Palo Alto Networks CEO:AI在6周内找出5年的漏洞
Chamath Palihapitiya × Jason Calacanis × David Sacks × David Friedberg × Nikesh Arora
- Arora认为,Mythos级别的代码分析已经成为现实,可将数年的网络安全工作压缩到数周。 Palo Alto Networks用6周进行测试,发现了通常需要5至7年才能找到的漏洞,成本仅为“低几百万美元”;持续运行“ultra mode”后,还可能将多个漏洞串联成新的攻击路径。他认为,类似能力将在3个月内进入野外,即使现在还没有发生。
- 分析型SaaS已经“结束”,因为企业可以直接让语言模型处理自己的数据。 Jason提到,他所在公司把一个无人使用的20席位产品缩减为3个账户,将数据接入Slack和Claude,账单降低90%;下一步是把销售、生产力和SAP库存数据放在一起查询,而不是分别购买分析模块。
- 随着AI摧毁上层分析层,基础设施软件的价值反而会上升。 Arora预计,未来3年企业存储的数据量将增加10倍,Databricks、Snowflake、MongoDB和Oracle等数据库与平台将因此受益。工作系统和记录系统已经深度嵌入企业,但未来5年,它们的界面和工作流可能围绕智能体重建。
- 模型层正走向按量计费的公用事业经济,而应用层将吸收利润池。 买家会以截然不同的价格购买不同级别的智能,应用公司则在模型之间进行调度,并提供企业所需的工具链、记忆能力和面向具体业务的可靠性。最快的收入路径,是替代一项已有预算的产品,或向消费者按每用户约$5收费。
- 由于攻击场景可以容忍防御系统无法接受的错误率,网络风险正在不对称上升。 Arora称,MSO的误报率约为30%——用于发现潜在攻击路径很有价值,但用于理赔或保护车辆则是灾难;而他的业务目标是0.01%,最终达到0%。与此同时,89%的攻击或数据泄露仍始于凭证被盗,而不是复杂漏洞利用。
- Arora认为,Google有望成为首家1万亿美元公司,因为它同时拥有模型、资产、基础设施和企业分销能力。 单靠模型质量无法拿下客户;推动采用所需的销售力量掌握在超大规模云厂商手中。硬件也不会消失,因为金融服务业的低延迟、高吞吐工作负载无法在不牺牲经济性的情况下简单迁移到云端。
- PANW由AI驱动的经营杠杆可能扩大其并购范围。 Arora描述了过去收购产品公司、再通过PANW的上市引擎推动销售的打法。如果PANW能以高得多的效率运营企业,收购什么的重要性就会下降;Jason将潜在经济模型概括为90%区间的毛利率和40%区间的净利率。Arora希望用6至12个月观察企业AI最终如何落地。他的保留意见是:AI转型可能需要更多技术员工,而不是更少。
1. Mythos将数十年的糟糕代码变成即时攻击面
Arora的框架始于Google Search让信息民主化;如今AI正在“让智能民主化”。它可能让250名营销人员的产出保持90%的一致性,也可能让5,000名面向客户的员工都接近那个人人点名要合作的同事的水平。
PANW的6周Mythos测试发现了漏洞;按其既有流程,这些漏洞需要5至7年才能被挖出——尽管Arora认为PANW的代码测试能力已处于行业顶尖百分位。测试成本处于“低几百万美元”区间,而持续运行“ultra mode”后,单个漏洞还可能被串联起来,形成一条穿过整家公司的新攻击路径。
主持人提出红队挑战:如果这种能力泄露出去会怎样?Arora给出的估计非常直接:“我们距离那一步还有3个月,如果现在还没有发生的话。”主持人原本估计是6个月;Arora提到了模型4.8和5.5,并指出攻击者不需要攻破最难的目标,一个老旧的工业边缘系统就足够了。
随之而来的竞赛,是防守方在攻击者利用漏洞之前发现并修补它们。被问到防守方做得如何时,Arora回答:“没有我们本该做得那么好,这对我们的业务非常好。”Jason说,CISO们同时要应付供应商补丁、自有代码,以及一个没人真正知道该如何解决的开源软件问题。
2. 网络安全最脆弱的环节,是普通的经济基础设施
Arora不接受把每个威胁都描述成前沿模型战争:89%的攻击发生,是因为凭证被盗。“我不认为我们需要更多模型去破解这些东西”——普通的用户名、密码和被忽视的系统,已经提供了足够多的入口。
他更担心的不是防守严密的国家安全目标,而是运行打包软件的牙医或医生诊所。Change Healthcare遭到攻击后,医生办公室无法正常运转,UnitedHealth不得不提供数十亿美元的抵扣额度;这就是经济混乱的模板。
“不存在万能解法”:系统必须持续升级、续期和修复。漫长的修复周期会“提高这个行业的终端价值”;而有效的AI防御要求企业收集大约10倍的网络安全数据,让模型学习组织记忆、上下文,以及正常行为与恶意行为之间的区别。
