1. Brand vs Product
Harry Stebbings
Nikesh, last time we did a show, I was 22 hours into a 24-hour fast. I listen back now and think, my word, you had the audacity to be with one of the OGs of this business and be hangry. I was hangry with you and short-tempered.
Nikesh Arora
Well, the good news is, as I told you earlier in our chat, I have total memory loss. I have no recollection of what I said or what we talked about, so I have to go back and listen to it. I'm just happy to be here.
Harry Stebbings
It was a great show. We got on blissfully well. It was wonderful. I don't know what that was about.
Nikesh Arora
I think we should stop doing podcasts remotely.
Harry Stebbings
Oh God, I agree.
Nikesh Arora
Force people to come in here on a regular basis.
Harry Stebbings
I actually do, and the nice thing is, they do. But the only challenge is, they sometimes come quite jet-lagged because they come at 4:00 in the day, and that's a little bit tough.
Nikesh Arora
Then maybe you should do it at 11:00 p.m.
Harry Stebbings
Maybe.
Nikesh Arora
Yeah. If you get people from California, it's a perfectly nice time for them, at 10:00 p.m. or 9:00 p.m. Maybe you need to—
Harry Stebbings
And maybe I need to adjust. Yeah, I'm the selfish one. I was saying Marc Andreessen said that's on me. Marc Andreessen said I should really actually embrace it. We haven't even got to the first question, but fuck it. He said, "You need to embrace, 'How is it all your fault?'" If you embrace everything in life with, "How is it my fault?" actually, a lot of the world changes.
Nikesh Arora
Actually, let's spin that a bit. How do I make it better? Just change the outlook. It's, "How do I make it better? What can I do to make this better?" That's how I run my day and my life and my company. How can I make it incrementally better today, and how can I make it radically better in 3 years?
Harry Stebbings
Have you ever had something that you couldn't make better?
Nikesh Arora
Not for lack of trying. All we can do is try. If it works out, it's great. And if you try a lot, you succeed more often than you think.
Harry Stebbings
We were talking downstairs about your personal brand and about making it better.
Nikesh Arora
I don't think about it like you do because this is what you do for a living. I think about running my business.
Harry Stebbings
Okay, so I think this is fundamentally wrong.
Nikesh Arora
I'm here to learn. Teach me, Harry. I'm here to learn. Teach me.
Harry Stebbings
No, but I actually think your personal brand is your business.
Nikesh Arora
I think if you build a great product and a great company, people like your product, and eventually your brand survives all of it. I think you can have a great brand, a shitty product, and shitty execution, and your brand goes to hell in a handbasket. So I flip it around.
Harry Stebbings
Do you think that is still the case today, though? I think brand can be such an accelerant today, especially in a world where it's just so noisy.
Nikesh Arora
See, I spent many years at Google, as you know. I was actually chief marketing officer for 5 years. If you look historically in technology, there are companies that have died but had great brands. Remember Sun Microsystems? It was a darling, you know, 30 years ago. It doesn't exist. Why? Because their brand went dead or the product went to hell.
What about Yahoo? Remember that company? It's a great brand. Amazing. It was way before Google. I think it's probably a fraction, probably even a 2-decimal-point number compared with what Google is. So I think product helps make brands.
Harry Stebbings
But I think those were founded and broke into the public discourse when there was much less noise. So I think if you were to put that today, you need to have a brand first to get into the public discourse.
Nikesh Arora
Look, let me speak against my own thesis. There's a spectrum, okay? On one end of the spectrum, you only have a real differentiated product, in which case the product helps build a brand. Google Search is now something you will Google, right?
On the other hand, it's a commodity. It's water. No one knows why this is called Evian, right? But this is a commodity. Here, only the brand matters. So it depends where you are on the spectrum.
If all you are is a commoditized product, yes, brand matters a lot. If you are a differentiated product, then you build a brand on the back of the differentiated product. And you can decide where you want to be on that spectrum.
Harry Stebbings
Well, speaking of that brand, I saw your tweet, and I was like, this is masterful. You tweeted, "Broken up, the frontier model problem is a breadth versus depth problem."
Nikesh Arora
Yeah, look, I've been really listening to some of your podcasts and paying attention to what happens to the market because I want to understand where all this settles down—not just because I want to understand it, but because it also impacts how I build my own business, right?
So you've got these phenomenal frontier models, and they keep leapfrogging each other. Every few days, there's a net-new model delivered by OpenAI, Google, or our friends at Anthropic. The question becomes: okay, fine, these models are moving in this space; what do I need to build? What do I need to do with these models?
Then, as we came to that DeepSeek moment, when everybody was busy chasing DeepSeek, you realize even the best model has a high false-positive rate. But for some reason, in the consumer space, we don't seem to care.
I was talking to my sister this morning. She said, "I just went to ChatGPT and asked all these questions. It was very helpful." So I guess what happens is consumers are way more tolerant of false positives because there's always a person in the middle, right?
There's always somebody who's understanding what the model says and making their own judgment about whether they believe the model or not, and somehow people get rid of some false positives. Somehow, people don't care about the false positives. Sometimes people believe the false positive. So the consumer is highly tolerant of this notion of false positives and doesn't seem to distinguish; it just seems to get better and better.
I literally had Gemini produce an investment memorandum for something I was looking at. I looked at it, and it looked pretty accurate. Give or take, I'd tweak a few things, but it seemed passable. So on the consumer side, it's a breadth issue, right? It wrote an investment memorandum for me, which is cool.
I would have had to hire a banker and a bunch of investment analysts. It would have taken me days, and I did it in 4 minutes. So the breadth is there, which means it's my go-to place.
As you know, in consumer, if you become the go-to brand, talking about brands, it's hugely beneficial, right? Whether it's YouTube—that's the only place to go look for streaming video—or Google—that's the only place to go do a search—it becomes hugely multiplicative from a distribution perspective.
So our frontier-model friends are chasing the consumer brand, and the false positive doesn't matter. On the enterprise side, false positives matter a lot. They matter because, if you imagine a future where an agent's going to make independent decisions and act on them, you have zero tolerance for false positives.
Now, take Waymo. In my view, Waymo is the biggest agentic product out there because, guess what? You've replaced a human being called a driver, right? All decisions are made by AI and machine learning. It decides when to turn, when to stop, and what to do.
But think about the amount of edge-case training it took to replace that human agent with effectively an AI-driven agent. I don't know—tens of billions of dollars. So that's what it takes to take 1 use case and train the hell out of it.
If you think about what happened there, they could have used the equivalent of an AI model, but then they built so much context and intelligence and edge-case training and proprietary data to make that happen. That data is not available on the internet.
You can't stick the next model of Anthropic into your Mercedes and say, "Okay, drive me home." It's not going to be able to do it. And that's the depth issue, right? You need the depth of the context, understanding, and intelligence around the model to make it useful for the truly agentic use case.
So I just think there's this constant tension. The frontier models want the consumer attention because that drives post-training for models and drives the consumer brand of the model. On the other hand, the real enterprise revenue is going to come from use cases that require a lot more context.
The 1 standout use case we all know is coding, right? Coding is a universal activity. Everybody does it, so everybody's data is helpful in training the model, and that becomes a large enterprise application. Hopefully, there's a few more out there. But I think that's the tension that I wrote about.
Harry Stebbings
When you think about the workflows and the way enterprises are engaging with AI, specifically models, to what extent do you think we will be locked in a frontier-model-dominant world, versus having a majority of enterprise workflows done with open source, and being more cost-efficient moving toward that most of the time?
2. Enterprises Are Still Getting AI Wrong
Nikesh Arora
I think more than half the enterprises are still not getting it right from the perspective of using AI.
I think we're still busy trying to incorporate AI into our current business practices. How do I take what I do today, use a little bit of AI, and get marginally more efficient because I don't want to do this the old way? I think the opportunity is to fundamentally rethink your workflow with AI.
That's where the true benefit is going to come. I think the winners in the long term will be people who actually rethink their companies with AI, not people who adapt their current workflows marginally with AI.
Harry Stebbings
How can you do that if you're an enterprise? I assume we have thousands of CEOs of big enterprises who listen. That sounds great. What do I do? Do I do a brainstorming session?
Nikesh Arora
No, I think there are perhaps 2 or 3 different categories. One category is: let's take the workflows of today. We have workflows around ERP, sales team management, and human resource management. There are existing workflows which have been SaaS-ified, as in some software company decided we all have common processes. Let me build a container where these common processes can be marginally customized by the enterprise. They can code their workflow into my SaaS application, and we're off to the races.
That workflow required a lot of human judgment and human interaction. The software is not intelligent. It's been coded, right? You define the input, you define the output. I do the input, and I know what output I'm going to get.
