the ability to restore operations quickly is a separate purchase from the ability to prevent. Recovery vendors therefore price against protected workloads, data, or volume, instead of headcount. Rubrik reported subscription ARR of $1.66 billion in the quarter to 31 July 2026, up 33%, with management attributing the shift in customer urgency directly to Mythos and frontier models.⁵³
Gartner projects worldwide information security spending at $248.9 billion in 2026, up 12.7% in constant currency terms, and rising to $372.6 billion by 2030.⁵⁴ It projects the narrower market for securing AI systems to reach almost $4.8 billion in 2027, up 68.7%, and almost $7.7 billion by 2028.⁵⁵
Vendor results show where this spending is already appearing. CrowdStrike called Q2 FY27 its best quarter in company history, reporting record net new ARR of $332.8 million and revenue of $1.47 billion, and raising its full-year ARR guide to roughly $6.6 billion.⁵⁶ Palo Alto closed fiscal 2026 with revenue of $11.48 billion and next-generation security ARR of $9.10 billion, up 63%.⁵⁷ Its platform now includes the $25 billion CyberArk and $3.4 billion Chronosphere acquisitions, so the acquired businesses must sustain growth within it for the headline rate to reflect more than M&A.⁵⁸ Zscaler's fiscal 2026 ARR reached $3.77 billion, and the company disclosed that 90% of organisations in its frontier AI risk assessments had models or servers exposed to the internet.⁵⁹ Okta described a customer evaluation in which its tooling found 50 AI agents in the environment and 1,500 two weeks later.⁶⁰ All four are describing the same customer problem from different positions across the stack.

The rationale for cybersecurity spending has shifted alongside its scale. 85% of organisations that suffered a breach plan to raise security budgets in response to the frontier AI threat, compared with 64% after their own breach.⁶¹ More than half of these organisations now intend to buy AI security and governance tools specifically, an 88% increase on the prior year.⁶² For a sector whose purchases have historically followed the last disaster, this represents a potential change in the shape of the demand curve. The test will be conversion: agentic products remain immaterial to revenue at some of the newest vendors by their own accounts, so the deals closed in 2026 have to renew and expand through 2027 before the category counts as proven.⁶³

Pure-play vendors operate at each layer, but customers are increasingly buying several layers from one provider, a trend known as “platformisation” Palo Alto reports that platformised customers now generate more than 65% of next-generation security ARR at a net retention rate above 120%. It added roughly 220 net new platformisations in Q4 2026, up 44% year-on-year, and has a long-term target of more than 4,000 by fiscal 2030.⁶⁴ Its two largest quarterly wins, worth $126 million and $72 million, combined network security, security operations and identity.⁶⁵ CrowdStrike is pursuing a similar strategy from the endpoint outwards through Falcon Flex.⁶⁶ Platformisation concentrates budget among vendors that can sell across layers, while the specialists compete on depth. While the technical layers remain distinct, commercial agreements increasingly cut across them.
Two figures carry the cybersecurity theme. Gartner's path from $248.9 billion of information security spending in 2026 to $372.6 billion in 2030 sets the size of the budget.⁶⁷ IBM's $1.93 million average saving for organisations using AI extensively in security operations sets the reason it gets approved.⁶⁸ The asymmetry that the BIS identified, where a defender must hold everything and an attacker needs one way in, is what keeps both numbers moving.
AI is shortening the distance between a vulnerability and an intrusion. The question is whether security products can give that distance back to the customer. Renewal rates, expansion and the speed of recovery will provide insight as the theme evolves.
This document is not intended to be, or does not constitute, investment research as defined by the Financial Conduct Authority.