误报是区分“令人印象深刻的模型”和“可靠防御”的门槛。Arora称,MSO的误报率约为30%;他认为这对攻击来说“很棒”,对防御来说却“糟糕透顶”。企业级工具链必须把10%-20%的错误率推向0.01%,网络安全最终则要逼近0%,同时不能牺牲对漏报的控制。“我不会让我的孩子”坐上一辆错误率为10%的自动驾驶汽车。
3. 分析型SaaS已死,但基础设施更有价值
Arora的判断是绝对的:“如果你是一家分析型SaaS公司,那就结束了。”当客户可以直接让LLM处理底层数据时,那些收集客户数据、再把分析作为增量市场模块卖回去的产品,就失去了存在理由。
Jason给出了一个具体案例,也体现了其中的经济账:他的公司原本有20个SaaS席位,几乎没人登录,但数据本身仍然有价值。公司保留3个账户,把产品接入Slack和Claude,让所有人通过自然语言与其交互,并将账单削减90%。
最终形态,是把销售代表表现、生产力和SAP库存放在同一数据层中,从而回答过去需要跨越3个SaaS产品才能提出的问题。因此,Arora认为基础设施“被低估”:如果企业在未来3年持有10倍的数据,Databricks、Snowflake、MongoDB、Oracle、数据库和存储都将受益。
Arora把中间这一类称为“工作系统”或“记录系统”,认为它们已经深度嵌入企业运行方式。但如果智能体能够工作,UI可能会消失:智能体应当提取销售电话内容、更新Salesforce或Oracle,并自动完成文书工作。他预计,未来5年,整个工作系统和记录系统都将被重新发明。
4. 模型成为公用事业,应用层吸收利润
Arora预计,模型将变成一个公用事业层,企业可以“随时购买智能”:日常工作使用更低智能、低成本的模型,更复杂的任务则对应高得多的价格。客户电话并不总是需要最新、最昂贵的模型。
主持人问,OpenAI和Anthropic是否应该成为新的Microsoft Office。Arora的答案是,专业应用公司会在模型之间进行调度,并打包工具链、记忆能力和工作流——因为50,000家公司需要相似的应用,不应该各自重建一遍。
Arora称,一家模型公司的CEO曾告诉他,最新模型的完整权重可以装进一根USB盘;他称权重就是“IP”。随后Jason提出,数据可能在24到48小时内完成蒸馏并复现模型,但这是Jason的框架,不是Arora的判断。
Arora认为,在全球竞赛中限制前沿模型发布3到6个月,并不能解决安全问题,因为其他人可以把相当的模型发布到开源社区。编码已经成为第一个爆发式应用,网络安全是另一个显而易见的利润池,而数百亿美元规模的传统应用软件正等待重构。他看到最快的两条收入路径:替代一款已有预算的现有产品,或向每名消费者用户收取约$5——“替代型应用很美”。
5. Google拥有冲击1万亿美元的资产,硬件也将持续存在
Arora以“临时CEO”的视角称,Google被低估了,并有能力在他们有生之年成为首家1万亿美元公司。他的逻辑是分销:即使模型最好,也需要销售团队说服企业采用;而3家超大规模云厂商已经拥有最大的销售队伍。
硬件仍是处理低延迟、高吞吐数据的最低成本方式。大型金融机构仍在使用硬件,因为把金融服务工作负载迁移到云端会增加延迟,而“如果延迟上升,利润就会下降”。
瓶颈在生产而非设计:GPU数据中心建设潮已经让零部件和工厂排期堆积。Arora估计,重建美国供应链可能需要10年,但这场“人生级的暴利机会”以及100亿美元至1000亿美元不等的承诺,可以为新产能提供资金。Friedberg补充称,加速折旧也是激励的一部分,资本开支可以在第1年100%抵扣。
6. AI可能扩大PANW的并购范围,同时推高员工数量
PANW最初的并购打法,是买下产品公司、重构其后端,再通过自身的上市引擎推动销售——把一段1,000万美元的客户关系变成潜在的2,000万美元关系。Arora称,这套方法曾推动公司市值超过1,500亿美元;之后PANW在判断身份系统对智能体和安全用例重要后,收购了一家250亿美元的公司,该交易已于3个月前完成。
新机会更广:如果PANW能利用AI运营一家效率高得多的企业,其经营利润率可能足以超过行业水平,从而让更大范围的并购变得可行。Jason将潜在经济模型概括为90%区间的毛利率和40%区间的净利率;Arora认同,如果公司能破解这套模式,收购什么就没那么重要了。
Arora表示,公司需要接下来的6至12个月观察AI最终如何落地,以及它能多有效地用于企业,然后再扩大业务菜单。他也否定了简单的削减劳动力叙事:PANW如今的技术员工数量,比没有AI时本来会拥有的数量还多,因为AI正在推动全公司的转型。
This might come as news to you, but humans have been writing bad code for a very long time.