The idea is to imagine workflows where, in the hiring process, most of your workflows are containers. Imagine AI actually helping you make judgments. You say, “Put every CV into AI and say, ‘These are the 20 people you should interview.’” Then, “Look at the CV. You should ask this person the following questions. Send a note to Harry saying, ‘Interview this person. Ask the following 10 questions,’ because your 3 other colleagues only asked the following 5.” We need no false positives to human beings.
AI could be hugely helpful in informing and making the process more intelligent. But that requires us to give up human control and let AI do 80% of the thinking for us. That's not how we're doing it right now. All we're doing is taking this invoice, scanning it, extracting the data, putting it into AI, and saying, “Look at that, it's happening 20% faster.”
Harry Stebbings
Do you think we are willing to give up that human control? You see cases like that today, where I think 1,700 people signed a petition saying they were unwilling to let it track their mouse and keystroke behavior. We are seeing resistance to giving the data.
Nikesh Arora
I would argue they're different points. I think they're 2 different points. Mass collection of data to inform AI is a little dangerous because people see the outcome of what's going to happen, right? I've heard of companies where people are using cameras to track people folding laundry and ironing clothes because they want to be able to train physical AI in the future to do those things.
That part aside, I think on the enterprise side, we can actually run a business much more effectively and efficiently if we decide where we are willing to relinquish control to AI. Take marketing, for example. Anything that is required to train a marketing model is already out in the public domain. By definition, marketing is public domain, right? If you didn't market it, it's not in the public domain.
So, I have the best training data in marketing. I don't need to train an AI model with more marketing content. I may need to train it for tone of voice and what my brand is. I'm pretty sure an AI model, if I throw my marketing collateral into it, will tell me, “This is not consistent with your brand.”
If I look at all the things you've been talking about over the last 10 years, I think some people have done that. They've actually analyzed earnings scripts of companies and said, “Over the last 20 years, what has company X done? And when does the CEO start getting away from a topic because perhaps it's not going so well?”
So, this is really smart. They can do that stuff. It's the best marketing training database in the world—the frontier models. Why do I need 400 or 600 people in marketing? My biggest problem in marketing is that I have 600 people, but I'm not sure they all fully understand how to consistently deliver my tone of voice and my value proposition, or how not to break my brand by having different collateral in the public domain.
Harry Stebbings
You have 600 people in marketing? You have, I take it, 21,000 people?
Nikesh Arora
Well, it's not going to be 600.
Harry Stebbings
No, what is it going to be?
Nikesh Arora
I don't know. My rule of thumb is that in the next 3 years we'll probably have half the people in G&A-type activities in companies—things like marketing, finance, and HR—because there's a lot of process management there. A lot of process management can be made more intelligent using some version of an adapted future AI application, for lack of a better word.
So, SaaS applications will give way to AI applications. The difference is that SaaS applications have no opinion. AI applications will have opinions. That's a fundamental rethink we need from a workflow perspective.
Harry Stebbings
Can you just help me out? AI applications will have opinions. What does that mean in terms of how you use them and the output that they have?
Nikesh Arora
Everything, right? Your agent, whatever you want to call it—the AI assistant, the AI marketing assistant, the AI HR assistant—is going to say, “I looked at your copy. It sucks. It's not good enough. It's not consistent with your tone of voice. Here's what I would recommend.” That has an opinion.
That will make my average employee much smarter than they are today. Then I don't need so many of them, because they're doing most of the work for you.
Harry Stebbings
What would you say to the people who say, “You're wrong. We won't see that halving of those functions, and actually marketing teams will create more copy, more content, and be in more places”?
3. AI Guardrails Aren't Robust Enough
Nikesh Arora
I think the place where people could be wrong is how many technical resources we need in the future. I think we need more, not less. There's this fallacy that people believe we're going to have fewer people working because AI is going to take over our jobs. I don't believe that.
I think what's going to happen is that you can't imagine the number of people on my team who want more technical resources and more AI-savvy resources because they want to do exactly these things. They're saying, “Well, I've got an amazing project to transform marketing. I've got an amazing project to transform HR.” What do you need? “Well, I need more people who understand how to prompt frontier models, build harnesses, bring proprietary data into play, bring models into play. I need more compute and more storage because I want to learn everything.”
So, I think we're going to need more technical resources. I think we're going to need more sales resources, because if your product's really good, you need more people to go out there and cover the universe because not enough people know about it.
I'm in Europe. I met 20 customers last week, and I still see half of them don't know all the stuff we have. I'm like, “Dude, we've been around for 20 years. Why is my team not out there pounding the pavement, telling them everything we do?”
The problem is that there's not enough time in a day because I'm too busy dealing with some arcane piece of software at work that I have to go feed. If that software were really intelligent, it would tell me what to do.
Harry Stebbings
In terms of wanting more technical resources, tokens I would put in the more technical-resources camp. How do you think about effective token-allocation strategy? You're seeing very different camps, from your Metas, Ubers, and Microsofts that put in budgets to your free-for-all, be-creative approach. How do you approach it?
Nikesh Arora
Look, I know this whole world of token-maxing has gone topsy-turvy with the whole conversation that I'm having about the tokens people are using. The challenge right now is that 90% of enterprise employees are not AI-savvy. They're not. They have to learn. I can't send them to university. There's no course you can take at any school anywhere. They have to be able to learn on their own.
I think we're back to a Darwinian moment where everybody has to figure out who's really good. Now, you've seen people like Brian Armstrong and Jack Dorsey go out and say, “I'm going to decimate my organization, and I'm going to start building from scratch.” They're going to some version of 30% or 40% of the people because they figured out there's no redemption. I can't train these people. I'm just going to find the people who are going to come in and help me do this stuff.
That's one model. The other model is gradual. We've been hiring people only through hackathons now, right? We see natural attrition of 2%, give or take, a month, and we just replace those people with people who are actually AI-savvy and come from hackathons. Give me 12 months, and I'll have transformed 20% or 25% of my team. Give me 3 years, and I'll hopefully have enough AI-savvy people working at Palo Alto Networks.
So, there are 2 different ways to get there. I think part of what you're seeing in the token-maxing world is that people are learning and experimenting. The risk is that your smartest employee, who knows how to use AI really well, could be using 20 times the tokens that an average employee uses.
If you get into this whack-a-mole moment of saying, “Oh my God, I'm going to stop people from spending too many tokens,” you will actually hurt the best AI-savvy people more than you hurt the average employee.
Harry Stebbings
And by the way, I think the best talent will want to go where they will be best equipped with the most expensive frontier models and the biggest budgets. I think that will almost be like an employee benefit.
Nikesh Arora
Yes, possibly, but I think part of the challenge is that right now everybody's experimenting on everything.
And you have to figure out what it is that I need to build as an enterprise and what can I get off the shelf? Right? If I can get an AI-based thinking application that does marketing for me, I don't need to build it. It's a generic problem everyone needs to solve. I can tweak it, I can customize it, just the way I did with SaaS applications, but I don't need to build mine from scratch.
So, I've made sure that everything my team is building is proprietary to us. This is where we have unique, distinguished knowledge that we bring to bear, which nobody else can do on the outside. Let's put that, let's package it, let's use it. Where it's going to be a generic AI application 12 months or 24 months from now, let's just wait.
Harry Stebbings
So, you have a free-for-all on tokens to allow your teams to do their best.
Nikesh Arora
We have a “use judiciously” model for tokens.
Harry Stebbings
It's not a free-for-all.
Nikesh Arora
“Free-for-all” sounds like you can go token-max the hell out of it. We have “use it judiciously,” and we keep track of it to see what people are doing. If we find somebody who's using it well, we won't constrain them. If we find somebody who's gone a little over the top, we'll find a way to cap it.
Harry Stebbings
Yeah, Marc Benioff said the other day that he spends $300 million on Anthropic a year for his developers, and that works out to be about 3.8% of average developer salary spend. If it stays there, the valuations of Anthropic and OpenAI are grossly overvalued. And if it moves to 20%, they're actually very undervalued. And if it becomes what Brandon at Macquarie said, which is, “We'll spend as much on tokens as we do on salaries,” they're grossly undervalued—grossly undervalued. I want to talk about where you think the percentage of developer salary spent on tokens will be in 3 years.
Nikesh Arora
That's still a narrow lens for me. If I step back today, very abstractly, there's not enough compute for what the world is demanding. Unequivocally, not enough compute. Right? You can't buy compute. Compute is costing 2 to 3x or 4x more than it used to cost 2 years ago. There's not enough compute.
That scarcity of compute and that excess cost required to build and deliver compute, which allows us to go make AI useful, is causing the constraint and forcing pricing. Right? Interestingly, I think more than half of the compute is going to feed the consumer, which is a fundamentally loss-making entity right now. I don't think any of the frontier models make any money trying to get you and me to use ChatGPT or Claude or Gemini every day. It's free. That's a lot of compute. Imagine there are billions of people around the world using it for all kinds of queries every day. That's sucking away half the compute, which is making no return. Guess where the pressure goes? The pressure goes on the other half of compute, which is being used for coding in enterprise applications.
