[BidClub_]
No Priors · · 58 分钟

No Priors | 对话 Palo Alto Networks CEO、前 Google 首席商务官 Nikesh Arora

Sarah GuoElad GilNikesh Arora

YouTube
TL;DR
  • Nikesh Arora 认为,Google 已为从排序链接转向综合答案做好准备,但真正的不确定性不在产品能力,而在于如何变现。 搜索实现了信息民主化;生成式 AI 如今承诺带来“智能民主化”,而 Google 仍掌握分发、产品能力和 AI 能力。更难的转变,是从围绕文本链接和广告销售线索,转向按消费或“完成的交易”收费,就像 YouTube 在获得庞大分发后才找到自己的商业模式。

  • Agent 比生成式 AI 更具颠覆性,因为它们可能消除数百万应用促成交易所依赖的界面。 如果 Agent 可以直接预订航班或餐厅,许多应用就会退化为 Agent 之下的 API,或 MCP 客户端—服务器交互。最脆弱的企业,是那些“对 UI 忠诚度很低”的企业:它们的前端很薄,品牌除了展示交易处理器之外几乎没有其他价值。

  • Arora 表示,只有在能够以企业级准确度执行精确动作时,企业 AI 才能支撑自主工作经济。 消费者可以容忍重新尝试一个错误答案;企业无法接受“我让你关的是那台服务器,不是这台”。他认为,今天的系统仍是有人参与的助手,并设想“AI as a service”应用逐步接管工作流,未来可能按工作量、席位或 Agent 席位收费,而不是立即取代完整职能。

  • 持久的企业 AI 公司需要专有上下文和记录系统,而不只是套在基础模型外面的 wrapper。 通用模型像“来自顶尖大学、最聪明的 PhD”,但仍要学习每家公司的做事方式和领域数据。如果模型的推理能力趋同,只增加护栏或呈现层的 wrapper 可能被模型吸收;掌握工作流、规则和权威数据的系统则拥有更强护城河。

  • 在网络安全领域,AI 会奖励拥有广泛传感器覆盖和全企业上下文的平台,同时威胁狭窄的调查 wrapper。 Palo Alto 的核心判断是:“看不见的东西,就无法阻止”;传感器仍是拦截已知恶意活动、并收集识别未知恶意活动所需数据的基础。调查孤立告警的 Agent 今天可能有用,但 Arora 预计,随着跨域数据让自动诊断更具确定性,集成平台会逐步挤压它们。

  • AI 正把网络防御变成一场速度竞赛,而许多企业目前正在输掉这场竞赛。 观测到的从锁定目标到入侵并窃取数据的最快路径,已从7年前的3—4天缩短至23分钟,而平均响应时间仍以天计。Arora 表示,89%的攻击源于凭证窃取;相比一次成功登录后无限期信任用户,他更偏好异常检测、即时访问权限和行为信号。

  • 近期最明确的经营杠杆在重复性行政和支持工作,销售以及顶尖产品人才则相对更受保护。 Arora 估计,大型公司可能获得“200、300或400个基点的效率提升”;他认为,优秀公司应通过提升产品质量和诊断能力,在2—5年内争取削减80%—90%的客户支持。编码 Agent 应该加速工程师,而不是淘汰最优秀的工程师:Palo Alto 已经看到一个 Agent 找出漏洞、将500行代码压缩至75行,并解释一段15年前的代码。

  • Palo Alto 的扩张打法,是平台整合叠加由收购驱动的“分布式研发”。Arora 将产品组合从4个扩展到24个,组织成3个平台,并收购了27家公司,通常瞄准行业第1或第2名,而且经常让创始人继续担任业务负责人。 其目标,是把一个约有25年历史、高度碎片化的安全行业变成平台市场;但“Agent”究竟意味着什么仍未形成共识,产品方向也因此持续复盘。

摘要 · 为研究而整理的核心内容

1. 搜索正从信息检索走向综合智能

  • Arora 对历史的切入点,是搜索最初那个令人惊叹的承诺:在互联网上输入一些内容,就能找到答案。20年的索引工作带来了“信息民主化”,甚至让印度农民也能获得信息;生成式 AI 则回应了下一个需求——“别把这一堆东西都丢给我,让我自己筛。试着替我把它们弄明白。”

  • 他把新阶段称为“智能民主化”:对于一个已经被解决过9,999次的问题,人们不该反复花钱请专家再解决一遍。Google 在理解用户意图、组织信息方面的经验,应当能够进一步回答用户真正想表达的内容;Larry 大约15年前就已经在描述这一方向。

  • 主持人提出的挑战在经济层面,而非技术层面。Google、Apple 和 Facebook 掌握着触达数十亿人的分发能力,而 Gemini、ChatGPT 和其他模型正在抵达相近的位置;目前没人知道,围绕文本链接和广告的变现,如何转化为消费或交易收入。Arora 给出的先例是 YouTube:它长期被认为在经济性上不如 Netflix,但如今已经是“一门很大的生意”。

2. Agent 可能把数百万个界面压缩成交易通道

  • Arora 认为,“Agent 化挑战远大于生成式 AI 挑战”。产品经理花了30—40年打造界面,让普通用户能够操纵底层算法——Expedia 的输入框,本质上替代了用户编写 SQL;但自然语言正在削弱界面本身的战略价值。

  • 再往前推一步,用户甚至不需要与界面交互:他们的 Agent 可以直接完成任务。Arora 用刻意粗略的数字推演称,移动应用超过500万个,其中或许一半主要用于收集用户输入并完成交易;这些应用可能变成 API,或成为 Agent 之下的 MCP 客户端—服务器交互。

  • 这种颠覆也可能改善变现。直接响应广告主要卖的是销售线索,但企业愿意为完成的交易支付更多:“也许直接替你买下机票,比帮你找到一个广告主获得更多收入。”在稳定模式形成之前,许多应用都将被重写,并被迫决定自己究竟是消费品牌,还是交易基础设施。

3. 薄界面暴露脆弱性,但忠诚度仍能守住分发

  • 被问及谁最容易受到冲击时,Arora 指向那些“对 UI 忠诚度很低”的企业。如果一个产品只是交易处理之上的薄前端,消费者可能并不在乎究竟是哪一个旅行界面为其签发前往印度的机票,也不在乎是哪项服务替其预订餐厅。

  • 隐含的分界线,在于非产品体验是否真正创造了品牌偏好。Agent 可以轻易绕过同质化的预订界面;但要替代一个用户主动偏好的目的地,就困难得多。

  • Guo 提到 OpenAI 两个尚未充分验证的商业模式命题:面向大众的智能订阅,以及为更难的思考或“工作”提供可规模化的付费。Arora 认为消费者愿意订阅值得关注,但企业工作定价所要求的标准,远高于消费级聊天。

4. 企业自主化受制于精确度、责任和工作流重构

  • 消费者经常会重新理解一个错误的搜索结果,或重写一次提示词。企业无法接受一个自主模型在损坏生产基础设施后说:“糟糕,抱歉,我犯了个错。我让你关的是那台服务器,不是这台。”

  • 因此,Arora 不认同企业已经把需要自主精度的工作交给 LLM。当前部署仍是“一个高级助手,或者更好的助手”:它们总结知识、提出多个答案,同时保留人工参与。精确任务最终可能支撑按工作量收费,但“我认为我们还没走到那一步”。

  • 他设想的架构更接近“AI as a service”,而不是传统 SaaS:围绕 AI 端到端重构企业工作流,让应用从人类使用中学习,并逐步接管更多重复性任务。编码产品属于“正在训练中的 AI 应用”,先从开发者切入,是因为当模型提供75%可用代码时,开发者可以修补剩下的25%。

  • 主持人追问,基础模型公司是否会像 Microsoft 将 Office 打包进产品、Google 在 Workspace 中展示 Gemini 那样,向主要垂直行业前向整合。Arora 认为,编码之所以相对容易,是因为公开代码可以让模型达到90%的编码能力;遗传学、药物研发和网络安全则需要专有数据集,无法获得同等程度的公开数据。

5. 记录系统,而非通用 wrapper,才是持久的企业护城河

  • Arora 的比喻是,前沿模型像“来自顶尖大学、最聪明的 PhD”。Palo Alto 仍然要教会这位 PhD 自己的上下文、方法和问题;换入一个新版本的模型,可能更像重新招聘并培训一位 PhD,而不是更换一个可互换的零部件。