I spent 10 years at Google and you know, Google search was democratizing information. If you take that analogy and think about what AI is doing, AI is democratizing intelligence.
Money is a way to keep track.
Yeah. It’s not the goal. You’ve been the CEO of Palo Alto Networks for 8 years?
Coming up on 8 years this week.
And I think when you started, it was a $17 billion market cap, if I remember correctly.
Thereabout.
And this morning I checked, and it’s $238 billion. If you listen to what we said yesterday, now that you’ve passed $100 billion, you’re more likely to actually 10X. So the first 10X was much, much harder. You’re on your way to a trillion dollars.
From your mouth to God’s ears.
Well, I think you are. Okay, let’s double-click into what you see, because you’re in a really interesting position to see all of it. You see the birth of AI. Maybe you’ve seen the rise and fall of SaaS.
The rise again, right?
The rise again. You were one of the first—and one of the few—to get access to Mythos. So let me just push the button. Go, Nikesh. Start.
First of all, thank you for having me here. I think AI is exciting. It’s exciting to see all the stuff that’s gone down in the last possibly 24 months. I think Sarah just said it: they were right in anticipating the huge amount of compute that was going to be needed. So all that stuff is going on.
But you can see this notion, which we talked about briefly last time, that AI is really democratizing intelligence. What that means is, I have 250 people in marketing. They produce varied forms of output. Now you can get 90% of the output to be consistent across those 250 people. I have 5,000 people who talk to customers. My failure mode is when 5,000 people do different things, where people say, “I want to talk to Joe because he knows how to solve the problem and Jim doesn’t.” Now you can get 5,000 people to act almost consistently in their interactions with people on the other side.
I think it’s going to have a phenomenal impact on how we run businesses and how we operate. It’s going to change the entire landscape. In that context, you touched upon Mythos, and Dave has been very involved with this. Mythos has shown us that all the bad code that humans have written over the last 50 years can be assessed by AI, and the vulnerabilities can be shown. We tested it for 6 weeks, and in 6 weeks we found what would have taken us 5 to 7 years.
Wow. Say that one more time.
In 6 weeks, we found vulnerabilities that would normally have taken us 5 to 7 years to find.
So, Mythos—but these are vulnerabilities where? In your own code base, your customers’, or your own code?
Sorry?
These are vulnerabilities in your own code base or in your customers’ code?
Oh, wow.
So Mythos was not oversold. It was legitimate.
The capabilities of AI to assess vulnerabilities in code are real. Not just that: if you put it on ultra mode, which is persistent thinking, so it keeps trying until it gets an answer, you can actually daisy-chain vulnerabilities—that is, find a new attack path into your company through your vulnerabilities.
We pride ourselves on being in the top percentile of companies that test our code because we’re in the cybersecurity business. If you take that and compound it across all the companies that exist in the world that write their own code, or the 10 million developers who write code, this thing is going to find stuff that would have taken us 10 years to find.
How much did it cost? Did you track the token cost? Was it $100 million, $10 million?
No, it was in the low millions. But again, as Sarah said, the cost curve is going to come down. Already, OpenAI has a model that’s cheaper and more consistent. Anthropic has come out with another model—
You buy the hype.
It’s not hype. It’s true.
That’s the point. The capabilities are—
The capabilities are true.
Yes. I mean, you saw IBM announce a $5 billion project to fix open source. That’s the biggest problem.
What would have happened if Claude didn’t have the restraint and they put it out in public? Do you think it would have been a real attack vector and caused chaos in corporations?