4. If Nikesh Started Palo Alto Today: The Waymo vs Tesla Approach
So now you're saying enterprise applications and coding have to pay until we build transaction models or advertising models on the consumer side, because they're not ready. Now, you could say, well, that happened in search, too, right? Google Search was around. That happened to YouTube. People used a lot of YouTube, a lot of compute, but it wasn't paying for itself. The problem is the compute requirements and the cost are now 10x what they were in that era. So that's forcing token prices to go up.
I think the long-term token pricing should be 1/10 of what it is today. When that happens, you'll see that people will consume more. You can decide whether it's 3.8% or 15.8%. I'm not sure we can tell the answer right now, because pricing will move very drastically in the next 3 to 5 years. I think at some point in time—
Harry Stebbings
Sorry, so in time, you think we'll see dramatic reductions in token prices?
Nikesh Arora
I think so. I think in the next 3 to 5 years we'll see a reduction in token pricing. I think at some point in time, consumer use of AI will get constrained by these frontier AI companies because they have enough post-training data—more than they need—and each user is inherently unprofitable in the activities they do in frontier AI models.
Harry Stebbings
Do you not think they just build advertising engines, like OpenAI is doing now, to pay for that business?
Nikesh Arora
That's an interesting question. It has to come from somewhere. When I started Google in 2004, we were 2% of global advertising revenue, and global advertising revenue was estimated between $500 billion and $600 billion. I think online is about 70%, by last count, of total advertising revenue. And I don't think the overall number has changed by more than 3% a year or 5% a year. So, I don't think the total advertising pie is going to increase. You've already taken away 60% to 70% of the advertising pie in the online world.
Unless you tell me there's going to be an explosion at the top, where more people are going to spend more money in marketing, that money that you're hoping to fund consumer AI from advertising will have to come from current advertising revenues. So, I don't think that changes the equation drastically to make the consumer profitable. I do think there's an opportunity that AI ends up taking more transaction revenue, which has not been in the purview of AI.
5. The Breadth vs Depth Problem With Frontier AI Models
Harry Stebbings
Can you explain that to me?
Nikesh Arora
Well, think about the marketing chain, right? We do advertising. Advertising is inherently efficient. What's the best conversion rate you get in online advertising, you think?
Harry Stebbings
1% to 1.5%.
Nikesh Arora
That's fine. The best of breed is 7% to 10%.
Harry Stebbings
Wow.
Nikesh Arora
Sometimes, but the average is probably 1.5% to 2%, which means 85% to 90% of marketing is wasted, right? So now, if you get really smart, you have memory, you have context, and you get smarter in targeting Harry when he's trying to buy something out there in the world, then your conversion rate goes up, right?
If you look at the entire value from the time you decide to buy something till the end—you get the product—you know, take the case of consumer goods. Today, I want to say the cost of consumer goods is probably 5% to 8% of total list price. The 92% is distribution and marketing. It's highly inefficient. So you could imagine a world where AI makes marketing really efficient, and you get more dollars coming from traditional marketing into the online world because it's coming in the form of transaction.
Harry Stebbings
If tokens get cheaper—
Nikesh Arora
Yes.
Harry Stebbings
Why are we not seeing frontier models get cheaper? We all thought that this would be cheaper.
Nikesh Arora
Well, right now they're figuring out that all your frontier model companies are value-maxing, not token-maxing. There is no money at $1 trillion. At some point in time, they realize, “Oh my God, where's the next $100 billion of compute going to come from? The financial markets are not going to bear the cost of another $100 billion at $1 trillion or $1.5 trillion, because I'm going to need it again the following year.”
So they say, “Well, I've got to build a sustainable business model and start showing some degree of gross-margin profitability.” The only lever they have is to take the fastest-growing thing that they have in their portfolio from an economic perspective and charge us more for it. That's where you get the price of tokens from. I think the price of tokens is high.
Now, you can imagine, if the price of tokens is high, every technology company is trying to figure out, “How do I make my compute more efficient in the future?” So I'm sure we'll see a whole bunch of advances in the world where memory and compute are going to start getting used more efficiently from a modeling perspective. And I still believe I don't need Fable 5 or Mythos 5 to do 90% of what people do with the AI today. Why is the last model not good enough for certain tasks?
Harry Stebbings
I think I'm wavering here, as I think the models are overkill in terms of capabilities, especially for consumer and most enterprise demand. But the models from 2 years ago were good enough for most of the queries that we asked.
Nikesh Arora
Right. That's right. The problem is they were inefficient from a compute perspective.
Harry Stebbings
Totally.
Nikesh Arora
So you're seeing the efficiency come in. The problem is the cost of R&D is now being spent in terms of what the tokens have to pay for. So I think token prices come down. I think the amount of compute that we need is going to be huge over the next 10 years. I think the frontier AI models are in a position to capture a significant amount of the future economic value of the use of AI.
Harry Stebbings
Everyone is fundamentally looking at the stack, and this is me being very open as a venture capitalist. That's why the shit's been successful. I'm just saying what every venture capitalist feels. We're all looking at it again: Oh, Jesus, I have no idea where value is accruing. You've essentially got infrastructure, which is kind of at the top, and then you've got models and apps, to be totally—
Nikesh Arora
Yes. Look, infrastructure's making money. Infrastructure's more expensive than it's ever been. That's why you're seeing trillion-dollar market caps in the infrastructure space: because of the scarcity of compute and the need for speed.
Harry Stebbings
Do you think we're in an infrastructure bubble, as people think or suggest?
Nikesh Arora
I have a question, which I don't know the answer to, and you can tell me, since you spend more time with people here. I have to go do my day job. At what point in time does physics kick in and we just can't produce the compute as fast as we want to?
While the infrastructure people are gearing up for large amounts of capacity and large amounts of demand on the infrastructure side, you come to a point that says, “You know what? There's only so many data centers we can build. There's only so much energy we have. There's only so many—”
Harry Stebbings
Shortages of copper. But you do the Panthalassa, which is building data centers at sea.
You've got Elon building them in space.
Nikesh Arora
So, I think there may be a digestion period at some point in time once we think the demand for compute is there, but the capacity to execute is now limited by physics and the infrastructure players have built up too much capacity for this demand. I don't know when that rationalizes. Maybe it rationalizes and causes us to think about a different sort of time frame for putting all this compute out.
That doesn't take away from the need for compute. We will still want as much compute as we can deliver, as fast as we can deliver it. I think some of the model companies have outstripped anybody else's ability to build frontier AI models at that capacity and at that speed, and to train them. I think you are seeing perhaps a settling down of who's going to be the frontier model player in the future.
The question becomes, in the economics, what value accrues to the model and what value accrues to the application layer, as you said. I think the application layer is probably a simplistic term because, for the first time, you have memory in applications. Applications understand context. They understand context specifically as to what you want and what I want.
You're seeing that in the consumer space. That has not yet come to the enterprise space, funnily enough. I think that shows up in the enterprise space, which means the demand for compute and memory goes up on the enterprise side. I haven't used all the coding models myself, but over time these coding models have to get really smart about understanding the individual context of enterprises and humans. That's how they'll be more effective and more efficient.
For that, we're going to still need more compute and more memory. So, I think that'll start defining where the value accrues. I think the value gets shared between frontier models and the context that gets created in enterprise play. I think the frontier models are fully understanding that this is where the gap is.
I suspect the frontier AI models, if I had a crystal ball, will spend a lot more time in the next year or two building memory around consumption.
Harry Stebbings
Building memory around consumption. What do you mean, like expanding context windows?
Nikesh Arora
More than that. If you look at the consumer interaction that you have with your favorite frontier model, it's starting to remember: “Oh, you asked about this yesterday. You asked about that.” Should I take the question you just asked me in the context of everything I know about you, or should I just limit the answer to as if I don't know anything about you?
Having context of what I said to you over the last 30 days, the last 60 days, or 90 days requires you to store a lot of information. It requires a lot of personalized interaction that needs to happen. If you want to maintain your moat with Harry and Nikesh in the future, the more context you have about me, the easier it becomes for you to give me the answers in the future. As you start building context in a user base, you create stickiness, and that becomes your moat.
Harry Stebbings
To what extent does Mythos cannibalize a business for you? To what extent does it make a business for you?
Nikesh Arora
Mythos, I think, ends up being an accelerant to cybersecurity.
Harry Stebbings
Yeah.
Nikesh Arora
I think what happened when you saw Mythos come out was that it demonstrated that all the training we've been giving these models on how great code is written, the models were able to turn around and say, “Well, I also know how to find bad code.” So, what happens is you point the gun the different way, and the model says, “Oh my God, look at all this code that you have. There are so many flaws in it.”