  • Thomas 早期给出的建议,是不要去追逐一个小型网络安全模型,因为大型模型会变得越来越聪明。如果模型的推理能力趋同,差异化就会转向把这种智能应用于专有领域,而不是以更小规模复刻通用能力。

  • 当 wrapper 只是增强模型或增加护栏时,它就暴露了脆弱性:底层模型可以不断扩展,直到 wrapper 消失。持久的应用则会封装一套工作流,并控制一个记录系统——薪酬、假期、股权、归属期,或其他模型本身不拥有的权威数据集。

  • 对于法律审查、应付账款等通用职能,Arora 要求 Palo Alto 团队不要内部开发:总会有人以更低价格提供这项能力,可能按席位、Agent 席位或工作单元收费。但专有源代码或 FDA 试验数据必须继续隔离保存,因此供应商必须接受对租户隔离、训练使用方式,以及“我的数据归我所有”的严格测试。

6. 网络安全优势始于传感器,并通过上下文不断复利

  • 网络安全首先要求出现在“每一个边界、每一个终端、每一个传感器”上,因为“看不见的东西,就无法阻止”。Palo Alto 有意扩展到包括 SASE 和终端产品在内的控制点:传感器一方面拦截已知恶意活动,另一方面产生推断未知恶意活动所需的原始数据。

  • Arora 批评那些垂直孤立的工具:它们接收某一类数据,在自己的云端分析,再返回数千个可疑项目。如果邮件安全产品看到 Elad 点击了钓鱼链接,却看不到后续防火墙流量,它只能建议调查,而不能确定究竟发生了什么。

  • Palo Alto 的替代方案,是整合企业数据,在数据接入附近完成事件关联,并利用完整上下文自动调查。Arora 将许多当前的 SOC 和网络安全 Agent 初创公司比作通用 LLM wrapper:当平台尚未具备某项功能时,它们有用;但随着集成产品吸收这项能力,它们会越来越受到挤压。

  • 主持人的反驳值得保留:大型企业无法迅速整合包含数十种产品的环境;据称,一位安全负责人手下就有118个身份工具。Arora 承认短期内会很混乱,但他把网络安全描述为一个约有25年历史的行业,其点状解决方案是一种威胁出现后再逐个诞生的结果。他认为,如果安全栈中80%的能力最终都能广泛获得,那么它们最终就应该迁移到平台上。

7. AI 攻击者把数天暴露时间压缩到数分钟

  • 如果防御方相信 Agent 可以发现并执行工作,Arora 表示,他们就必须假设攻击者也能将 Agent 释放到整个企业环境中,寻找可被攻破的暴露面、模拟攻击路径,并“在几分钟内,或不到1小时内”窃取数据。

  • 7年前他刚开始工作时,从锁定目标、渗透到窃取数据通常需要3—4天;Palo Alto 目前观测到的最快速度是23分钟。“根据物理规律,你的响应时间必须少于1小时”,但平均响应时间仍以天计;攻击时间被压缩,既是 AI 带来的最大威胁,也是平台机会。

  • 在这样的时间压力下,持续渗透测试的战略价值上升。Arora 表示,大约一半公司会回避严肃测试,因为“它们害怕发现问题”;Palo Alto 选择7×24×365运行测试,而不是依赖周期性的第三方顾问,因为一家安全供应商自身被攻破将是生死攸关的问题。

  • 社会工程进一步放大了问题:Arora 表示,89%的攻击源于凭证窃取,而公开数据问题以及语音或 deepfake 技术,正在削弱许多双因素认证手段。与其假设身份通过验证后就可以无限期漫游,他更希望采用即时权限和异常控制,甚至检测“你的打字方式”是否发生变化,并据此阻断访问。

8. AI 应该消除支持工作,同时让产品实质性变好

  • Arora 认为,AI 可以在销售环节提供适度赋能,例如定制演示文稿、提案或 SDR 工作;但他怀疑,Agent 能否比一个值得信赖、向 CIO 或 CISO 展示产品的人更快完成说服。自动化触达还可能遭遇自动化的“屏蔽所有 SDR” Agent,让获客从创造企业需求,转向匹配已知需求。

  • 行政工作提供了更大的杠杆。如果200人负责制作文档,而模型可以完成其中90%,公司可能只需要更少的操作人员,再加上设计工作流和护栏、熟悉 AI 的员工;Arora 粗略预计,效率提升将达到“200、300或400个基点”,规模越大的组织获得的绝对金额越多。

  • 他更明确的北极星是:“客户支持之所以存在,是因为我们做出了糟糕的产品。”优秀公司应该在2—5年内争取削减80%—90%的支持工作——不只是自动化处理投诉,而是改善 onboarding、减少缺陷、加快修复,并通过数据提升诊断能力。Palo Alto 目前会把由产品造成的支持问题排在新功能之前。

  • Guo 反驳称,生成式代码可能淹没审查能力,并制造大量无人真正理解的软件。Arora 认为,今天的质量“已经是现在最差、也是未来会遇到的最差水平”:Palo Alto 已经看到一个 Agent 找出漏洞,将500行代码压缩至75行,并解释一段写于15年前、连作者都已找不到的代码。他的保留意见指向人,而非技术:“愚蠢没有解决方案。”

9. 平台野心需要分布式研发和持续纠偏

  • Arora 对企业经济学的洞察是,营收不足10亿美元的公司,销售、市场和支持成本可能占总成本的50%—65%,而最大型供应商约为30%;研发仍约占12%—16%,一般及行政费用约占4%—8%。杠杆来自先赢得一个客户的信任,再在其整个环境中扩张,而不是反复为新增客户承担获客成本。

  • Arora 加入 Palo Alto 时,公司有4个产品,后来扩展到24个,再组织成3个平台。要求客户从118家供应商迁移到1家,会“让他的大脑短路”;因此 Arora 描述的是一条为期2—3年的平台化路径,把3个平台作为比直接要求客户整合到1个平台更容易接受的目标。

  • 公司的27次收购,都是“在高度创新市场中的产品开发和研究”,或者如主持人所说,是“分布式研发”。Palo Alto 瞄准行业第1或第2名,而不是继续打磨第3或第4名;它经常让被收购公司的创始人担任业务负责人,并通过收购 Protect AI 增加模型扫描和持续 red teaming 能力,这些正是其原有 AI 防火墙尚不具备的功能。

  • Arora 的领导闭环把雄心与异常直接的沟通结合起来:他把员工会议从8人扩大到25人,并每两周与50名员工交流,检验“为什么”经过4—5层组织传递后是否仍然成立。尚未解决的边界是 Agent——供应商在定义、连接器、MCP、身份和委派方面意见不一,因此有一支团队每天花2小时拼出一个可用的整体判断。他的更广泛立场仍然乐观:AI 是一股双刃剑式的技术浪潮,一些坏事“最有可能”发生,而社会“最有可能、也希望能够”找到穿越它们的道路。

Today we're here with Nikesh Arora, the CEO of Palo Alto Networks. He joined Palo Alto in 2018 when it was the nextG firewall player and has since grown it to six to seven times the size as a leader as a platform security company. Previously he was the SVP and CBO of Google during its massive growth phase from 2004 to 2014. Welcome, Nikesh. Nikesh, thanks so much for being with us.

Nikesh Arora

My pleasure.

Sarah Guo

I don't know where to start because I want to talk about AI, security, and leadership. Given your history growing Google as chief business officer, we have to ask you: What do you think is the future of search, and how threatened is it?

Nikesh Arora

Nothing like a slow little lowball to welcome me to your show. Turn it up a little bit.

Sarah Guo

This guy was at Google, too, at that point in time, weren't you?

Elad Gil

But I talked to him too much.

Sarah Guo

What did you think?

Elad Gil

I think we should defer the question to you as the expert.

Sarah Guo

Oh, look at that. He knows how to put his own mouth back. Have him do all the hard work.

Nikesh Arora

I think the idea when search came about—I still remember going out there and trying to sell search to people, and it was, “Oh, my God, you mean I can just go to the internet, type something, and get the answer?” We spent 2 decades trying to get all the information out there on the internet so it was easily accessible to people. You saw the benefits: the democratization of information. Farmers in India could get stuff, and people could get information.

I think now we're in an age where people are saying, “Great, don't give me all this stuff to sift through myself. Try to make sense of all of it for me because it's too much.” That's what you're seeing in today's generative AI models. In my own words, I call that the democratization of intelligence. All of us will have the basic intelligence that every other person next to us has because we can figure it out. I don't have to hire the same people to solve the same problem for me for the 10,000th time and pay the money, because it's already been solved 9,999 times and the outcome is somewhere on the internet.

