AI-pocalypse moment: 6 stocks that could gain from AI security fears
The AI trade just had an AI-pocalypse moment.
Over the weekend, Anthropic CEO Dario Amodei called for the industry to slow the pace of advances in frontier AI models to give safety measures more time to catch up. His concerns received support from other prominent AI leaders, including Sam Altman and Elon Musk.
Markets reacted quickly.
The Philadelphia Semiconductor Index fell more than 5% on Monday as investors questioned whether greater caution around AI development could eventually slow the enormous infrastructure spending boom.
But one corner of technology moved sharply in the opposite direction.
Zscaler jumped 16.5%, CrowdStrike 13.9%, Palo Alto Networks 13.1%, Okta 12% and Fortinet 9%. The First Trust Nasdaq Cybersecurity ETF gained around 6%.
The message from the market was interesting: if AI needs more guardrails, cybersecurity could become an increasingly important part of the AI value chain.
Why cybersecurity could be the next layer of the AI trade
The first phase of the AI boom was about building AI: chips, memory, data centres, networking and power.
The next challenge is using AI inside real businesses — safely.
There are two sides to the security problem. AI can make cyberattacks faster and cheaper by helping attackers automate phishing, find vulnerabilities and operate at greater scale. At the same time, businesses are giving AI agents access to emails, databases, applications and financial systems — and increasingly allowing them to take actions on their behalf.
That creates some very practical questions: Who is this AI agent? What should it be allowed to access? What data can it see? And how do you stop it if something goes wrong?
This is where cybersecurity becomes part of the AI infrastructure. Companies will need to verify identities, control access, protect networks and devices, secure sensitive data and monitor what AI agents are doing.
Importantly, this opportunity does not necessarily disappear if development of the most advanced AI models slows. Companies can continue deploying the AI that already exists, while greater caution could mean more testing, monitoring and security around it.
So rather than seeing cybersecurity as an alternative to the AI trade, investors may increasingly see it as an AI prerequisite.
And different cybersecurity companies solve different parts of that problem. Here are six to watch.
1. CrowdStrike: protecting the device
Think of CrowdStrike as the security guard sitting on your laptop, server or other device.
Its software watches what is happening on these devices and looks for unusual behaviour that could signal malware, ransomware or an attacker. CrowdStrike has since expanded beyond devices into cloud and identity security.
AI makes this more important in two ways. Attackers can use AI to move faster, while AI agents themselves can operate across company systems. CrowdStrike is building security that monitors what those agents are doing and can restrict them when something looks wrong.
Why it is different: CrowdStrike's strength starts with the endpoint — the actual devices and systems where attacks often happen.
2. Palo Alto Networks: the all-in-one security platform
Palo Alto Networks is the broadest security platform on this list.
It started with network firewalls but has expanded into cloud security, security operations and AI security. That means a large company can use Palo Alto to protect several different parts of its technology infrastructure rather than buying separate products from many vendors. Its AI security offering, for example, includes controls over which generative-AI applications employees can use and how company data is protected.
This could matter as AI makes cybersecurity more complicated and companies look to simplify the number of security tools they use.
Why it is different: Palo Alto is less a specialist and more a bet on companies consolidating cybersecurity spending with a few large platforms.
3. Zscaler: deciding what you can access
Zscaler solves a different problem: just because you are inside a company's network doesn't mean you should be trusted.
Its “zero trust” approach checks who or what is requesting access before connecting them to an application. Instead of opening the door to the whole corporate network, it gives access only to what is needed.
That becomes particularly relevant with AI agents. A company might want an AI assistant to read certain documents, for example, without giving it access to payroll, customer information or every other corporate system. Zscaler is extending its platform specifically to control users, devices, workloads and AI agents in this way.
Why it is different: Zscaler is essentially the traffic controller deciding which users and AI agents can connect to which applications.
4. Okta: proving who — or what — you are
Okta focuses on identity.
Most people have already interacted with this type of technology. When an employer asks you to log in, verify your identity and use two-factor authentication before accessing an application, identity-security software is helping decide whether you really are who you claim to be.
AI creates a new challenge because companies may soon have thousands of AI agents acting on behalf of employees and applications. Those agents also need identities and rules determining what they are allowed to do.
Okta is extending identity management beyond humans to these non-human identities.
Why it is different: CrowdStrike asks whether the device is safe; Okta asks whether the person or AI agent should be trusted.
5. Fortinet: protecting the network
Fortinet's traditional strength is network security.
Its firewalls sit between corporate networks and the outside world, inspecting traffic and blocking threats. It also provides security for branches, data centres and cloud environments.
AI means more applications, devices and machines communicating with each other — and potentially more malicious traffic moving through those networks.
Fortinet therefore provides a more traditional cybersecurity exposure than some of the newer AI-security stories on this list.
Why it is different: Fortinet is primarily about protecting the roads that digital traffic travels on, rather than proving someone's identity or protecting an individual device.
6. Cloudflare: protecting the internet-facing application
Cloudflare sits between websites and applications and the wider internet.
If a business has an app that customers use online, Cloudflare can help keep it available, speed it up and protect it from attacks.
AI adds another layer. Companies are increasingly connecting applications to AI models and allowing AI agents to interact with other software. Cloudflare is building tools to control those connections, prevent sensitive data from leaking into AI models and protect AI applications against attacks such as prompt injection.
Why it is different: Cloudflare is particularly exposed to securing the connections between internet applications, AI models and AI agents.
The simplest way to think about the six
They are not all solving the same cybersecurity problem.
CrowdStrike protects the device. Okta verifies the identity. Zscaler controls access. Fortinet protects the network. Cloudflare protects internet-facing applications and AI traffic. Palo Alto tries to bring many of those security functions together on one platform.
That distinction matters for investors. AI could expand the cybersecurity market, but it does not necessarily mean every cybersecurity company benefits equally.
The question is which security problems become more important as AI moves from something employees occasionally use to something that can access company data and take actions on their behalf.
Risks: the market may have moved too quickly
The biggest risk is that investors have already priced in much of the opportunity.
Several cybersecurity stocks jumped more than 10% in a single session, and some have already delivered substantial gains this year. Parts of the rally were already reversing the following day.
More AI risk also does not automatically mean more cybersecurity revenue. Companies could consolidate vendors, AI-security features could become bundled into existing products, or enterprise AI deployments could slow enough to delay new security spending.
Higher bond yields are another risk for richly valued growth stocks.
Ultimately, the thesis needs to show up in the numbers.
If AI adoption continues to grow but cybersecurity revenue, recurring contracts and earnings estimates do not accelerate with it, the investment case becomes much harder to justify.
What investors should watch next
The AI-pocalypse may have given cybersecurity its moment in the spotlight.
But the next phase will be decided by earnings rather than headlines.
Watch whether AI security starts generating measurable recurring revenue, whether customers consolidate more spending onto the largest platforms and whether earnings estimates begin moving higher.
The AI boom has already created enormous demand for the infrastructure needed to build AI.
The next opportunity could be in the companies helping businesses use it safely.