As we talked about, like every model, it also suffers from false positives. So, if you're an offensive actor and I point the model against, let's just say, 20,000 enterprises, and I go look at everything you've done, somebody's left a WebSocket open, somebody's messed up in IP addressing, et cetera. So, it finds the flaws from the outside in.
That allows a bad actor to figure out how they can daisy-chain vulnerabilities and get into your infrastructure. It's not good enough from a defensive perspective because I can't use the model and say, “Go take every vulnerability you found, build a patch, and go patch my system and protect me.” Because, well, guess what? It's going to patch 30% of things which are not wrong. Who knows what that's going to do to blow up your infrastructure?
So, when Mythos came, we looked at it, treated it with respect, ran it against our code, and discovered it finds bad stuff much faster than humans can. We found in 6 weeks what would have taken us 5 to 6 years. We got it. We ran around and patched it, but Claude Code helps build a patch, and you still have to run it through human evaluations, through testing, through production testing, and sandboxing: Does this patch break anything in the infrastructure?
Only then, after 6 weeks, were we able to go patch everything. Now, what does this mean? This means that every enterprise better fix their stuff faster, because if I point the next generation of models against your infrastructure, it's going to find security flaws, security vulnerabilities, misconfigurations, and things that you've not been paying attention to.
So, it creates a bit of urgency on the part of customers to improve their cybersecurity posture, which I think generally is a good thing for cybersecurity companies.
Harry Stebbings
Fundamentally bad. When we just summarize what you just said, it allows you to weaponize bad actors to find holes, but it isn't good enough to provide the solutions.
Nikesh Arora
Well, look, the solutions are there. The solutions are there. The challenge is sometimes getting the attention and focus of the customer, saying, “Listen, I've got to go fix my stuff because it's important.”
What this has done is lit a fire under the security practitioners around the world, saying, “This thing is not good. This is going to weaponize the bad actors. I better make sure my defenses are in place.”
Now, remember, the way cyber defense is done is that cybersecurity is fundamentally two things. One thing is, if it's bad and I'm at the gate, I'll stop it, which means you have to have somebody at the gate. Now, we have 150 million sensors in the world where we stand at the gate protecting our customers.
If I can find a way of infusing AI at the gate and taking all these vulnerabilities and finding a way to protect you, I'm good. I don't have to change the gatekeeper, because there's no 'cloud' endpoint agent that exists out there. There's no OpenAI endpoint agent that exists out there that I can replace Palo Alto or the other people in the space with.
The problem is not at the gate. What happens is, despite all the perimeter defense you put in, things come in. Things leak in. People make mistakes. People's passwords get breached. There are vulnerabilities people get in through.
Then the question becomes, “All right, the bad actor is in my infrastructure. How quickly can I find him and get rid of him or her?” That becomes an AI task. That becomes the same conversation we're having so far: I need context, I need intelligence, and I need to know what this means.
So, creating that context and intelligence within the enterprise of what this intrusion means and how to protect against it becomes a challenge. This is the AI cybersecurity challenge.
Again, this is not trying to pitch my book here, but we spent 5 years trying to build that capability inside enterprises. So, in the net-net, it ends up being an accelerant. Does that mean I have everything I need? Not everything. Does that mean I need to get AI models to start helping me? Yes. So, we're going to infuse more AI into our defense infrastructure.
6. Should Governments Intervene on AI? A Discovery Process
Harry Stebbings
Do you think it is good or bad to have government intervention when you have models as powerful as we have them?
Nikesh Arora
I think we're going through a discovery process. I think this notion of guardrails has not been built robustly enough because these models seem to be easy to get past.
Remember the early days, when you used to read about somebody having this conversation with a model and finding a way to obey the guardrails because they asked questions differently and the model was able to get sort of jailbroken? It became a hobby amongst people, and they had all kinds of conversations with models.
I think it's the same challenge. How do you make sure that you can put enough guardrails around the AI model that you built to make sure it's only used for the purpose that you had? That's the challenge.
I think the guardrail needs to get better. To the extent the government feels the guardrails aren't robust enough, it's trying to tell us that it's a national security issue. We need to go fix the guardrails. But I think it's a simple matter of trying to fix and treat the guardrails as a real problem and solve it.
Harry Stebbings
Is it possible?
Nikesh Arora
I'm hoping it is.
Harry Stebbings
I hope it is, too. If you were starting this—I suppose he's one of the world's best cyber investors, so we might name him because he asked some spicy questions of you.
Nikesh Arora
Oh, okay. He's got questions for me?
Harry Stebbings
Yeah, he asked questions of you. He asked some interesting ones. But he asked, if you were to start Palo Alto Networks, a cyber company, again today—starting today, in the age of AI—what would you do differently that you're not doing now?
Nikesh Arora
The paranoia I have, if I look at self-driving, is that there are broadly 2 or 3 approaches out there, right? One was, my car is not going to have a human in it. It's called Waymo, right? I'm going to keep bombarding it, training it, until it learns by itself to drive, and no human is still behind the wheel when my customers are in it, right? You see, it's out there.
There are many cities that have Waymos. I saw one down the street from here. That’s one way of doing product development: every edge case gets discovered, you build training around it, every experience is a learning experience, and you keep training it to get to a point of total autonomy.
The other version is, I’m going to start taking segments of the driving and automating the segments where I get really comfortable. My car drives 50% of the time; the other 50%, the human gets in on the edge cases. That’s my Tesla, right? Tesla used to drive just on the highway for me, and now it’s getting better on other streets. It’s slowly getting better, but I’m still holding the steering wheel very often. It’ll tell me, “You’re not paying attention. Look at the camera, otherwise you can’t drive.”
I know FSD gets better, but that’s another way to get there. I’m going to keep training and fix this. I’m going to start working on the edge cases as my business continues to evolve. The third one is, I’ll infuse some degree of self-driving into my car because I’ve come from the traditional model of having amazing cars, great V8 engines, beautiful, sleek cars, and I’m not into the technology aspect. You see them out there on the street; they have all 3 versions out there.
My fear is, do we all need to stop and start thinking the Waymo way as enterprises, or is there room for the Tesla approach to self-driving in our businesses? We have an existing set of customers to satisfy who are not going to take kindly to me saying, “Guess what? I changed my product. It’s right 80% of the time, and I’m going to take another 3 years to train the product to be right 100% of the time.”
My fear is, am I pivoting fast enough in my product strategy that, over time, my products become more self-driving than they are today, or do I need to go faster? Can I get there by automating or AI-enabling certain parts of my product where I can apply the models that are capable of doing certain aspects of cybersecurity today and keep doing the others through machine learning, managing use cases and edge cases through machine learning? Or is it time for me to pivot? My view right now is, you have to have the Tesla approach if you’re an enterprise building AI-infused capability. But you can’t have the approach of traditional car manufacturers, which are trying to stick a little bit of AI in and AI-wash their cars, saying, “I’ll get there eventually.”
Harry Stebbings
Would you like to do the Brian Armstrong, Jack Dorsey? I often think a good question is: what would you like to do but you’re held back from doing?
Nikesh Arora
Different courses for different horses, right? I don’t think in our business we can go implode the organization because I don’t think the underlying application software is there. I don’t think all the things that we’ve talked about that we need to get done are ready from an AI software perspective.
I don’t want to build a lot of software that is proprietary to me for things that should be available for everyone. I don’t want to build an AI marketing stack. I don’t want to build an AI HR stack. I don’t want to build an AI ERP stack. I’m hoping that somebody goes and does that much more effectively and efficiently for the world at large. Perhaps it’s the next iteration of Salesforce, the next iteration of SAP, or the next iteration of Workday that is going to help me do that, because I do believe it needs to become more intelligent. We talked about how it needs to be more AI-enabled or AI-controlled.
I do want to build things that are particular to me, where I have all the information, all the intelligence, the context, and the memory from an organizational perspective. I think the right way to get there is to hold people accountable. I run a meeting twice a week now called AI E-I-E-I-O. It’s kind of funny. It’s like “Old MacDonald Had a Farm”—E-I-E-I-O—because everybody in my company wants to do AI.
I use it as a convening function, as a function to brainstorm across my team. How do we think about this? Why are we building this?
Harry Stebbings
What happens in that meeting?
Nikesh Arora
Everybody comes and shares how they’re adapting to the new world of AI. What are they doing from a product-development perspective? How are they thinking about it? How are they including agents in their products? How are they going to build the back-end infrastructure? How do we think about how they’re using tokens? How do we think about the capability of resources?
Remember, for me to transform a 21,000-person organization, I have to get the hearts and minds of the leaders to make sure we’re all swimming in the same direction, or pulling in the same direction. This is my way of ensuring the top 15 or 20 technical leaders in my company are pulling in the same direction, whatever that direction may be.