To the extent that Google has sharpened its skills in putting all that information together, being able to synthesize it, understand it, interpret my intention as an end user, and try to present me with the most likely outcome, I think that should translate well to the notion of generative AI being able to summarize the same things in a much more enhanced, orderly way.

I think, from that perspective, they are in a good position to transition the current search product into a future product. Call it what you want—“Ask Me Anything,” or whatever. It's funny: when you worked at Google 15 years ago, Larry had that vision. He used to talk about getting to a point where you answer my question and answer my intent, as opposed to answering what I type. He had the foresight to talk about that.

From a product perspective, they are in a good position to transition the product to what end users need. You've seen that with Gemini, ChatGPT, and other models that are getting to the same place. Let's not underestimate the power of distribution. There are 2 or 3 companies in the world that have distribution to billions of people, whether it's Facebook with all its properties, Apple with its properties, or Google with its properties.

They have the distribution, the product chops, and the AI chops. I think the bigger question is: How does the business model transform from what it has been, with text links and ads being represented against them? What's the new monetization that will come as a result of that?

Elad Gil

It's likely to be agents or something else in terms of starting to take action.

Nikesh Arora

Yeah, we can come there, too, but I think, because she has a search question, search is an advertising-revenue question. The question is, how does advertising revenue morph into some version of a consumption or transaction metric? Because when I say, “What are the best blue pants in the world?” I'm not doing it for academic interest. I'm actually going to transact. Maybe an agent could do this, or know the fastest flight to get to Rome. The agent could do that, and we'll talk about agents in a second, because I think that's much more disruptive than generative AI.

Sarah Guo

To that extent, how they transition the business model is going to be interesting. I don't think anyone knows what the business model is, but all I can say is that, having been there and admired what they do, they spend time getting the product adopted first. Eventually, when there are tremendous amounts of distribution for the product, you find that a model emerges.

I remember how, for the longest time, nobody quite knew how YouTube was going to make money. Everybody was looking at Netflix as the one making money in streaming, and YouTube wasn't. I think YouTube is a big-ass business now compared to most other streaming players in the world. They'll figure out how that model transforms. I do think the agentic challenge is a much bigger challenge than the generative AI challenge.

What sort of challenge do you think that is, or how do you think that's going to take shape?

Nikesh Arora

Look, the idea is that, if you step back, we spent 30 or 40 years building products where we focused on the UI. Product managers are effectively glorified UI managers who are trying to make sure that we common folks can interact with data and some sort of engineering algorithm behind it, because we're not smart enough to talk to the engineering algorithm ourselves.

You go to Expedia, and it's a bunch of boxes we're supposed to fill in as humans, and it gives us the answer without having us write any search query, SQL, XQL, or whatever you want to use to find the information. I think generative AI has made that easier. We can talk to the UI in natural language to some degree, and it can generate outcomes on the fly. To that extent, all of product development is going to change with generative AI and this natural-language capability.

If you take that next step further and say, “I actually don't need to come interact with the UI; my agent can go do the task for me,” step back and think of that. Fifty percent of the applications in the world are some sort of transaction-fulfillment applications. If there are 5 million apps on the iPhone or Android phone—I'm picking a number; I think it's more than 5 million—half of them are trying to get you and me to interact with the engineering algorithm and give it some data.

Mhm.

Nikesh Arora

If all those become agentic actions of an Uber agent, the question becomes—

Elad Gil

Who sits atop?

Nikesh Arora

Yeah.

Sarah Guo

Who's the Uber?

Nikesh Arora

And that's also a lot of Google's traditional revenue, at least on the advertising side. It's not the brand ad.

So it's part of that business model in some sense.

Nikesh Arora

Yes, it is. Most direct response is lead gen. In marketing speak, it's lead gen, which eventually results in a transaction or fulfillment of an information request.

At some level, it is a precursor to a transaction. People pay a lot more for the consummated transaction than for the lead. Maybe the business-model transition is: Stop giving me leads; give me consummated transactions through agents. Maybe I'll get paid more to buy you the airline ticket directly than to have you find an airline-ticket provider that is advertising, versus transactions.

I think the opportunity is there from a business-model perspective. Before we go back to that stable world where these business models have transformed, we're going to go through a very disruptive phase where a lot of these apps will be rewritten. We'll have to question whether some of these apps are direct-to-consumer apps or APIs—or perhaps MCP client-server interactions, if we don't call them APIs anymore—that will actually consummate that transaction.

Elad Gil

Who do you think is most vulnerable?

Nikesh Arora

Wow. You guys don't ask simple questions. He has to go for the jugular on every one of them. Who do I—

Sarah Guo

That's why you're such a good investor.

Elad Gil

Yeah, we're looking forward to your insights on this stuff.

Nikesh Arora

No, I know. Look, I think the most vulnerable people are where there is poor loyalty to the UI. If it's just a thin front end to a transaction-processing system in the back, do you care who you get your ticket to India from?

My wife is coming back. Do you care which airline, travel agency, or travel UI you get your ticket from? Perhaps you don't. You just want a ticket that allows you to get on a plane and get to the other side. Do you care who books your reservation for a restaurant?

At the end, where you're effectively a transaction-processing interface, where you build some degree of brand loyalty through a whole bunch of non-product experiences, I think those become vulnerable.

There are several more controversial ideas that OpenAI is trying to prove out. One is the scalability of consumer subscription.

Sarah Guo

How does that work?

Nikesh Arora

Well, it's just like: Can you imagine? I think it's actually quite surprising how many people are paying subscriptions for this intelligence today.

Yes. Right. Yes.

Nikesh Arora

I think the other is—and I want to talk about the B2B side—that you should get paid for thinking harder and solving harder tasks in a scalable way.

Nikesh Arora

This is what they want. They want to sell work, right, to businesses.

Elad Gil

What do you mean by work to businesses?

Nikesh Arora

I think there’s a view that the traditional way you sell most enterprise software or products is as a seat unit.

Sarah Guo

Yes.

Nikesh Arora

Or it’s some sort of volume unit, like an appliance or something, or a coverage, right?

Elad Gil

Throughput-based, yes.

Nikesh Arora

And here, the view would be, well, if I solve a really hard problem for you, I have a unit of work. It’s essentially translating to a unit of compute, or sort of charging for value, and I think there’s a strong belief in some of the labs that they should be able to charge for that.

Sarah Guo

How do you react to either of those business model ideas, because you’re now at Palo Alto in the business of selling direct value versus ads?

Nikesh Arora

Yeah. Okay. So are we pivoting from consumer to business now? Are we moving away from the subscription? We went off on the whole idea of people paying for subscriptions. I think that is a bigger leap.

The bigger leap is that, in the consumer world, we are much more tolerant of inaccurate answers, or not-perfect answers. How many times do you go to a search, even today, where you’re looking for something, you don’t find the right answer, and you say, “Well, let me look again. I must have asked the question wrong. Let me ask the question.” You probably do that in your prompts in ChatGPT or Gemini, or pick your favorite LLM.

Elad Gil

But in the enterprise world, there is not that tolerance for an inaccurate outcome. Especially if you get into the agentic world, you could say, “Oops, sorry, I made a mistake. I meant you to turn off that server, not this one. I blew up a whole bunch of my enterprise because you gave me the wrong answer, dear friend LLM.”

Nikesh Arora

So I don’t think we’re going to—I don’t think we’re there yet, to be fair. None of us are giving autonomy to any form of LLMs to create any agentic task or do any work for me. We’re all using them with humans in the loop for suggestions, and we’re still using the use cases where we’re okay with multiple answers.

We’re actually having the humans be— it’s almost like a glorified assistant, or better assistant, or somebody who’s a knowledge worker who’s summarizing a whole bunch of information that I may not be able to have from the outside. I don’t think we’re getting into precision tasks. We’re not getting into precision actions yet.

So, look, if you can generate precision tasks with accuracy, precision actions with accuracy, yeah, sure, maybe you can charge me for a unit of work. But—

Sarah Guo

I almost feel that in the enterprise, we’re going to go back to some version of redefined, for lack of a better word. Let’s call them AI as a service instead of SaaS.

Nikesh Arora

Perhaps AIaaS.

Elad Gil

Right. Sounds nuts as a term. Yeah, yeah.