We’re 3 months away, if not already there, from this being available in the wild.
Okay, open source?
Yeah, just 3 months.
Yeah. Yeah, because we’ve been saying that it’s roughly 6 months away before Mythos-level capabilities are available in Chinese models, open models, whatever. But you’re saying it could be 3 months.
Well, look, 4.8 is already out, and 5.5 is already out. They have similar capabilities. You don’t need to crack the hardest code to crack. You just need to find a few vulnerabilities in code that’s out there. Take an old industrial system that’s running OT code on the edge. You can find that vulnerability reasonably easily.
So we’re in a race right now between the cyber defenders finding these vulnerabilities and patching them before the cyber attackers do the same thing.
Yes.
How do you feel like we’re doing in that race?
Not as well as we should be doing, which is great for our business, but that’s a different story.
So every company has to go look at its code base, figure out where the vulnerabilities are, and fix them. If you talk to CIOs today, their biggest problem is that all the vendors are showing up saying, “Please patch my piece of hardware that you have. Please patch my code that you have, because I found vulnerabilities. Fix it.” Meanwhile, the CISOs are busy finding their own vulnerabilities to fix, and then there’s this huge thing called open source that nobody quite knows how to solve.
Is it fair to say that as model capabilities go up, systemic business risk for large enterprises also goes up?
On the cyber side, yes. There are antidotes being built by people like us and others, where we’re going to provide some capability so you don’t have to patch everything. But cyber has done something very interesting around harnesses, memory, and context.
The part we don’t talk about here is that organizations don’t have memory and context of everything they do every day. That’s why you need to store a lot more data enterprise-wide to learn what good looks like and what bad looks like.
Right. The same problem is in cybersecurity.
We need to collect 10 times the data in the enterprise from a cyber perspective to be able to understand how to defend ourselves against AI attackers.
Do you think that traditional companies, like the SaaS businesses that have existed in this world, still have a place? As all this knowledge becomes more persistent and stored, what happens to SaaS?
Well, you see, SaaS is, as Bill said, different pieces, right?
Okay.
If you’re an analytical SaaS company, it’s over.
It’s over. What is an analytical SaaS company?
Somebody that says, “I’m going to collect a lot of data for you and analyze it for you.” I don’t need you to analyze it for me. I can run models against the data and analyze it myself.
Every SaaS company has a marketplace. You can buy from the Salesforce marketplace. What do they say? “You have Salesforce data. I’m a marketplace app. Take me, and I’ll help you analyze the data.” I don’t need you.
You don’t need that.
I can just run an LLM against the data. So the entire incrementality that has been sold as incremental software modules to all of us doesn’t need to be sold to us, because I’d much rather have LLMs running against that.
Interesting you bring this up. We had an instance with a SaaS product with 20 seats. Nobody was logging in and using it, but the data was there. So we created 3 accounts, got rid of 17, connected it to Slack, connected it to Claude, and now everybody can interface with it through natural language, and we’ve reduced our bill by 90%.
Well, not just that. What are you going to do next? As Jason said, you’re going to take data from different products, put it in one place, and run the analytics against that. I want my data for my sales reps, my productivity data, and my inventory data from SAP. I want it all in one place so I can run analytics against it and say, “Who’s selling a lot? Where do I have less inventory? Let’s build inventory in a region where my salespeople are extremely productive.”
To run that query, you’d have to have talked to 3 different SaaS products. Tomorrow, you can put all the data in one place. So that’s sort of category one.
Okay, category one: analytics is dead.
Yes. In the medium term, all these bolt-ons today and tomorrow are marginally irrelevant. Infrastructure software is undervalued.
Okay, what is infrastructure software?
Stuff that gives you databases. You collect data into it. Stuff that allows infrastructure to work, whether it’s database software—
Databricks, Snowflake, like that?
Databricks, Snowflake, MongoDB, Oracle—all these things. You need core storage infrastructure and core data.
You're going to need 10 times the data stored in an enterprise than we have today. Right—3 years, 10 times. So, anything that helps you collect infrastructure data and manage it, you need.
I think the category in the middle is called—let's call it—system of work or system of record. Those are deeply embedded in the way businesses work. I have 6,000 salespeople; they know how this works.
What's going to happen is, step 1, we will take away the UI and let agents do the work. UI in enterprise software and consumer software is the worst thing we did as technologists.
You had a couple of examples of this. You told me this story—I don't know if you want to repeat it—of this one company that tried to hold you hostage on a license.