As you know, if there’s no expert, then a group of smart people does better than an expert. I don’t think there’s an expert for future enterprise design yet in terms of, “Here is the blueprint.” As you said, as a VC, you’re saying, “Holy shit, where’s the value going to accrue? Is it going to be in models? Is it going to be in the application layer?” Trust me, we have to have a point of view on that stuff and what’s going to emerge in the future before I can start transforming my company. How should I build my products?
Harry Stebbings
Are your leaders AI-built? I interview CROs as well, some of the best CROs and some of the best CPOs. In all honesty, the bigger the company, the less AI-built and AI-mature they are. To give the example of one the other day, a public company doing $5 billion-plus in revenue: the CRO goes, “You know, we don’t have that AI talent internally, but we’ll bring it in.”
Nikesh Arora
Yeah, look, I discovered this in 2004 when I was in Europe, around Google Europe. I used to go around and meet CEOs. There was this fad where CEOs would hire this 24-year-old sherpa. They were called the web sherpas or internet sherpas, right? It was like a chief internet officer. Remember those companies had chief internet officers at one point in time?
Harry Stebbings
I was 8, so no.
Nikesh Arora
You were 8; you don’t remember. Well, we’ve seen this movie before, and sometimes it’s fine to have seen this movie before. The task of the chief internet officer was to make sure the organization was ready for the internet, because, “I’m too busy in my traditional business, and I don’t know who Amazon is. I don’t know who Google is. So this wonderful 24-year-old who understands this stuff is going to help be my savior.”
Then CEOs would wash their hands of the internet because they had this wonderful team of people who would get frustrated because they couldn’t get anything done; nobody was giving them attention. The risk of that happening is true with AI as well. I’m so busy doing what I did yesterday, I have no time to think about tomorrow. So, meet my chief AI officer, who was probably a researcher at some amazing university before and has low execution skills.
Until I can get my leadership to understand and agree on the extent of the AI challenge and the AI opportunity, we’re not going to make progress.
Harry Stebbings
What specifically are you not focusing on today because of the burdens of today’s problems?
Nikesh Arora
Everything. When you go talk to a product manager in any large company, I’m pretty sure they have a product roadmap that exists in their heart and in their hands. It’s just 6 months or 12 months long: “I’ve got to fix all these things.”
What’s interesting is, in the 6- to 12-month plan, there’s nothing called agents in there. How come the world is talking about agentifying everything and your product roadmap doesn’t have that? “I’ll get to it once I get this done, because this is what customers want right now.” I’m like, no, that doesn’t work.
How do I get you to do more agentic work? How many people are you going to free up by doing development the way you’re doing it today, so I can use that excess resource to go make new things happen? Those are all important conversations. I can have them one at a time across 14 or 20 people, or I can have them twice a week with them and have people demonstrate what they’re doing.
What’s fascinating is, you have to make sure your leaders are ambitious. You have to make sure they’re competitive. You have to make sure they want to win. You have to make sure they have a learning mindset. When they watch their peers around them do cool shit, they want to show up with cool shit the next time.
For me, it’s getting 14 people together and saying, “Hey, Harry, tell me today: what have you done for AI in the last 3 days since I last talked to you in the organization?” Whatever motivates you—whether it’s the fear of Nikesh asking you in 3 days again what you did, your inherent learning ambition, or your team pushing you—you will show up with something.
Then you’ll see what the other guys are doing. You’ll say, “Oh my God, I’m doing a lot,” or, “I’m not doing enough.” It creates a little bit of Darwinian competition amongst them. It creates this urge to go embrace this new technology, and I think hopefully I get 14 people fully motivated. Then they go to the next set of people, because I need to transform from the top down, not from the bottom up, on this topic.
There’s bottom-up experimentation, of course. People using tokens to see who’s really good at that allows me to find the best talent. So you’ve got to find a way of transforming 20,000 people over the next 2 years in that direction.
Harry Stebbings
Bottoms up, top down—you’ve got to get into these organizations. That sounds normal. I wish I was a VC. I could have said that on the podcast and talked about stuff. Clearly, I need to get out more. I just sit in this dark room all day in a cave.
I’m sorry. Okay. The question is, how do you get in effectively, and how do you get implementation and adoption done well? I’ve had guests on the show say before, “You cannot do enterprise adoption without FTEs today.” And then I’ve had Matan come on the show, our friend from Factory, and say, “If you need FDEs, you have a shit product.” Bold. And I love [likely Matan].
I think it was a great clip, so I’m grateful for the virality that came with that.
Nikesh Arora
Was that the one that went viral?
Harry Stebbings
That one did very well. Yeah, Shyam from Palantir then obviously chimed in. My job is to create a discussion. What is true and what is right? Do you have to have FTEs to sell into enterprise?
7. Agentic Security: Why You Need a Gateway for All Agent Traffic
Nikesh Arora
I think what’s true is that we’ve only been chasing the enterprise dream for AI for the last, what, 12 months at best. If you think about everything that happens on a weekly basis, we see new things come that we don’t quite fully understand and grasp, right? We’re all busy trying to get our arms around LLMs and how they’re going to be great for chatbots to talk to our customers in enterprise, and suddenly agents showed up.
It’s like, “Oh my God, I have to figure out agents. They’re going to start working internally. Agents are going to do a lot of stuff.” I’m pretty sure you can still have an Agent Fest and have everybody tell you what an agent is. You still have to walk out and say, “I’m not quite sure that his agent or her agent is the same as what the last guy said.”
Because AI is moving so fast, I don’t think the products are fully there yet. The enterprise products at the application layer don’t exist in their entirety because we haven’t tested them against the enterprise ask. FTE is a short form for saying, “My product’s not fully there because it’s evolving as the technology evolves. I’m going to send some people across who are going to sit in your office and build my product while I adapt to your needs.”
That’s what we saw from Palantir. That’s what we’re seeing from all these companies. What you’re saying is, “I’m going to send my product engineers or developers to your enterprise, and they’re going to build my product.” You get it if you do it right.
Again, FDEs are different versions. Some people are just trying to get you to consume AI, which is actually not an FDE; it’s just a technical sales consultant who’s trying to help adoption. On the other hand, an FDE truly is somebody who actually brings the code back from the customer side and goes back to your product and says, “Listen, I built this on the customer side because they had this need. We should incorporate this into our product because everybody’s going to need it.” That’s an FDE in my mind.
I think FDEs are needed for the short term because, remember, all the enterprise AI startups are hungry for revenue. For some reason, we’ve created this notion that, “Don’t worry, just keep selling it. There’s a huge sort of pent-up demand around AI applications. Sell it before the product is fully ready.” That’s what you’re saying.
Harry Stebbings
Do you think that’s right?
Nikesh Arora
I think that’s the case. As we think things evolve in the next 12 to 24 months, people will switch from one set of products to another because something will emerge as a better product. Look at the coding conversations, right? How many coding companies have you heard of in the last 24 months?
We had Wind Surf, we had Devin, which is now Cognition. Wind Surf got sold. Those are the early guys in coding. They don’t exist in their current form. Now you’ve got Codex and Claude and Antigravity. You’ve got Factory doing SDLC, and you’ve got Cognition doing SDLC.
You can see, as the market evolves, people who have concentrated on different parts of the value chain around coding are getting formed. The product is getting more and more formed over time. Who knows, in 2 or 3 years, who’s going to be the leader in that space, because the product is not fully ready when you start.
Harry Stebbings
Do you want to make a bet on who will?
Nikesh Arora
No, you do that.
Harry Stebbings
I just need a good one that my teams can use. I don’t need to make a bet. I love that, and I agree.
Can I ask you, how do you choose who you decide to help? I spoke to your daughter, Ayesha, before, and she said one thing—not the only thing, because she said lots of things—that many people don’t know about you. One is that you help a lot of people, a lot of founders, and you ping them.
Nikesh Arora
Yes.
Harry Stebbings
How do you choose who you ping and who you help? Matan obviously being one of them.
Nikesh Arora
Well, my current paralysis, as I told you, is that this market is moving so fast. Based on what you read, OpenClaw comes out, and suddenly there’s this thing that people are going to have agents. There was a moment when everybody was going to have agentic browsers, remember? You don’t hear about them much, but there was a moment when everybody was going to have an agentic browser. Your browser was going to be your computer, and that was going to do all the agentic tasks.
When I hear about these things, I’m trying to assess which one’s going to work. If it works, how does it impact my product portfolio? What do I need to build in anticipation of this technology becoming mainstream? That window from the idea to execution is shortening in the AI world, as you can see, right?
The way these companies are coming out, getting formed in 12 months and 24 months, and getting to $100 million ARR is probably the fastest ever. That means if that’s what my enterprise customers are using, I have to figure out how to secure that stuff. My team doesn’t fully understand all this stuff.