Nikesh Arora

SaaS wasn’t a real term either. Sure. Yeah, yeah.

Sarah Guo

Sounds even worse. But anyway, imagine that, because you literally have to design the enterprise workflow—

Elad Gil

End to end, and see how I can do that from an AI-first perspective, right? Perhaps the likes of Cursor or vibe-coding apps today. They’re trying to at least look at a part of a developer’s workflow and say, “Here’s what you do. Here’s a bunch of tools that can help you through that journey, dear human, and I’m going to see, based on how you use it over time, I’m going to get smarter and smarter and be able to take over more and more of what you need to get done.”

So I think it’s kind of like these are AI apps under training. When they grow up, they’re going to take over more and more of our tasks and allow the repetitive tasks to go away, so you can apply yourself to new, unique problems. But I think there’s a long time coming—

Sarah Guo

If you look at a lot of the platform shifts that have happened in the past—for example, with Microsoft OS, they eventually bundled the Office suite on top, right? Those were applications that were running on top. They ended up rebuilding or buying them, bundling, and cross-selling.

Elad Gil

Right. Travel and local and a variety of other areas.

Sarah Guo

Um—

Elad Gil

But they’re doing that in Workspace too, right? You guys are beginning to see Gemini show up, and, yeah, exactly. So actually, coding is a great example, right? OpenAI tried to buy Windsurf. Anthropic has Claude. People are trying to forward-integrate there. Claude also—or Anthropic—mentioned they want to forward-integrate into financial tooling right now.

Sarah Guo

Yes. Do you view this world as basically the platform—the big foundation lab companies—are likely to try and move into the biggest business verticals directly over time?

Nikesh Arora

That’s an interesting debate. So let’s go back and see why. Look, the reason you’re seeing developers as the first adopters is that they’re the most likely to experiment and to be able to work with half-baked outcomes. If you give me 75% of the code that I need, I can parse through it and figure out the remaining 25%, because that’s what I do for a living.

It’s much harder to do that in other professions, where we’re not fully in tune with all the guts of what we’re doing. So I think that’s an interesting place to start, and over time that workflow will go out into testing and other parts of the software development life cycle. So I think that’s kind of interesting.

I’ve had this conversation specifically with some of the people who are driving some of these larger LLM businesses, and I remember the very first phone call I made to Thomas. We talked about small models and large models, and he gave me good advice: “Don’t chase a cybersecurity model, but don’t chase a small model, because these large models become so much smarter that the smaller models will not be able to be as smart as these things.”

Elad Gil

That was sage.

Nikesh Arora

Yeah, yeah. That was very good. In the very early days, one of our competitors announced they were going to work on cybersecurity. If I go back and look, I’m pretty sure that was a great announcement. I don’t think anything has come out of it.

So we decided not to chase that because it didn’t seem to make sense. That was pretty sage. I do believe that, after a point in time—and I think you and I talked about this right before doing this—you were giving me great insight that the models are converging. Their reasoning capabilities are converging.

If you believe all these models are going to be extremely smart but somewhat similar in capability, the question—and I always say this to people—is, look, in the enterprise world, getting the smartest model in the world is like hiring the smartest PhD from the best university you can find in the world.

For that PhD to be useful at Palo Alto, we still have to teach them our ways, right? They’re not going to be useful when they walk in the door. They have to understand our context, they have to understand how we do things, and they have to understand how to take our problem and solve the problem.

Whether you call that pharmaceuticals or genetics, you have to make the model get smart about genetics. It’s a very smart model, but you have to give it a lot more training data in a particular domain for it to become really smart in that domain.

So I think the interesting opportunity will be: How can we take these models and apply them to domains where we have proprietary data? The developer use case is a generic use case. There’s enough code out there in the public domain that you can actually get 90% of the way to being smart at coding.

There’s not enough genetic data in the public domain, or pharmaceutical drug-discovery data in the public domain, or proprietary cybersecurity data in the public domain. So the question becomes: How do you take these models, how do you take that brain, and apply that to a domain to make it really smart?

I think the challenge right now is that if you’re building a wrapper, effectively, as an AI-as-a-service company, and all your wrapper does is enhance the capabilities of a model or put some guardrails around it, then your biggest risk is that the model slowly expands into those capabilities and you’re no longer in business.

The difference those companies are going to have from others that might survive is, if you look at every SaaS company, it’s actually the packaging of a workflow—the system of record, right? My HR system is a connection to the workflow. Every employee knows how to use that workflow, and every time it locks down a certain table and says, “This is your system of record. This is what Nikesh gets paid. This is when he took holidays. This is what his equity looks like. This is when he vests.”

It’s less about the app; it’s more about that data and that system of record. So eventually, if these apps have to live in the long term, they have to marry the capabilities of AI, which effectively becomes an enterprise system of record.

A model is not going to become my system of record. It’ll still be some proprietary, locked database somewhere, or some data tables—pick your pick. Maybe the interaction mechanism is no longer a workflow; it’s some sort of agent or some sort of AI interface that allows that system of record to be maintained and created. But there still have to be some rules.

So I think that’s where the opportunity is, as compared to just putting a wrapper around generic processing. Today, I’m going to help you analyze legal contracts. Well, guess what? I ran my legal contracts with ChatGPT, and it works just fine.

Where are we, actually, given your visibility into enterprises, in terms of actual adoption, value, and use cases?

Nikesh Arora

So I think the use cases—there are 2 current major use cases, right? One, let’s call it—what do you call it—generalized, or perhaps cross-enterprise, consistent activities. Right? Generalized, so—

Sarah Guo

To have a legal team.

Nikesh Arora

Yes. Do you have legal teams? Does every enterprise have a legal team? Yes. Do they have any particular proprietary knowledge compared to, you know, a particular LLM? Unlikely. It’s more that I need them for legal advice, not for Palo Alto advice.

In that use case, could we use a Harvey equivalent or whatever those are? Sure. It enhances their productivity. They get their 50% faster. Could I possibly, in the future, use some sort of AI-based interpretive application that helps me process my accounts payable faster and codify them? Sure.

There’s a whole bunch of repetitive, generic tasks across the enterprise that I’m pretty sure could be done by some version of an AI wrapper around an LLM, with some particular context or my data. To that extent, I think we’re all experimenting with those things, but my caution to my team is: don’t try and build it. Somebody’s going to build them for all of us. It’ll be much cheaper to rent them.

It might be by some metric of work or per seat, maybe an agentic seat. I don’t know. There’ll be some mechanism that they’ll charge us on, but we don’t have to build it because it’s going to cost me a lot more to build my own accounts-payable smart AI system than what I can buy off the shelf.

Elad Gil

Is that what your customers believe now? All the largest enterprises?

Nikesh Arora

I think many of them do, because this is not an easy problem to solve. First of all, finding the skill set and finding people who understand this means living in this world of constantly evolving models. You know this better than me: you can’t take one model out and put the next version in, and have it work exactly the same way. This is like getting a new PhD and training all over again, saying, “Let me explain how we work here.”

From that perspective, I think most rational players in the enterprise space—customers—would want somebody who’s the expert to build it, for us to have some version of adaptability to it, and to make sure it’s secure. None of us—no enterprise customer—wants their data floating in a multitenant environment, saying, “Oh my God, my data is training other people’s data.”

If it’s accounts payable, have a good time. You can understand how I codify stuff; have a good time. But if it’s proprietary data, when I’m doing FDA trials, I don’t want my FDA trial data training somebody else’s data. I think they’ll err on the side of caution and say, “I want my instance to be secured.”

We spend half our time, before we look at any of these packaged AI apps, talking to customers and understanding the security. I don’t want my source code to be training somebody else’s coding app. To that extent, there’s a whole bunch of conversation: Is it ring-fenced? Is my data mine? Are you using it to train your model? Are you using it to train your system?

We spend a lot of time testing it to make sure that they’re not doing it. A lot of time and effort is spent there. Not every enterprise is as discerning; we have to be because we’re in the security business. But I think you’ll see some version of stability and acceptance there, where people will take these generic, AI-as-a-service apps that are helping humans get better.

Mhm.

Nikesh Arora

Like, I don’t want my source code to be training somebody else’s coding app.

Sarah Guo

How do you think about that in the context of applications you think may make the most sense in cybersecurity? If I look at founder activity, there’s more and more activity around SOC. There’s a lot of activity around pentesting.