You just pointed AI at it and you just—
Yes, that was analytics SaaS, so that's over. That's a different issue. But think about it. Today, we spend our lives having product managers design UI so all humans can interact with data behind the UI.
Yeah.
If you believe agents are going to work, I can just tell an agent, "Look, figure out from my sales call the key points and go post it into whatever sales-tracking system I have, whether it's Oracle or Salesforce." Conceptually, an agent should be able to do it.
We're spending $1 trillion building these agentic backends. We need these agents to be able to do it. If that happens, UI goes away. If UI goes away, I can rewire my system of work.
Right.
My sales guy should have to say, "I had the sales call. Do all the paperwork and all that needs to happen in the back of the company, and I'm done."
And it's also happening passively, which is really interesting. It's looking at email, it's automatically taking the Zoom transcript and summary. So, the sales system of record is now—you don't even need to input it. It's like, "I already have the Zoom call notes. I have the deck. The deck was made, the sales deck was made by AI."
We're all going to be looking at a chat window and just saying, "Here's what I want."
Your audit trail becomes a lot better because humans are not touching your data. It's always being managed by agents, so I think the whole system of work, system of record, gets reinvented in the next 5 years.
Yeah, there's no data entry. That's an interesting point. Let's talk about national security for a second. I just want to maybe zoom out. So, one side of Mythos, as you said, is the value that it has to you and to enterprises. The red-team version of Mythos is where foreign state actors can essentially create economic havoc inside of a country.
Yes.
As these models escalate in their capability, what do you think should happen when these models are ready?
The sad truth is, there are a few thousand breaches or attacks that happen. They happen for pretty rudimentary reasons. It's not because somebody cracked a hard-to-crack thing. It happens because 89% of attacks happen because credentials get stolen.
Or your username and password.
That's it.
I bet my password is password.
Yeah, I'm sure it is. Did you have a dollar sign?
Dollar sign password.
Fantastic. Well done. See? You're already ahead of everybody else.
So, 89% of breaches happen because of simple things. I don't think we need more models to go crack this stuff. Now, these models can attack critical infrastructure and things we try to protect from a national-security perspective. Yes, we need defenses there.
I'm not worried about the national-security part being protected because they're very on it. They're the right people. They spend 10% of their budgets on IT security. I'm worried about the small offices across the country where they're using some piece of packaged software, and you're running a dentist's office or doctor's office.
Remember when Change Healthcare got breached?
Every physician's office shut down.
Shut down, and it's ransomware.
Because of ransomware at Change Healthcare.
That was the clearinghouse system. That's when UnitedHealth had to actually give billions of dollars of credits to the physicians to be able to run their businesses at that point in time.
That's what one should worry about. It's less about—
The big nuts will get cracked.
—about cracking some PG&E power-generation facility. It's more economic chaos. Yes. And so, what do we do?
I don't think there's a silver bullet. I think this will basically take a while until every system gets upgraded, renewed, and fixed over time. I just think it increases the terminal value of the industry.
Do you think that there's a world in which these models become so good that you could see yourself advocating for more nationalism around how they're controlled, how they're managed, and where we point them? Or do you think there should be a set of these models that never see the light of day, that only the NSA and other folks get access to, or guys like you?
I have a slightly differentiated view about models and how they will evolve versus what we heard earlier from an OpenAI perspective. I still believe models are going to become a utility layer. You'll be able to buy intelligence on the fly.
You can say, "I don't need a 180-IQ person to go do this task. Give me a 120 IQ, and I need a 250 IQ to do this task. I'll pay $10 for this, or for this I'll pay 1 cent." So, I don't know that there's a one-size-fits-all model that gives you the most up-to-date intelligence to answer my customer call, saying, "Sorry, sir. I have no idea how to solve your problem."
I think models will get differentiated from a utilitarian perspective. If you look at what's already happening in the market, the profit pools are in applications, not in models.
Sarah talked about Codex running away. She didn't say OpenAI is running away. She just said Codex is running away. I'm sure Dario says Claude Code is running away. So, you're seeing that—
They're attacking profit pools.
They're attacking profit pools because that's where the money's going to come from. The profit pools are in applications that companies can use. The profit pools are not in model usage by companies because most companies have no idea how to use the models.
Are these companies, in a way—OpenAI and Anthropic—the new Microsoft Office, coming in and doing all applications, all productivity software for organizations?