So I’m really listening to podcasts, listening to people, watching people tweet, watching people on LinkedIn saying, “This is an interesting technology.” Helping the founder is my first step. I ping somebody who’s doing something interesting, which I don’t fully comprehend. They seem to be getting to a degree of success that gives me a feeling this could be something relevant—perhaps not this company, but the construct that they’re working on, the concept they’re working on.
Harry Stebbings
I’m an investor in a world of uncertainty; you go later, where there’s more certainty. We talked about this downstairs. I have that luxury in terms of a flexible mandate to do that. You have that luxury, too, in terms of the benefits of scale and acquisition budget.
Can you not just sit on the sidelines and wait for the right things to percolate and then buy them at $1 billion?
Nikesh Arora
Yes and no. Yes, we can wait. That doesn’t mean I don’t need to learn. I’m paying attention to 8 different players in the space, which I’m sure you do, too, trying to see who succeeded, why, what they did wrong, and what the guys who got it right did, too.
It’s very hard for me to assess what made it work. Was it fundamentally a bad idea? The technology is bad. Agents are not good. This agent is not going to work. It could be that, or this company didn’t implement it right. Agents are still a phenomenon; somebody else is going to execute right.
I need to understand the underlying technology for sure to make sure that my team is thinking about it. Do we adopt it, adapt it, and secure it in the future?
We bought an agentic AI gateway company 6 months ago. It didn’t cost a lot of money, but I figured, “Listen, if everybody is going to agentify the enterprise, how are we going to know how many agents you have running around the enterprise? How do I keep track of them? How are we going to govern them? How are we going to secure against them?”
I said, “The only way to do that logically is to find a way to aggregate agent traffic somewhere. If it goes through a certain gateway, a firewall, or some router, I can watch all the traffic and I can stop an agent from acting. That’s the only way it works.” I said, “The first thing you need to be able to do for agentic security is to have some sort of a gateway.” So we bought a gateway product.
Now, I got it at the right price. If I wait and look at what’s happening now, suddenly people are waking up to the idea that we need some sort of a router or gateway that all traffic needs to go through because of optimization reasons, routing reasons, and token-maxing reasons, which you have to pay double. Maybe. It wasn’t a big price, but I could have paid double.
That’s not the point. Things I buy are either going to help me 10x or 100x, or they’re going to fail spectacularly. It doesn’t matter if I paid 1x or 2x at that point in time. Of course, I shouldn’t be paying 2x and having it fail spectacularly all the time, but the 1x or 2x doesn’t make a difference. The 1-to-10, the 1-to-100, is what you do.
That’s what we’d like to do as well—not from an economic return perspective, but from a business-value perspective in our business.
Harry Stebbings
Are you more involved in Corp Dev today than you’ve ever been?
Nikesh Arora
No, I’ve always been more involved in Corp Dev. This is not a problem.
Harry Stebbings
Is that normal?
Nikesh Arora
I think I’d say I’m more involved in trying to learn what’s happening out there from a technology perspective than I’ve ever been, because the stuff is moving so fast. If I don’t have a point of view, and if I don’t encourage my teams to pay attention to it and talk about it, I think there’s a risk we miss a trick.
If you miss one trick, you can survive. You miss 2 tricks, you’re probably impaired. You miss 3 tricks, you could be obsolete.
8. Miss One Trick You Survive. Miss Three - You're Obsolete
Harry Stebbings
A lot of SaaS providers are feeling obsolete today. Their share price is telling them they’re obsolete. Do you think the majority of SaaS vendors have been oversold, or do you think that is an accurate reflection of where markets are moving?
9. Is the SaaS Sell-Off Justified?
Nikesh Arora
I think what the market is telling us is that the system of work, or the systems of record, will see a reimagination of workflows, as you and I talked.
So, going from software that doesn't have an opinion to software that has an opinion and expresses an opinion, and also does a lot of work for the human so the human doesn't have to do repetitive tasks—I don't think those AI applications have been created. I think the SaaS versions exist. We all use them.
I think at some point in time we'll see AI applications that do a lot of the tasks, and workflows get reimagined. I do think a lot of SaaS has built a lot of analytical capabilities to sit on top of the systems of work and systems of record. I think it's a lot easier to abstract that data into some large data lake and have LLMs analyze that data for you and give you the answers.
I think the analytic world is getting reshaped already. You can see people like Snowflake, Glean, or Databricks—all these people boast enterprise data lakes where you can bring the data, run LLMs against it, and get much more synthesized analytics and outcomes than you ever had before.
I think the third question, which we started off with, is that people are not sure how many people are going to work in these enterprises in the future. So, if you take the confusion over how many seats are going to survive in a SaaS world, the confusion around analytics being done differently, and the system of work getting reimagined, I don't know what the right valuation is.
Harry Stebbings
Done differently? So, again, disclaimer: I'm a podcaster.
Nikesh Arora
Oh, you get it. Yeah, yeah, you're a successful investor managing lots of people's money. That's true.
Harry Stebbings
But disclaimer: podcaster.
Nikesh Arora
Got it.
Harry Stebbings
I understand the seats question. I understand the workflow. Can you help me understand this?
Nikesh Arora
Well, if you look at most SaaS software, once you're fully deployed at a company, the company says, “Listen, I've got all this cool data about all your employees in my HR system, and I can help you get more insight in the HR system.”
Or if you take Salesforce, they have a Salesforce AppExchange with 300 apps you can use, which are analytical apps that feed off your own system-of-record go-to-market data and help you analyze that data.
Harry Stebbings
Do you know Neill Mehta?
Nikesh Arora
Yes, of course.
Harry Stebbings
Yeah, I love Neill. I think he's one of the most phenomenal people. I'll never forget him being in London at Christmastime. It was, I think, Christmas Eve or the day before, and he was spending time with me going through my pre-seed portfolio.
Nikesh Arora
Right.
Harry Stebbings
I think that just shows the hunger that he has for learning the day before Christmas. He was out to catch the cool early company so he could make lots of money.
But he's just so intent on finding the next thing. He always says the one question is, “Are companies' best days ahead or behind them?” And that's a very helpful one.
Nikesh Arora
Good question. Good question, yes.
Harry Stebbings
Are Salesforce's best days ahead or behind it?
Nikesh Arora
I don't know. That depends on how they execute from here on.
Harry Stebbings
If I were to paint a bear case for you—
Nikesh Arora
Mhm.
Harry Stebbings
What would that be?
Nikesh Arora
The bear case is that we don't get this transition right, with the world going to an AI-first future. Because, look, these false positives will keep reducing over time. Agents will become a real thing. Agents will do a lot of work for humans that humans have been doing manually in the past.
All that needs to get embodied in your product. If I can't make that transition happen with my team in the next 3 years, yes, there's a bear case, because somebody else will build a better mousetrap.
Harry Stebbings
And the bull case is that you understand it better than any other security provider and become the default security—
Nikesh Arora
The bull case is that we get that transition right. There's already a trend in our favor underlying that, where people are realizing they can't have 40 to 60 cybersecurity companies that they have to manage themselves.
We've been driving this trend of platformization already for the last 24 to 36 months. We already see the fruits of that, where people are saying, “You know what? I don't want 40 people solving my problem. Let me put Palo Alto Networks in and solve the problem that 20 different companies do together on one platform.”
Now, the good news is, because we're all coming to our senses and saying, “Yes, we need a lot more enterprise context and enterprise data. It has to be stitched. It has to be seamless,” that's what we learned with our current proposition. I just need to embrace the right AI capabilities in that stuff.
Harry Stebbings
Does platformization remove the ability to generate venture-scale returns? Remember, I need $10 billion companies. This is the big thing that I think most founders still don't fully comprehend. It sounds awful, but a billion dollars doesn't do it anymore. It needs to be $10 billion. It needs to be $20 billion or $30 billion.
With platformization, I can get a billion-dollar exit to you, hopefully. Please buy any of my companies for a billion in cash. I'll give you the catalog. You can take them.
Nikesh Arora
But I—you know what? I'd pay $10 billion.
I'm not going to fight against innovation. I think there'll be venture-scale returns in cybersecurity because, remember, we're the most innovative industry in the world. The bad guys are always looking for a new way in. They're not saying, “Oh, I exploited that 2 years ago. Let's try it again. Maybe somebody hasn't deployed a patch against that. Sure, we fixed that one.”
You've got to go find a new way to attack people. It's highly innovative. There are new attack vectors. People are going out there trying to chase them.
I'm not going to build everything myself. People will build great stuff, and sometimes people will build great stuff and build a platform around it. That's fine.
Remember, we come to a different vantage point. When I started Palo Alto Networks, we were less than 2% market share in the entire cybersecurity revenue. We're closing in on 8% or 9% right now. There's still a lot of room between 8% and 9% and 20%, 30%, or 40%.