There’s activity around a lot of areas that are very human-intensive, and in some cases involve repetitive tasks, which make a lot of sense for this form of generative AI to take over. Then there are people incorporating AI into existing products, like Socket, for sort of a Snyk-like competitor, and other aspects of code security.

I’m curious, from your vantage point, what do you think are the most interesting areas of cyber AI?

Nikesh Arora

If you step back and think about cybersecurity, there’s a world of cybersecurity that operates by saying, “This is the known bad. I found it; let me stop it.” Sure, that’s a good thing. I found a bad actor; let me stop it. I found malware; let me stop it.

To be able to stop bad things from getting into your network, you have to be deployed on every sensor. The first thing a cybersecurity company says is, “Look, I can’t stop what I don’t see.” So I have to be present at every edge, every endpoint, and every sensor of your organization.

Five years ago, we made a conscious choice that our strategy should be to get into as many sensor locations or control points as we can. So we did that. We have a SASE product and an endpoint product.

I think the sensor business will have to stay, because if you’re not there, you can’t find anything. It doesn’t matter how much AI you have; you have to be there to find it. Sensors are pretty good at stopping the known bad. If it’s known bad, I stop it.

Most cybersecurity breaches happen because of the unknown bad, because we stop all the known bad. So everything you’re talking about is trying to find the unknown bad, or a vulnerability that has left the door open so bad guys can get in. That’s what a Socket- or Snyk-like competitor is trying to do.

Now, in cybersecurity, there are companies that are the sensors. A sensor allows you to do 2 things: stop the known bad, but also collect valuable data to analyze and understand what the unknown bad may be. So we get the benefit from both: we’re a sensor stopping the known bad, and we also collect a lot of data.

Traditionally in cybersecurity, people have been, I’ll call it, vertically integrated from end to end. They say, “Let me sit at the endpoint. I’m going to trap all the data around a particular topic. I’ll take that data into the cloud, analyze it, and then tell you, ‘Oh my God, I found something suspicious. Here are 5 suspicious things you should investigate.’”

But the problem is that I don’t have context. When the data passes my sensor, it’s gone.

Take a simple example: I send you an email with a phishing link. You click on it, and when you go to the website, I steal your credentials. Now, I’m an email security company. I see a bad email. I know how to stop it. I don't know it's a bad email and Elad clicks on it.

Now you’ve gone from my email product somewhere else in the company and gone to the internet through a firewall. I have no idea what you did. So all I can say is, “That link looks suspicious. I clicked on it. Maybe you want to investigate.”

No customer wants a list of 5,000 things they have to investigate. People are busy building these agents, saying, “Let me build an agent to help you investigate this and investigate that.” But I think the better answer is: if I had all the context of the enterprise, I could mine that data to find what actually happened.

We’re taking a different tack. We’re saying, “Let’s see if we can consolidate all the data in the enterprise.” If we can, we can run a whole bunch of machine-learning algorithms and do all these activities on top of that.

The current startups you mentioned are trying to do what AI wrappers are trying to do around LLMs. Over time, we’re going to get better and better, and we’re going to squeeze their capabilities out over time so that you wouldn’t need them.

Yeah. And there are a few different sets of them, because there are also the ones that are just trying to automate human services associated with the security world today. Pentesting would be one example, where you often hire external consultants to help with that.

SOC may be another one, where effectively you’re looking at the Security Operations Center across all the different events that are happening and trying to automate that.

Nikesh Arora

The reason you’re trying to automate the SOC from the outside in is because you’re not running 10,000 machines out at the ingestion point. Why should I first collect all the data and analyze it afterward? I should analyze the data and cross-correlate it at ingestion to make sure I understand the bad things, put them up there, and then build agents to investigate the bad things.

Elad Gil

Well, this is my question now: the environment in a large enterprise today is still very fragmented, right? They’re just doing this pass-the-hat trick that you’re describing with all these different tools. Hopefully, they’re very dominated by yours—

Nikesh Arora

But it’s all chosen by customers. “Dominated” is a bad word. You’ve worked once in a large company. You understand that in a highly competitive environment.

That’s right. Yes, of course. I was talking to a friend who runs security at a large financial institution, and he’s like, “We have 100—”

Nikesh Arora

Does he want some cybersecurity?

He’s definitely got some help on it; he wants more. But he’s got 118 identity tools, right? I didn’t think there were 118 identity tools.

Nikesh Arora

Identity crisis.

There we go. You’ve got to try it.

Nikesh Arora

So he bought an identity company to solve that. You’re all right. Maybe the answer is just to make it all cyber AI. But I think his view is that it’s untenable for him to consolidate all of this in the near term.

Yes. And so I’m going to attach something afterward that does the human consolidation.

Sarah Guo

Yes.

Elad Gil

Like the Silk automation thing, right?

Nikesh Arora

Yes. The interesting part is that we're the youngest industry in technology because cybersecurity did not exist before connectivity came about. Nobody had to—you were in a mainframe, you sat in the office, you connected the mainframe to a pipe into the back end, and you were off to the races. Nobody was actually going to come and intercept your traffic.

Sarah Guo

Scary before the web. Yeah.

Nikesh Arora

That's right. So the web and applications out there made it serious. It's a 25-year-old industry. Every time a bad problem showed up, somebody built a point solution to solve that problem.

Mhm.

Nikesh Arora

So it is a fragmented architecture. It's a fragmented environment. There's a lot of data being used and analyzed multiple times by multiple vendors because they were needed for that point in time. But like any industry, that capability commoditizes over time, right? There's no genius in building a firewall. Every firewall, within plus or minus 10%, does the same thing, right? Some things do it better.

The question is, what do you add on to? What capabilities can you build beyond that? So if you believe that, sure, in a stack, 80% of the capabilities are going to be capabilities that even most companies still don't have, and they can be delivered in one platform, then on the other 20%, we can add add-ons. But over time, we will eventually gobble those up because there'll be a new 20%.

Until 1 year ago, nobody was talking about AI security.

Now there are probably more companies than you can count who all show up at Elad's house saying, “Please give me some money. I'm starting a cybersecurity company for AI. I do prompt injection. I do malware checking on models. I do model data poisoning. Agentic attacks.” None of those things existed.

Nikesh Arora

Of course, you'll find people building features to protect against those because we're still too busy fixing the problems of the last 5 years, where the mass-market problems are. Over time, I think what you'll see is that the platform approach is going to eat into this feature approach. There are companies with cobalt code out there as well.

So, 118 identity vendors sounds like a lot. I didn't know there were 118 vendors, to be honest. He might have meant cybersecurity vendors, which I can believe—that's also a lot.

What new problems from AI do you actually pay attention to? What do you think is going to be a mass-market problem?

Nikesh Arora

Look, if you back up and believe your own rhetoric, then I, as a bad actor, should be able to unleash agents against an enterprise, against every aspect of it, and figure out where the breachable parts are or where the holes are.

Elad Gil

Mhm.

Nikesh Arora

In a matter of minutes, or less than an hour, I should be able to point my attack toward that vector. I should be able to run simulations on how to attack this thing, and I should be getting exfiltrated data.

When I started 7 years ago, the average time to identify a target, get through it, and exfiltrate data was in the 3- to 4-day timeframe.

Yeah.

Nikesh Arora

The fastest we've seen right now is 23 minutes. If the bad actor can get in and out and exfiltrate data, or shut down your endpoints with ransomware, in under an hour, then by physics your response time has to be less than an hour.

Mhm.

Nikesh Arora

The average response time is still measured in days. From that perspective, the biggest threat that AI brings is that it continues to compress the timelines to shut down your business, cause a compromise, cause ransomware, or cause economic disruption. I think the pressure just went up on our customers to get their infrastructure in order.

That's the risk and the opportunity.

Sarah Guo

Yeah, I think Elad mentioned pentesting, which hasn't traditionally been a very strategic part of the security landscape.

Nikesh Arora

Yeah, pentesting is just to knock down every part of your defense. I think half the companies don't do pentesting because they're scared of what they'll find. They're doing some minimum compliance level.

From a technology perspective, pentesting is trying to attack the area. There are companies like RunSybil now that do this. They can do it continuously, in the 23 minutes you describe. I'm like, that's exactly what an attack is—24/7/365 at Palo Alto. We don't hire third-party people. We run that as a default because that's our existence. If we get compromised or breached, we have a problem.

Elad Gil

Yeah.

Sarah Guo

You mentioned email. I think it's a well-known issue that a lot of breaches happen because of social engineering, because of email, because of credential takeover.