No, I see there's going to be application companies that are going to arbitrage between models and solve your business problem. If I'm a company, I don't want to write every piece of software myself. I want my HR system software, which is agentic-enabled and AI-enabled, to be delivered by some application company. It'll be a new AI application company.
I want my sales-management system built by the new agentic AI sales force of the world, whether it's Salesforce or somebody else. I want applications. Now, what Sarah said is the profit pools are in the application layer. That's why they want to be the application layer.
I think we're still waiting for that layer of companies to be invented or created, where applications will sit. Fifty thousand companies need the same application. Why would I build it myself? It's highly inefficient. It's silly for me to use OpenAI directly and rewrite my entire sales system because I'm smart. Right? I'm not. I want somebody to do it for me.
I think that layer of companies is still not fully formed.
So, we're going to be waiting for it.
Control plane, a harness, and then—
That's right. They will build the harnesses and the memory into those application layers. Now, the question is, how big is the application layer? Is it one application? Is it one enterprise application that does everything, or is it a specialized application?
And you kicked out this software vendor. You did it because they were being abusive in pricing. So, that—
Use a different vendor.
What's that?
We swapped out for a different vendor. We just took more control.
Love it. So, it really is a pricing issue. That's why the SaaS apocalypse, in some ways, makes sense. They're not having pricing power because you could say, "Well, I'll just put 10 developers on this and I'll save $10 million."
Yes.
I think the part goes back to what Chamath said about regulation, or whether you want to regulate these higher-powered models. The question is, at some point in time, when these newer models, which are even more powerful, get built, they will come at a different price point, and they might have to go through a certain vetting process to understand what their capabilities are.
But I think we're in a global race. I don't think holding back our models for 3 to 6 months is going to help us any. Somebody else is going to put them out in open source. I was shocked to hear, when I was talking to the CEO of one of these model companies—
He says, “The entire weights of their most recent model can fit on a USB stick.”
Say that again.
The entire model weights of their newest model fit on a USB stick. That’s the IP.
That’s incredible, because all the data can be distilled in under 24 to 48 hours and the model comes out. I’m curious.
That’s the IP. So, are you telling me that we can hold on to that for 6 months?
Right. We have a debate about how difficult it is to make a frontier model. Some companies are starting to think about making frontier models using their data advantage to build their own. Have you thought about that at Palo Alto? It does seem like you have proprietary knowledge on how security works. Could you build your own large language model or an SLM, a small language model, that would give you some advantage in the future?
One thing that nobody talks about is the false-positive rates on the models. What is the false-positive rate on 4.8 and 5.5?
No idea.
You guys don’t talk about it. You should. The false-positive rate on MSO was 30%.
Oh, wow.
Right? So, it thought it found something, but it hadn’t.
Yes.
The problem is, it’s great for attack and horrible for defense. You find something 30% of the time that says, “I found a problem,” and you say, “Let’s plug the hole.” Wait, there wasn’t a hole there in the first place.
No missile inbound.
Right.
Yeah.
The same problem applies in enterprise. If you use a model without the right harnesses and the right training, you could be running into 10% or 20% false-positive rates. Let’s use the model to pay, I don’t know, insurance claims.
Yeah.
Oh, great. A 10% or 20% false-positive rate. I just lost money. The sycophantic nature of these is ridiculous, too.
So, the problem is not who wants the newest model. The problem is, how do you take that model with a 20% or 10% false-positive rate and make it a 0.01% false-positive rate? In my business, I want 0%.
Without losing the false negative.
Sorry?
Without losing the negative—the false negative.
Yes, but it’s like saying, “Hey, let’s take the new self-driving car. Mercedes is going to use Opus 4.8, and you can just sit in the car and it’s going to drive you.” I’m not putting my kids in that car with a 10% false-positive rate. Are you?
There’s a lot of work that happens after a model, which needs to happen to make this thing useful and effective in the business context.
Let me slightly pivot for a second. You were, for a very long time, the chief business officer at Google. You were the president of SoftBank. Now you’re the CEO of Palo Alto Networks. So, let’s play armchair CEO.
Armchair CEO.
I’m still bristling from David Friedberg trying to create a distinction between founder CEOs and non-founder CEOs. Just saying, David.
By the way, false positives.
Sorry?
And false negatives, too.
Give us what you would keep, what you would change, and what you like about the following companies.
This is going to get recorded and put out there. I don’t know.
Give us your thoughts. You’re one of the smartest business people.
You don’t get to live with the glory of these All-In podcast sessions.
Ready?
Yeah, sure.