That means there's still 60% market share out there to go enjoy in different companies. That's not all going to be existing players, including us. There is room to build companies that have tens of billions of dollars of market cap in the next 10 to 25 years.
Harry Stebbings
It's an enormous market, eh?
Nikesh Arora
It's beautiful.
Harry Stebbings
Yeah. Wow.
Nikesh Arora
Well, think about it. What percentage of the S&P is tech now? Compare that with 20 years ago.
Harry Stebbings
Year-to-date gains are like 8.6%.
Nikesh Arora
Forget the gains. What's the total S&P market cap? What percentage is tech, and what was that 20 years ago? What will that be 20 years from now? It was less; it'll be more.
Harry Stebbings
Yeah, I'm 100% aligned in that area.
Nikesh Arora
So, the entire tech space—what do you call marketing tech in the future? Marketing spend or tech spend? What do you call HR tech in the future? HR spend? Or what do you call the spend on all the tokens that replace repetitive human tasks? It all becomes tech spend.
10. Are Chinese Open Source Models a Real Security Threat?
Harry Stebbings
You said a word: “bad guys.” China is, in many people's eyes, a bad guy. We see a huge number of incredible open-source models being used extensively at a much cheaper cost. Do you think the proliferation of Chinese open-source models is something to be concerned about, or is it an inevitable feature of a burgeoning ecosystem?
Nikesh Arora
For a second, let's play the thought experiment. Take the word “China” out for a second and answer the question.
Harry Stebbings
Do I think open-source models are dangerous?
Nikesh Arora
Yeah.
Harry Stebbings
No.
Nikesh Arora
You think open source—I don't know what they say.
Harry Stebbings
I don't think open-source models are dangerous.
Nikesh Arora
Right. So, does it matter where they come from?
Harry Stebbings
Yes.
Nikesh Arora
Okay. So, you're not worried about open-source models; you're worried about Chinese open-source models.
Harry Stebbings
100%. I'm not saying I am not.
Nikesh Arora
Remember, there was a large tech company that also had open-source models for a while.
Harry Stebbings
Sure.
Nikesh Arora
Right. So, it's interesting to watch open-source models. I think the question becomes: In the future, do we end up with horses for courses? Do we end up with models that are very task-specific and helpful for certain tasks, and do we then always need to use this mega-frontier AI model for everything?
You already see that with ElevenLabs and the voice models that are out there, which are specific to a task. They probably do that task better than what the frontier AI model does.
We're talking—if you believe the world bifurcates into many task-specific models that are going to be useful for that task, that task-specific model could be better trained across the depth in a vertical space. That's going to happen.
Physical AI, for example, I don't think physical AI will be as easy as having a generic frontier model because there's no consumer use case for physical AI. It's a depth use case only, right?
The question is: Is your physical AI model that helps you fly planes going to be the same physical AI model that helps you drive cars? Most likely not. Will it be the same physical AI model that does robotic manufacturing? Probably not.
So, you're going to see depth in these models. You're going to see a world of bifurcated models with some sort of orchestration layer, as we've talked about. You're busy finding orchestration-layer companies that can allow you to pick the best model for the right task.
Those orchestration layers have to get smarter and smarter. They have to understand the context. They have to understand the memory. So, the question is: Do I store my memory and context in the orchestration layer, or do I store that in the frontier model?
Harry Stebbings
Which one do you think it will be? I know I'm the investor; I should know, but I don't.
Nikesh Arora
No, I think the challenge is that, right now, the frontier models know this problem and are aggressively moving to incorporate memory and context into their models because they understand that's the moat. The challenge is that you have to pay twice. If you say, “No, I don't want to use your memory and context,” the model may not be usable.
If you use an orchestration layer, the orchestration layer today is not as well funded as these models. The risk is that you end up in an architecture where the model has a lot of context and you cannot be model-agnostic. You actually become model-captive to get maximum efficacy and value for what you're going to get done.
It's not like you have a choice. You have to go all in on a model, or you can't go all in on a model. You can't do with one what you can do with the other. If you want to do with the other, you have to redesign your entire application, which is deeply embedded with the capabilities of the second one.
So, in the world of bifurcation and horses for courses, I think open source is a good thing because it allows you to play the cost curve. I don't need the smartest model to do the smartest thing, so open source is good. Whether it comes from a certain country or not, the question becomes: what backdoors are you worried about that these open-source models have?
What are you worried about? That's true for any nation-state, right? If there's a nation-state-sponsored open-source model, what are the backdoors? Can I get in? Does the model wake up one morning, have a sleeper agent in it, and start sending all the data somewhere else? Those are questions. Those can be secured. That's why you come to Palo Alto Networks to help you secure the models.
Harry Stebbings
Who is going to secure your backdoors?
Nikesh Arora
I don't know. What kind of idea do you have?
Harry Stebbings
So this is not a hangry night. This is a different kind of night that I'm dealing with.
Nikesh Arora
This is Monday morning.
Harry Stebbings
Yeah. All right.
Nikesh Arora
It's just terrible. What is the best time for me to show up here?
Harry Stebbings
I am in your time zone. I'm well rested. I'm not jet-lagged.
The quote from the chat: “Only secure your backdoors, not the—”
Nikesh Arora
Your mind is going in the wrong direction. The only 3 things you seem to have caught on to—
11. What Nobody Tells You About Having Money
Harry Stebbings
I know. I've got 2 questions, and we'll do a quick-fire.
With the incredible success you've had, you've made a lot of money. The question I have is: what does no one know about having money that they should know? One thing for me is that I've become much more impatient. We have very different—you're far more successful than me—but I've become way more impatient. No one told me I'd become impatient. I'm used to good quality in everything, and now, when it's not that, I'm very pissed. I don't like that in myself, but no one told me it would happen.
How do I fix it?
Nikesh Arora
Therapy.
Harry Stebbings
This is the common Western solution.
Nikesh Arora
Yes. Have somebody else tell you—
Harry Stebbings
You've gone back saying, “Oh, I must feel better now because I told somebody that I was going to therapy.” My therapist told me I should put myself first more often. I came back to being impatient because that's how you put yourself first. More important, believe in yourself, right? Is that what you're supposed to do? Optimize for yourself? Put myself first, and then it was your dad's fault.
Nikesh Arora
Oh my God. Is that what your therapist told you? That must be British. Okay.
Harry Stebbings
But no one told me that. I wish they had. What does no one tell you about having money that they should?
Nikesh Arora
I think it's not about money as much as it's about success. Remember, we all follow Maslow's hierarchy. I came to the United States with 2 suitcases, $200, and I was willing to do anything at all, within reason and on the right side of the law, to make sure that I made a life for myself because there was no way to go back.
I was going to use a different word, but I'm not going to use it because you'll go crazy again. There's no going back, right? It was a one-way ticket, which I did not have. I had no recourse. So, I was willing to do whatever it took. I took notes, became a security guard, and tried to pump gas for a weekend.
Harry Stebbings
You became a security guard?
Nikesh Arora
Yeah. When I came to the United States, I was a security guard. I took notes for the disabled, and I flipped burgers at Burger King. I had $200. I had to find a way of paying my tuition.
Harry Stebbings
Which of those was quite transformative to your mindset? Did you hate them? Did you love them? What's that like?
Nikesh Arora
It had to be done. It's karma. When you come from Eastern philosophy, it's karma, right? It's destiny. This is what you need to do to break your destiny, so you do that. You don't worry about what you have to do.
Now, at that point in time, there was no—
Harry Stebbings
How did you know you were going to be successful?
Nikesh Arora
I don't know. Who knows? Nobody knows they're going to be successful. You just come in and do your best, hope for the best, and see what happens.
That's very Eastern philosophy, right? You believe in karma and destiny. How do you manage billions of people in the world? You make sure they believe in destiny. If they believe in destiny, they'll say, “Oh, this must be what was my destiny in the end. I tried my best. This is where I ended up.”
That's better than your therapist. It just keeps you centered, saying, “Okay, I tried my best. I gave it everything I had, but perhaps this is what God intended for me.” You find that hard to believe?
Harry Stebbings
If you were my therapist, I don't think I could afford you, though. That's the point.
Nikesh Arora
This is free. You're getting it free. I'm not sure I fully embrace all of that, but that was where I started. From that perspective, over time, you climb up Maslow's hierarchy. It was about food and shelter, then it became about ambition, and it becomes self-actualization.
Conceptually, in Maslow's hierarchy, you get to a certain amount of money, and then you decide there are some things I don't have to do anymore. I don't have to be a security guard. I don't have to flip burgers, right? But that very quickly goes up to saying, “I don't have to tolerate certain things that I tolerated in my life because I don't need them in my life. I don't have to adapt to the circumstance because I can walk away.”
Harry Stebbings
Do you ever get worried that the willingness to walk away makes you softer?