Nikesh Arora

89% of the attacks happen because of credential theft, right?

Elad Gil

Somebody becomes you or me. People like us aren't getting any smarter, and now you have models that improve 1% a day. How concerned are you about deepfakes, generated spear-phishing, voice attacks, and all that stuff?

Nikesh Arora

To the extent that they enable the act of social engineering, yes, those are concerning. I think most forms of two-factor authentication are going to be out the window. I won't say which bank, but I call them and they say, “Oh, can you please confirm your identity?” They ask me 3 arcane questions, which I'm pretty sure GPT or Gemini will be able to answer in under a second because they're only scouring the web to find public information about me and ask me questions.

I think all those forms of authenticating who you are are getting easier and easier to compromise. So the question becomes: Do you solve it their way or our way—as in, the way they're looking at it or the way we're looking at it?

At the end of the day, every one of these social-engineering attacks and credential takeovers eventually initiates some bad activity in the enterprise.

Mhm.

Nikesh Arora

The bad activity in the enterprise often takes the form of what I will call anomalous behavior.

Mhm.

Nikesh Arora

Suddenly Sarah decided to exfiltrate all the data in Elad's company. Even though she used to email with him every day, today she's logged in and downloading everything onto her laptop.

Sarah Guo

This actually happened last week.

Nikesh Arora

Thank you. Great deal flow.

Is there nothing suspicious in that?

Nikesh Arora

That sounds pretty suspicious. I can spend my time trying to make sure that nobody can take over Sarah's identity, or I can make sure that Sarah doesn't act anomalously. If she does, then I throw in a block at that point in time.

Elad Gil

Mhm.

Nikesh Arora

So I'm looking at life a different way. That's why we're buying this identity company. Identity companies today say, “Oh, I checked you in the door. You're fine.”

And now you can roam anywhere in my entire enterprise and do whatever you want because you were checked into the door. That doesn't work anymore. I have to make sure that I can now use compute and data, and AI is going to allow us to analyze all the anomalous patterns.

I can say, “That's pretty weird. She would never have done this in the last 7 years. Why is she doing this now? Does she have the rights to do it?” I can do just-in-time rights. I can stop you from accessing this stuff.

You have to change the name of the game. You can't do it the same way. So the whole idea of us buying an identity company is to think about life by saying, “Stop giving people persistent rights. Give them just-in-time rights. Give them rights that analyze for anomalous behavior.”

In fact, what I want to do is say, “I actually don't need you to give me a second-factor authentication. I can see the way you type.”

And if your identity starts typing differently, I'll block you.

So, one of the things you've done incredibly well at Palo Alto over time is start with a core set of products and then expand, really providing both the platform and the add-ons that you mentioned. Was that something you came into the company knowing you wanted to do? Is that something you ended up adopting over time? I'm curious how you thought about that puzzle.

Nikesh Arora

Well, Elad, you and I have worked together before, and I remember you were at Google—a smart young man—and that hasn't changed. I came to Palo Alto and analyzed a business problem: the product.

I came with 2 things. One, I understand business. Two, you know, Larry told me many years ago that if a technology company loses sight of the product, it decimates over time. That's been true across technology. Take your pick among the tons of companies that haven't made it.

The business problem in enterprise is that if you look at an enterprise company with less than $1 billion in revenue, 50% to 65% of costs are sales, marketing, and customer support, which leaves no room for margin. If you look at the largest enterprise companies, that number goes to 30%.

So it's all about taking that 70% and bringing it down to 30%, because R&D and G&A don't change much past $1 billion to $10 billion or $100 billion. You still maintain 12% to 16% of R&D costs, and if you're efficient, like some of the large players in the market, you're at 4% G&A, or you're at 6% or 8%.

Nikesh Arora

So your maximum leverage comes from sales and marketing, customer support, and marketing. And you realize what that is? It’s the ability to convince one customer that you’re really good at what you do and be able to expand in that customer’s environment with the trust that you can do more and more things for them.

So that’s the insight I came in with: Why is it that Sarah’s friend has 118 vendors in the infrastructure? Because each of them gets vetted. This is security. It’s not like buying some random thing on the side. There’s a big procurement process and a testing process, right? Because you could be a bad security actor, and it could take my whole enterprise down.

So if you go through that entire process of validation, verification, and trust, why shouldn’t I take the trust that the customer has given me, earn their trust, and expand my capabilities across the platform? So that’s the insight we came with and realized: We sell firewalls. “Hey, you want a firewall?” “No, I’m sorry. I’m good for the next 5 years.”

I had a sales guy who was focused on an account that was his target. He spent 3 months getting a meeting and going through the process. Now he doesn’t have anything to sell them. So, okay, you don’t want a firewall, you want this. You don’t want that; you’ve got this, you want this.

Eventually, enterprise salespeople have to have enough of an offering set that allows them to present something to the customers. The good news is that in cybersecurity, there’s always some transformation going on because some technology is coming to its end-of-life form, and the company hasn’t innovated. Then you’re off to the next set of companies.

So that’s the insight that came. Yeah, it’s a great insight. And if you actually look at the margin structure for some of these things that you mentioned—sales, customer success, support—a lot of those things now have AI apps that are making people dramatically more efficient. Do you view the future of those functions as being very AI-enabled and AI-heavy, or how do you think about that transformation across companies like Sierra, Decagon, Rox, and others?

Nikesh Arora

Yeah, I think I’ll answer the first half of the question. The second half is your domain and Sarah’s domain. I’m going to leave you to answer that question for him because I don’t know the answer for the other companies.

But I think, look, if you fundamentally look at organizational efficiency, perhaps the best word is that people are scared of AI-based efficiency. I seriously doubt that an AI agent will convince the CIO or CISO faster than my human who goes and hangs out with them and shows them the product. So I think my sales teams are very happy in their existence. They don’t believe they’re imminently threatened by AI, so that’s a good thing.

Interestingly, on the product-development side, I think people will be—

Just to come back to that—sorry, I interrupted you—but there are other forms of sales enablement: a deck per customer that you customize, or—

Nikesh Arora

Yes, sort of SDRs. Those are marginal. That’s process efficiency, which will come through it. But guess what? Before we get there, I’m probably going to need 15 AI-savvy people to build the workflow, because an AI model is not just going to spit out a Palo Alto SASE proposal by itself. It’s going to have to be trained.

Do you think that’s customer-segment-specific in terms of the leverage you can get? A lot of people think, for example, about the SDR-level seller, where you’re sending a bunch of emails, cold-calling, or doing things like that, where it’s a lower-ACV customer.

Nikesh Arora

Yeah, but I think that’s only one side of it, right? If you stick to SDRs, we’ll go back to the other problem in a second, but stick to SDRs. At what point in time does my email start getting read by an agent whose job is to block all SDRs? Block all people trying to sell me, because I’m overwhelmed by the number of people who think they should write to the CEO because they have some company with 5 people automating something.

That’s interesting. Does that actually decrease the effectiveness of those sales teams over time? In other words, if you effectively have agents screening things, does that create a block for certain types of sales leads?

Nikesh Arora

Well, I think the question of the sales lead isn’t the issue, right? The question is generally either I have a need, and I know it, in which case hopefully my blocking agent knows my needs and eventually says, “Ah, you know what? Actually, we’ve been looking for this thing, and here’s an email which satisfies our need. So maybe that’ll do it.”

Or, as we do in marketing, you never need a new watch and you never need a new car, but you just buy it because somebody put it in front of you. I don’t think it happens that way in enterprise. So we can’t generate demand for something when we don’t normally have a need, but sometimes you can in cybersecurity.

So, look, I think those will be marginal efficiency outcomes because how many SDRs do you have? Eventually, you do the selling. We do lead generation. We’re in a large enterprise business. We go through a large, rigorous testing process. So, yeah, I can get a phone call, but if my product doesn’t show up, then it doesn’t matter how good the lead was.

Yeah, it’s interesting because I haven’t thought of it as just becoming—if we have agents doing this sort of low-level communication first—it could just become a more efficient market for finding the problem-match, right?

Nikesh Arora

Yeah, maybe. So I think if you go back to the organizational-efficiency question, I was talking to my CFO this morning. I was like, “When are you going to take a whole bunch of stuff that you’re doing with human beings and replace them with some form of at least 50%-efficient agentic analytics or apps?” I think we’re going to get there.