Okay. What you keep, what you change, what you like, and what you don’t like. Uber.
I’m on the board of Uber. I’m not going to talk about Uber.
I didn’t know that. Sorry. Okay.
Dr. Dara—he’s the CEO. He’s a great guy.
Okay. Waymo.
You’re trying to get me fired.
Waymo.
What do I like about Waymo? The cars work. It’s amazing. They should have more in many more cities around the world, faster. I would say that at the rate I’m going, I’m going to be fired.
Google.
I think Google’s underrated. I think it’s going to be the first trillion-dollar company in our lifetime. I think they have all the assets that are needed to make this successful.
People underestimate that you can be a model company, but you still need to have a sales force that convinces customers to go out there, embrace these models, and buy them. If you think about it, the 3 hyperscalers have the biggest number of salespeople out there, so they should—
One of the reasons why they’re a little bit undervalued is just the conglomerate nature. It’s hard to understand.
I don’t know. You guys are smarter than I am. I’m just a hired-hand CEO.
I didn’t say that. Reed said that. Let’s just be clear.
I know. I know.
I was providing a thesis on recovery out of the SaaS pack, let’s just say.
Okay. Okay. Got it.
Just to be clear, there’s a way to segment that basket, okay? And you’re not in that basket.
I thought you were making a distinction about how founder CEOs have the right to take more risk and are allowed to take more risk.
I wasn’t saying that. I think you provide a unique counterpoint to that, and there aren’t a lot of people like you. I think the same would be true of Jeff Weiner. I think there are a few other really great CEOs, but they are like Neo in The Matrix—type anomalies.
I think you’re one of those people. There’s a very rare kind of personality profile of someone who’s willing to take risk and take ownership of something that wasn’t theirs in the first place and make it theirs. It’s an extraordinarily unique trait, far more unique, actually, than being a scalable founder.
That’s an incredible save.
You’re forgiven.
Yeah, good save. Incredible save. Back to armchair CEO.
Wow, that was incredible. He’s more sycophantic than ChatGPT. He’s like, “Actually, I’m actually the best.”
Let’s go back to armchair CEO.
I’m liking this. He should use OpenAI more often.
OpenAI.
They should sell faster, right? They should sell faster.
I mean, you said it. Didn’t you just say it when Sarah was here, that—
Anthropic seems to have improved its ARR much faster than OpenAI.
I mean, that’s just the statistics.
They kind of went all in on enterprise.
I think that’s the conversation right now. It’s a race to take over the profit pools. If you’re going to need tens and tens of billions of dollars every year to get—what is that? 1 gigawatt is 10 billion of revenue.
It costs $50 billion, so this is not a great deal.
So, what are the most exciting profit pools, then?
You’ve got coding. That’s been the breakout application over the past year. It’s massive. You’ve got infrastructure, like you said, the new databases. I think cybersecurity is clearly one of them because of the threats and the patching cycles being so much more dynamic.
There’s a slight difference. As you can see, these models are trying to be the enablers of better cybersecurity, which is good because all of us need to use them to test. You’re probably going to see—I mean, Anthropic has already made its cyber-capable model generally available, so everyone can use it. OpenAI has one. I’m sure Google has one, too.
They understand this is a place where CISOs, or chief information security officers, want to use it to test the code. So, this is another profit pool. I think we haven’t seen the onslaught against the application-software companies yet.
There are tens and tens of billions of dollars in application software waiting to get reinvented, as we talked about. I think eventually you’ll see these people saying, “What if I took this $40 billion, $50 billion, $100 billion TAM down? I can build a whole brand-new backbone with generative AI, and it would be so differentiated that it would cause customers to move.”
We’re seeing it as a playbook in the accelerators now. The year-zero and year-one companies—people are coming to us with the pitch: “This is $1,000-a-seat-per-year, $500-a-month-per-seat SaaS software. We can do it for less. We’re going to charge them based on consumption. We’re going to take 80% or 90% of the cost out as—”
What are the 2 fastest places to make revenue?
The 2 fastest places to make revenue? In enterprise, replacement apps. If you replace something I already have a budget for, it’s easy. I take something bad, I replace it with something better, and I get money. Replacement apps are beautiful.
If you can replace an industry or replace a profit pool, it’s great. The second place is consumer revenue. It’s a lot easier to get $5 per user on the consumer side.
Netflix.
So, that’s where—I mean, look at it. I think we collectively probably pay more on subscriptions per month than we ever did historically, and you thought your cable bill was high.