Nikesh Arora
The willingness to walk away makes you softer? No, actually, it's the other way around. The willingness to walk away makes sure you optimize the outcome. When you negotiate, if you're fully vested in the outcome, you fold at some point, saying, “Well, I can't let Harry Stebbings walk away because if Harry walks away, I have no deal.”
But if I say, “You know what, Harry? It's going to be these terms or no terms. I'm willing to walk away,” then it becomes a battle of wits, right? Does Harry want it more, or do I want it more? Does it make you softer? I don't think being willing to walk away makes you softer. I think being willing to walk away makes sure that you understand the pros and cons of what you're dealing with.
It makes you understand whether you should spend your time there or not. It just makes you understand whether you can get an outcome that is useful for you as well as the other person. You know, we have a lot of choices in life once you have the amount of wealth you have.
Harry Stebbings
I'm on the clock, sir.
Nikesh Arora
Easy, easy, easy, easy. You said that a few times.
Harry Stebbings
Final one, and then we'll do a quick-fire. I care a lot about kids, actually. I love kids, and I want to be a really good father when I am one. You're a CEO of a public company, which is incredible. You've had an insane career, and I've had the pleasure of meeting one of your children. She's amazing.
Nikesh Arora
Cheers.
Harry Stebbings
She's amazing. What advice do you have for me on how to be a great dad, but also not lose an inch on work? I'm not willing to sacrifice much on the work side.
12. How to Be a Great Father Without Sacrificing an Inch on Work
Nikesh Arora
Yeah, this is the hardest problem in the world. I think there are 20 or 30 billion people who have been born since the beginning of civilization. Yet there is no AI that can train us on what we need to specifically do to create the outcome we'd like to create.
It's way too many variables, right? There are all kinds of people in the world, and I'm sure their parents—some of the parents are amazing, and some of the parents are not as amazing. So, I think part of it is that you can do your best from your perspective, and I think kids absorb a lot by watching you—your work ethic. They watch your values, and they see how you interact with them.
My daughter probably has a better sense of who I am as a person than anything I can tell her because she spends time around me. She sees me interacting in every sort of micro-situation: what makes me impatient, what makes me patient, and what makes me do certain things. At the end of the day, your child believes that you have the best intentions for them. I think that goes a long way.
Harry Stebbings
I totally get you. I had a guest on the show, and they said, “Watch National Geographic if you want to be a good parent.” I said, “What?” He said, “Look at the elephants. The children follow. So, if you want your child to be nice to waiters, be nice to waiters.”
If you want them to work hard, work hard.
Nikesh Arora
Yes. Well, that's true in organizations, too, by the way. Organizations take on the form of the leader. I'm pretty sure if you close your eyes and rattled off 5 or 6 attributes of a company and said, “This company has a founder,” and then said, “How do you compare the company's cultural values vis-à-vis the founder?” you'd find a remarkable resonance between the 2 things.
13. Quick-Fire Round
Companies act because, remember, the organization is trying to please the founder because they figured out that's the way to achieve success. If my CEO is impatient, if my CEO is exacting, if my CEO is ambitious, if my CEO suffers no fools and gets stuff done, then that must be what they want to reward. So, you suddenly find that this, again, depends on whether he has the right values or not. And you told me a story about a guy who had different values and they had to shut the company down. But if he has the right values, people will watch your behavior and want to emulate your behavior.
Harry Stebbings
I want to do a quick-fire because otherwise I'll take up all of your time. What is a belief that's held by most top investors and founders in Silicon Valley today that you think is wrong?
Nikesh Arora
My concern would be, at this point in time, given the pace at which technology is evolving, given the uncertainty in terms of what's going to work, what's not going to work, and where there might be too much euphoria and a bit of FOMO going around in terms of, “My God, if I don't invest in something that's interesting and the right founder, I'll be left out.”
And because people have seen this happen, look at what's happening in Anthropic, right? If you missed the 1st round, the 2nd round, the 3rd round, the 4th round, the 5th round, then you look like a guy who's got money. Now, you had 20 years to invest in SpaceX. You had 3 to invest in Anthropic. That piece is fundamentally different.
I'm sure as many people are happy that SpaceX finally went public, as many people are probably sitting there moping, saying, “Damn, I should have done the Anthropic round 2 years ago when they showed up on my doorstep.” I think there's a lot of FOMO coupled with euphoria on the other side, and I think the risk is that we think every company that's going to show up now is going to be the next Anthropic, so we better get into it.
Harry Stebbings
My next one to you is: any moment, any board meeting, what was the biggest “oh shit” in a board meeting?
Nikesh Arora
I got a very interesting insight from one of my board members. We're prolific buyers of companies because I'm constantly paranoid that we haven't built it, somebody else is going to build it, so we better go acquire it and find the team to go get it done.
There was one particular acquisition. It took a lot of effort to get the founders to the table, get them to agree, grind through due diligence, and figure out whether it was going to work or not. It's a substantive amount of money, relatively speaking—hundreds of millions of dollars, close to almost $1 billion.
I called one of my board members and said, “Hey, what do you think about this?” He said, “You're calling me. You don't call me all the time about all the acquisitions you do, so this one must be different.” I said, “No, it's not different. I'm just thinking hard about it. It's taking a lot of effort.”
He said, “Go for a long walk. Ignore all the effort you put in.” He said, “Because sometimes what happens is you confuse effort with wanting to get the outcome. Because you spent a lot of time and effort trying to get it, then you feel like when you get it, you better take it because you put all the effort in.”
And he says, “You haven't spent a dollar yet. You just put in 3 months of effort. But remember, once you put the dollar, then it becomes yours. It's your job to make it successful. So, you still have one more chance to decide if you want it or not.”
I go for a very long walk and say, “If this walked in the door right now, and there was zero effort involved, all I had to do was write the check, would I take it or not?”
Harry Stebbings
Forget the sunk cost.
Nikesh Arora
Yes.
Harry Stebbings
We have the same in the investing business.
Nikesh Arora
Yes. You spend a lot of time. You're like, “Oh my God, I'm the one getting the term sheet, and nobody else has it. I nailed it. I've beaten out 8 VCs to it.” The question is not how many VCs you beat to get the deal. The question is, “Can this deal stand on its own merits, and would you invest in it if there was no competition?”
Harry Stebbings
What's the best advice you've ever been given?
Nikesh Arora
The best advice that a really old man gave me on a flight once was, “You know, life is simple. If you wake up in the morning, you're really excited about going to do what you do for a living, you're blessed. And if you're done after a long day and really excited to go home to your family, you're blessed.”
Like that?
Harry Stebbings
I do. And I actually tweeted last night, “I hated school when I was a kid. Sunday nights were the worst.”
Nikesh Arora
Yes.
Harry Stebbings
My Sunday night last night was thinking about our show and the conversation. What a great Sunday night. What a great Monday night.
Nikesh Arora
I was not sure where you were going to go with that.
Harry Stebbings
No. What it was—how lucky am I? Seriously. It's amazing.
Final one. What are you most excited for when you look forward to the next 5 to 10 years? What are you most excited for? Is it becoming a grandparent? Maybe. I might have just seen my mother become a grandmother.
It's amazing. She's amazing. Is it the health benefits? You know, I'm so excited that AI might be able to solve multiple sclerosis, which my mother has. That'd be incredible.
Nikesh Arora
You never know what tomorrow's going to bring you. The only way I've been able to do everything I do is not to get too hung up on what's going to happen to me a year from now or 5 years from now, because that's too far.
I think you wake up in the morning, you're given an amazing day, and, you know, everything's working around you: your kids are happy, your family's happy, you enjoy what you do, and you have good friends.
I was at a different place earlier this week, and they asked me, “You're not a 996 CEO. What do you do?” I said, “Look, I try to make sure that I can find something to enjoy every day.”
Because I have enough things to worry about. I could really get myself in the wrong headspace by worrying about a lot of things. I run cybersecurity, for crying out loud. I live off the fact that somebody's going to hack somebody at some point in time.
My phone rings saying, “Can you help us? Why didn't you spend the money before?” But can I help you? Yes, I can help you. So, I think it's a state-of-mind thing.
Can you get your state of mind to be optimistic, positive, and one of gratitude and happiness every day? If you can, it's going to be great. Well, guess what? If the health benefits come, I can start being Benjamin Button. It'd be amazing.
If my kids continue to be happy and successful, it'd be amazing. If my mother lives for 150 years and she's happy, it'd be amazing. There are so many amazing things that can happen and perhaps may not happen. So, let's just focus on tomorrow.
Harry Stebbings
And Nikesh, I so appreciate you being willing to come back for a second. I mean, after the first one, when I suggested it, I was like, “There's no chance he's doing this.”
Nikesh Arora
Good thing I have to go back and listen to the first one now.
Harry Stebbings
But thank you so much. You've been incredible.
Nikesh Arora
Thanks for having me.