I think the maximum replaceability will be in, let’s call it, administrative areas. I have 200 people doing documentation. Do I really need 200 people doing documentation? If models can do 90% of the work, they probably need AI-savvy people to write the guardrails around these models and templates, and they can prompt them.

So we’ll find some efficiency. Pick your number: 200, 300, 400 basis points of efficiency. The larger you are, the better you are, because you’re going to save more money.

I think sales doesn’t change as much. I think product innovation—the better companies will innovate faster.

I have technical debt. I’d love to get rid of a whole bunch of Salesforce code or a bunch of SAP code that I have, and get it more efficient. I can’t find good people to go to it because nobody wants to work on it, right? They’re all working on AI.

So can I get some version of agentic AI apps that are going to get rid of a few hundred of those people? Great. So I can get inefficient product-development ideas out of there, but I’m not going to let go of any good product person, because I’m going to get them to move faster. That’s my competitive edge.

I think we won’t see as much attrition in the vibe-coding outcomes or the product-development outcomes. You’ll just see faster innovation.

So basically, the statement that AI is displacing all human labor—that’s very overstated from your perspective?

Nikesh Arora

I think, on those 2 segments, customer support will have to go through that revolution. What I mean by that is, I always joke internally—I tell my people—customer support exists because we build bad products.

If you have great products, why would you have to have customer support? It’s complicated. It’s hard to onboard. It’s got too many dials, and that’s why it takes me so much time to make it, and then eventually it’s not efficient.

So we have most recently moved customer support closer to our product teams. I told my product teams: The day you have a bug, or the day you have a customer issue because of a product, fix that before you build a new feature.

I think, in concept, from a North Star perspective, we should be able to take 80–90% of customer support out in the next 2–5 years across the landscape. That’s what every good company should aspire to do. And when you take it out, it means your product quality should get better.

If I’m really using a good vibe-coding agent, why shouldn’t it write better code? If it’s writing better code, why shouldn’t it find flaws in my code much sooner? Why shouldn’t it run simulations?

So I’m expecting product quality to get better. I’m expecting the fixes to come faster. I’m expecting that we can diagnose the customer’s problem with data, as opposed to humans calling and asking all those questions.

Yeah, I think there’s a lot of anxiety from engineering leaders that product quality is not likely to get better. There’s just going to be way more of it—more bad-quality product? Or more—more just more product, right?

Nikesh Arora

That doesn’t mean it has to be bad product.

That’s fair. Yeah. I think the combination of generated code that people are not fully understanding from an architectural point of view, fully reading and reviewing, and that volume overwhelming the processes that we have today in software development is an anxiety.

Nikesh Arora

Let’s park that for a second. It is the worst right now that it’s ever going to be.

Exactly. It’s only going to get better. You’re the most optimistic security person I know. That’s great.

Nikesh Arora

Am I restricted to being optimistic in security?

Sarah Guo

Well, it’s not like a super-optimistic group. I’m just saying—

Nikesh Arora

Look, I think at the end of the day, being one of them, we have to do the best job we can, and then eventually life takes over. So it’s fine. But from a quality perspective, anecdotally, I have seen examples that have huge promise.

I’ve seen a coding agent find a vulnerability in security code at Palo Alto Networks that we wouldn’t have found unless it was out in the wild, which is a good thing for us. I’ve seen it take 500 lines of code and come back with 75 lines of code, which would have been much more efficient at doing the task that those 500 lines of code were doing. I’ve seen it come back with code explainability for code that was written 15 years ago. We can’t find the person who wrote it.

So there are some amazing examples of what the art of the possible is. If that’s just what we get today, I think 1, 2, 3 years from now, that stuff’s going to get better and better. So from that perspective, do I believe product quality gets better? I 100% believe that product quality gets better. I don’t think there is any debate on that topic right now.

It doesn’t look like there is a solution for stupidity in the world. So if you don’t have good people reviewing this stuff, then yes, you can end up with bad outcomes—not because AI is bad, but because you didn’t set up the right guardrails, the right process to do it. So I think we’re going to get good-quality outcomes. I think we’re going to see better and better capability.

I think the most vulnerable area in any enterprise is large numbers of humans doing repetitive tasks, which are either generic—which is the easiest to replace because everybody’s doing them; we don’t need them—or, even if they’re specific and have critical mass, if I have 2,000 people in customer support, I should be able to optimize a lot of that and hopefully deploy those people in much more meaningful things.

I imagine I have a child; you have children. Do you really want them to grow up and become customer support people and say, every time, “What do you do?” “I just pick up the phone and listen to somebody grumbling at the other end because something they bought is not working.” That sounds like a really horrible job. So I think those jobs should go away. What’s wrong with that?

And they don’t have the power to fix it.

Nikesh Arora

Yes, that’s worse. It’s like getting punched in the face and not being able to punch back. Somebody’s taught them, “The customer’s always right.”

Mhm.

Can we talk a little bit about leadership? You’re a very unique leader. This is a time of at least a handful of companies growing very quickly because they create value and do trades in billions of dollars.

Google from 2004 to 2014; Palo Alto Networks, 7 years in. You’ve added, like, the size of Palo Alto originally every single year since, in terms of enterprise value. That’s wild. What makes you a great leader in terms of growth at scale? What advice do you have for some of these people who are like Guinness Book of World Records in terms of growth in the first few years?

Nikesh Arora

Yeah, yeah. Well, as an optimist myself, I’d say AI wrappers or not, they’re creating a lot of value, and consumers and enterprise are buying very quickly.

Look, if you step back, it’s interesting. Every business that you’ve identified or you’ve looked at, we’ve talked about, has a much larger TAM than any of these companies are able to touch. The markets are growing. You have the opportunity to take share and grow in that market.

So I’m a huge fan of growth businesses. I hate the idea of restructuring something that’s on a declining curve. It would sort of scare me. So it’s good to find the right market from a growth perspective.

I always have this principle: Nobody wakes up in the morning and goes to work to screw up, or wakes up and says, “I went to my worst job possible.” No chance in hell. You can find people and get a group of people together. They can be innovative as hell and put a rocket into space faster than NASA.

These are all humans. They’re all people out there. There’s no difference between many of them and people who work at Palo Alto Networks or the people who work at Google or elsewhere. So what creates the difference between great companies and companies that are not as good? I’d say, within reason, you can find those people in every company.

I think it boils down to understanding the market, setting the right North Star, getting enough buy-in, talking about the why—not just the what you need to get done—getting people really excited and bought into it, and then making sure they have the resources to get their tasks done.

If you do that, then my job is to set the strategy, set the North Star, put the right people in place, and then basically act as their shield and keep blocking bad things or friction from slowing you down. If you can do all of those things, there’s a high probability you can create good outcomes. Never guaranteed.

Are there any unique structures, approaches, or tactics that you use that go against the grain? We’ve talked to Jensen a few times, and he’s pointed out, for example, that he has 40 direct reports. He doesn’t do one-on-ones. It’s a—

Nikesh Arora

I actually read that. I actually expanded my staff meeting from 8 to 25 after I read that.

It’s interesting, and it solves a different problem. At least in my case, I’ve discovered that I’m not always sure that these people communicate the why to their teams. So it at least eliminates one level of confusion: Why does he want this? “Oh, actually, I heard him directly. This is what he wants to get done.”

Sometimes you have this notion that you have to be a player, you have to be a coach. Sometimes you have to be directive, sometimes you have to be encouraging. It’s like, “We’re going to climb that mountain. We are going to climb that mountain.” If you go back and say, “We’re going to climb a mountain,” I promise people end up on that one.

So it’s important for people to understand the communication part. I’ve discovered that communication is actually underrated in organizations. Usually, the way I do my—call it a 360-degree test—is I meet 50 employees every 2 weeks and ask them questions.

Mhm.

Nikesh Arora

Then I discover, “Oh my God, these people are asking questions that I thought were abundantly clear: why we’re doing this, what we’re doing this for.” I discover eventually that by the time you get to the person 4 or 5 levels removed from you, they actually don’t understand exactly why we’re doing certain things.

They have fundamental questions around what we’re doing, and that causes them to do it differently or not do it. So that becomes an issue of communication: talking to people and making sure they’re all bought in.

I think from a business strategy perspective, we’ve taken a very different approach to M&A.

Right?

Nikesh Arora

We bought 27 companies so far. We’re about to buy our largest one, if we get approval and get it done. I don’t call it M&A. I call it product development and research in a highly innovative market where all of you guys are kind enough to support.