Yeah. Do you think that you’re going to end up building more or less hardware in the future, if you had to guess?
Hardware, even today, is the cheapest way to manage low-latency, high-throughput bits. You still need a data center.
Yeah.
What’s a data center doing? It’s just managing high-throughput, low-latency bits.
Yeah.
That’s why, if you look at financial services, it’s the most reluctant industry to go to the cloud, because you increase latency.
If you increase latency, you reduce profit. So, if you look at every one of your largest financial services companies, whether it’s Goldman or JPMorgan, Morgan Stanley, or these guys, they’re using hardware. Try to get them to run their business in the cloud; they can’t because they’ll have higher latency and lose money.
Right.
So, hardware is still being made. I remember when I used to advise Silver Lake, and I had thought Dell was done. Nobody wanted hardware. I think Dell might be back to a $300–$400 billion market cap. So, hardware is still going to be around. We’re going to need it. It’s the fastest way to move it.
Are our hardware development cycles changing because of AI? Are you seeing a lot of generative design stuff moving in silicon that historically was manual and long-cycle?
Yeah, but the long pole in the tent is the design, right? The long pole in the tent is production. Today, you can’t get a box produced because every piece of hardware componentry is backordered. Everything’s expensive, and every factory in the world is backordered because we’re trying to build all these GPU-based chip cards for every data center in the world.
Do you think the U.S. is equipped to fill that supply chain need? Can we do that here, or do you think we’re just done?
10 years.
With a firm top-down commitment.
Well, I mean, the good news is that I think the hardware industry is seeing a bonanza of a lifetime. Generally, when you see a bonanza of a lifetime, you can go commit $10, $20, $50, or $100 billion. I’ve seen a CEO on television committing to a $100 billion plan to build more memory. So, that’s good. That means they have the money to put the money in the ground, literally, to build these things for the future. So, I think that gets us more certain.
I think the tax incentive has a lot to do with that. The accelerated depreciation on the capex—you get a 100% write-off in the first year, right?
Just a final question as we wrap up. Over the last 8 years, you’ve grown organically very aggressively, but you’ve also been pretty acquisitive. You’ll take shots, and they’ve generally worked. So, you have a ton of permission in the market. When you hear what Bill Ackman said about how there are these kind of overbeaten companies, there are a few that get celebrated, that’s a ripe pool for you to pick from.
But some of that would require you to go maybe a little horizontally far afield, some would say. How do you maintain the discipline, or do you see yourself at some point considering things that are not nearly so much right down the middle of cyber?
So, I’ll tell you what. Until about a year and a half ago, we used to buy product companies and throw them into our go-to-market engine. We could rewire their back end so they could work better with our go-to-market engine. So, for me, if I’m selling $10 million to a customer, next time I go to them later, if I can sell them $20 million, it’s the most efficient way for me to amortize my go-to-market spend, right?
So, that was the model. We ran that playbook to north of $150 billion. Then we got to a point where we said, “Oh, we see an inflection arriving in identity. It’s going to be important from an agentic perspective, a security perspective.” So, we bought a $25 billion company, which we closed 3 months ago.
Um now it's actually a very different opportunity has presented itself. And the different opportunity sort of goes like this. If you can be the best at leveraging AI to run the most efficient enterprise business in the world, your operating margin can be far in excess of the industry. And if you can if you can crack that code
Gross and net, you’re saying? Gross in the 90s, net in the 40s.
Yeah, if you can crack that code, then it doesn’t matter what you buy.
Yeah.
I think the problem right now is the execution problem. Most subscale companies cannot afford to optimize their company and run it better. So, if we can run our company much better than everybody else and have a higher operating margin, then the Street will say, “Fine.”
Your first M&A was really tough, no? They were pretty skeptical, and then you kind of shoved it in their face.
They were pretty skeptical when they found a guy who didn’t know cybersecurity, didn’t know enterprise, show up, who worked at Google. The track record of people leaving Google and being successful out of Google is still—
Yeah.
—varied.
So, basically, you’re saying the menu’s open.
I think we need the next 6 to 12 months to figure out how this AI settles down and how we can use that effectively in enterprises. I think, if you think about it, people keep hoping that we’ll need fewer people to run companies. I actually have a counterview.
I think we’re going to have more people at Palo Alto on the technology side than we’ve ever had before because I think AI is causing everything to ask for a transformation. So, I have more technical people today than I would have had if AI didn’t exist.
Thank you, guys.
Thank you, sir.