Yeah. Innovation. It’s distributed R&D. Exactly right. Distributed R&D.

Nikesh Arora

We’re in this service for you.

Well, you guys do reasonably well for that.

Nikesh Arora

So you can say thank you and I can say thank you. I say it’s like, if you don’t win, I don’t win. If you don’t win, I don’t win. It’s fine.

We’re happy to be in a situation where you get to a certain stage and we get it past that stage and take it to scale, because I don’t believe we have all the smarts in the world. There are lots of smart people out there who are trying to solve different problems, and I don’t believe we can solve all the problems simultaneously.

Take AI. We started off saying, “Oh my God, when AI gets deployed, enterprises are going to want to make sure that their AI instances are secured and controlled and managed because they don’t want data leaking. They don’t want external input.” So we built, effectively, what we called an AI firewall.

And we discovered this company—you know what? People are actually trying to figure out whether the models that they have are hackable and have malware in them. So we weren’t doing that. We were just protecting them once they were in there.

There’s a company called Protect AI, which was actually assessing models. They were doing persistent red teaming against the AI models specifically, not just the enterprise. Going back to your comment on red teaming, models morph; their responses are unpredictable and nondeterministic.

The same model could answer the same question one way today and could answer it differently 1 week later because it learned. Now, if you start getting nonpredictable responses, you have to inspect all the responses to make sure none of them is malware.

Yeah.

Nikesh Arora

Right. So from that perspective, we do persistent red teaming of models. We do scanning of models. They said, “Oh, we haven’t done it.” We found this company and we said, “Thank you very much to the VC community for delivering that from an R&D perspective,” and put them as part of our platform.

So we do rely on, like you said, R&D as a service from the VC community, and that’s been very helpful. But we always go for number 1 or number 2. We never believe that you can take 3 or 4 and spit and shine and make it look like 1 or 2, because 1 or 2 don’t go away. They’re treated as 1 or 2 for a reason.

Nikesh Arora

More often than not, we make the leaders of the acquired companies the leaders of our business because we believe they've acted faster than us in a much more resource-constrained environment, shown a tremendous amount of resourcefulness and hustle, and delivered outcomes in innovation. So I think, from that perspective, we probably have a higher hit rate in the industry than most other M&A that has happened in the enterprise space. So I think we do that differently.

Elad Gil

Yeah. At the beginning with Palo Alto, and continuing today, you have perhaps been more ambitious than any other security company.

Nikesh Arora

I think that's right. How do you convince an organization to be more ambitious? My understanding of the cyber industry before was that you had endpoint businesses and firewall businesses, very sort of domain-specific, right?

I don't think you have to convince humans to be more ambitious. I think we're natively and naturally ambitious. You meet somebody and say, "Can you do more?" I've never heard someone say, "I think I'm done." Everybody says, "I want more. I can do more." We live in a consumptive society; we're taught to aspire for more.

So I don't think it's hard to make people at Palo Alto feel that we have the right to play at a bigger table on a constant basis, and people actually like the idea of ambition and aspiration and winning. Trust me, if our stock wasn't up 6 or 7 times in the last 7 years, a lot more people internally would have questions on our strategy than they have now. So I think it's a self-fulfilling prophecy. It's a good thing across the board.

More fundamentally, if you step back, our industry is not fully formed. It has 118 vendors; it is fragmented. You take a look at the CRM industry, the ERP industry, and the HR industry. These things operate on single platforms, right? Nobody has 2 Salesforces deployed in the enterprise. Nobody has 2 Workdays deployed in the enterprise. Nobody has 2 SAPs deployed in the enterprise.

Why? Because you need end-to-end visibility, a singular workflow, and a singular set of analytics to solve the problem. Our industry started off because, "Oh my God, we have a threat. Block the threat. Don't worry." So we're playing whack-a-mole.

As I said, over time, as these requirements normalize, they somewhat converge in the capabilities of vendors. Then how does it matter if you take from one versus the other? What becomes more important? All these platform companies I talked about—it's not like they have unique features on a feature-by-feature basis compared to their competitors. Over time, those have normalized.

But what they do have is end-to-end visibility and capability that integrates the functionality. That's why they're there. So if cybersecurity has to survive in the long term as a mature industry, we also have to become a singular enterprise platform.

If you believe that, we're nowhere there. We used to have 24 products when I came. We had 4 when I came; we took it to 24. We had 44 Magic Quadrant and top-right mentions. We've turned that into 3 platforms.

I say, "If you're going on a journey with us, it's going to take you 2 to 3 years to get a platform deployed with 3 right now." Had we said 1—oh my God, your friend can't go from 118 to 1. It boggles his mind. So let's take him to 3 first, or 1 or 3, and hopefully get him to the next one. We get him a third one.

So I think the idea from our perspective is, if we can become the platform of choice in the industry, that's a very big ambition, a very big North Star. But you don't get there if you don't start.

Maybe when you look forward—for both Palo Alto, cybersecurity, and AI—what keeps you up at night? What do you think most about?

Nikesh Arora

I think most about AI. I'm glad we think about it. It's certainly something you do, right? I think more about AI from the vantage point that if our view of how this is going to evolve is not within the guardrails of where it's going to be, we may end up taking Palo Alto in a different direction. Remember, we exist to help you secure technological advancement in a certain direction before you fully deploy it.

Today, our conversation with some of the cloud providers was, "How is everybody thinking about agents? I'm supposed to secure agents." The problem is I can't get one person to agree with the other person's definition of an agent.

I'm like, "What's an agent?"

"Well, are you going to use MCP protocols to deploy?"

"Well, no, we just have connectors."

"What's a connector in an LLM?"

A connector is effectively an API call, a microservices call. Why are you using API calls? It used to be called an API call in the past. Why aren't you using MCP servers and clients?

"Well, we're going to get there," right? How are you going to do an inspection of identity?

"We're going to register the identity somewhere else."

How are you going to do delegation? There are so many questions from an execution perspective and from how the industry evolves that it's not quite what keeps me up at night.

We talk about this every day. We have a team of people getting together every day for 2 hours, and we read everything. We talk about it, saying, "What do you think about this? What do you think about that?" Because when you don't have an expert, then hopefully the collective wisdom of 6 or 7 smart people—those people who I bring together every week, 2 or 3 times—is probably better.

So we're constantly trying to paint a picture of how the world of AI is going to evolve. We're building our opinion, and based on that, we have to design a product.

Mm-hmm.

Nikesh Arora

So that's extremely bleeding-edge, right? And if we want to be the cybersecurity partner of choice, we have to be able to go with the bleeding-edge capability and tell our customer, "Look, you have a problem. We're solving it faster than anybody else, and we can help you deploy AI securely."

So that's kind of what's exciting. It's a little bothersome because you have to keep understanding. You have to think, like, "Holy—where was I just here? What do we do with that now?"

Yeah. As you've been thinking deeply about AI, have you thought about it from a broader societal perspective—the impact on the world? Are there specific threats that you think about most, worry about most, or feel most optimistic about?

Nikesh Arora

I'm going to stick with Sarah's characterization of me as one of the more optimistic people about these things. I'm going to expand that beyond cybersecurity.

I think it's exciting technology. You've been in Silicon Valley for a long time. You've been investing for so long. The intensity and the excitement are palpable, right? You can't turn around.

Sarah Guo

It's really fun again. Yeah.

Nikesh Arora

It's really fun again, right? You can have dinners, you can debate all kinds of arcane topics, and I'm pretty sure you can find lots of people with different opinions. There are so many different directions you can go. You can talk about policy implications, you can talk about wrappers, you can talk about LLMs, and you can talk about infrastructure.

It's like a whole new technological wave, which has so many implications and majorly disruptive implications. From that perspective, I think it's exciting. Does every technology come as a double-edged sword? Of course it does. Every revolution in history has come as a double-edged sword, so why not this one?

You have to believe in the power. There are more good people in the world than bad people. The good people will hopefully continue to make sure that the bad things get controlled.

Now, are some bad things going to happen? Most likely. Are we going to find a way around it? Most likely, and hopefully. We powered through a pandemic, for crying out loud.

Elad Gil

Mm-hmm. Awesome. Thank you, Nikesh.

Nikesh Arora

Yeah. Thank you so much. Thank you for your time. Appreciate it.

No Priors | 对话 Palo Alto Networks CEO、前 Google 首席商务官 Nikesh Arora — 文字稿与摘要 | BidClub