Palo Alto Networks CEO: "AI Found 5 Years of Bugs in 6 Weeks"
Key insights
Companies
- Palo Alto Networks - Arora's company; built Mythos, the AI tool that found 5-7 years of code vulnerabilities in 6 weeks; closed a $25B identity-security acquisition 3 months before this taping
- Google - Arora spent 10 years there (former chief business officer); he argues Google is underrated and could be the first trillion-dollar company, citing its sales-force scale
- OpenAI - Referenced for model releases (4.8, 5.5) and the framing that its profit pools are in applications like Codex, not the base models
- Anthropic - Referenced for Claude, its cyber-capable model release, and its faster ARR growth versus OpenAI from going all-in on enterprise
- IBM - Announced a $5B project to fix open-source software vulnerabilities
- Salesforce - Cited as an example of a SaaS marketplace app category that AI can replace by querying the underlying data directly
- SAP - Cited as a source of inventory data an enterprise would want unified with sales data for AI-run analytics
- Databricks - Named as infrastructure software that Arora sees as undervalued relative to analytical SaaS
- Snowflake - Named alongside Databricks as core data-storage infrastructure that will stay valuable
- MongoDB - Named as core database infrastructure that will stay valuable
- Oracle - Named as core infrastructure and as a system-of-record example agents will eventually interface with directly
- Dell - Cited as an example of hardware demand cycling back after being written off, now near a $300-400B market cap
- Silver Lake - Arora previously advised the firm when hardware, including Dell, was considered a dying category
- Change Healthcare - Ransomware breach that shut down physician offices nationwide, used as the example of the real national-security risk (small, under-resourced operators, not hardened critical infrastructure)
- UnitedHealth - Had to issue billions in credits to physicians after the Change Healthcare ransomware breach
- Uber - Arora sits on Uber's board and declined to give an assessment, praising CEO Dara Khosrowshahi
- Waymo - Praised for reliability; Arora says it should expand to more cities faster
- Goldman Sachs - Cited among financial-services firms that avoid the cloud because of latency sensitivity
- JP Morgan - Cited among financial-services firms that avoid the cloud because of latency sensitivity
- Morgan Stanley - Cited among financial-services firms that avoid the cloud because of latency sensitivity
- Netflix - Cited as an example of consumer subscription revenue stacking up faster than people realize
Techniques and frameworks
- Mythos - Palo Alto Networks' AI system for assessing code vulnerabilities; in 'ultra mode' (persistent thinking) it can daisy-chain vulnerabilities into full attack paths
- False positive / false negative rate framing - Arora's lens for why raw model capability isn't enough for enterprise use; an early model's ~30% false positive rate makes it unusable for defense despite being usable for attack
- Analytical SaaS vs. infrastructure vs. system-of-record - Arora's three-way framework for how AI hits different software categories differently: analytical SaaS dies, infrastructure software is undervalued, system-of-record software gets re-engineered over 5 years
Summary
Nikesh Arora, CEO of Palo Alto Networks for nearly 8 years (market cap up from roughly $17B to $238B over that stretch), joins the All-In hosts to walk through what AI capability is actually doing inside a large enterprise, starting with his company's own AI code-scanning tool, Mythos. In 6 weeks of testing, Mythos found what Arora says would have taken 5 to 7 years of human effort to uncover, for a token cost in the low millions, and in "ultra mode" it can chain individual vulnerabilities into full attack paths. He's direct that this cuts both ways: the same capability that lets Palo Alto find its own bugs faster is roughly 3 months, not 6, from being available to attackers in the open, since frontier model weights are now small enough to fit on a USB stick and get distilled elsewhere within days.
Arora spends real time on why raw model capability isn't the whole story for enterprise defense: an early model he cites had a roughly 30% false-positive rate, which makes it useful for finding attack paths but unreliable for triage, since a third of "vulnerabilities" flagged aren't real. He generalizes this to any high-stakes automated decision (insurance claims, self-driving cars) and argues the unglamorous work of driving false positives toward zero, not chasing newer model releases, is where most enterprise AI engineering effort actually has to go. On national security specifically, he reframes the risk: 89% of breaches trace back to stolen credentials, not novel exploits, and hardened critical infrastructure is already well defended. The real exposure sits with small, under-resourced operators, illustrated by the Change Healthcare ransomware breach that froze physician offices nationwide and forced UnitedHealth to issue billions in credits.
The conversation's second half is a software-market thesis. Arora splits enterprise software into three buckets: analytical SaaS is "over," because once a company's data is unified, pointing an LLM at it directly beats paying for a dedicated analytics app; infrastructure software (Databricks, Snowflake, MongoDB, Oracle) is undervalued, since enterprises will need roughly 10x the data storage within 3 years; and system-of-record software (Salesforce-style systems of work) will be re-engineered over the next 5 years as UI disappears and agents interact with backend data directly. He backs this with a live example: Palo Alto killed a SaaS tool only 3 of 20 licensed seats were actually using, wired the underlying data into Slack and Claude, and cut that spend by 90%.
On where the money actually goes, Arora argues profit pools sit in the application layer, not in the base models, pointing to OpenAI's Codex and Anthropic's Claude Code as the parts of those companies actually "running away" with growth. He expects an intermediate layer of application companies to form that arbitrage between models and specific business problems, a layer he says hasn't fully crystallized yet. He also pushes back on the assumption that AI shrinks headcount, saying Palo Alto currently employs more technical staff than ever because AI is forcing transformation across every function at once. He closes on his own M&A logic: after years of buying product companies and running them through Palo Alto's go-to-market engine (most recently a $25B identity-security acquisition closed 3 months prior), he now sees a path where proving superior AI-driven operating margins (90s gross, 40s net) becomes the justification for acquisitions well outside cybersecurity's traditional lane.
Notable Quotes
"In 6 weeks we found vulnerabilities which would have normally taken us 5 to 7 years to find." - Nikesh Arora
"If you're an analytical SaaS company, it's over." - Nikesh Arora
"The entire weights of their most recent model can fit on a USB stick. That's the IP." - Nikesh Arora
"89% of breaches happen because of simple things... credentials get stolen." - Nikesh Arora
"I think we're going to have more people at Palo Alto on the technology side than we've ever had before because I think AI is causing everything to ask for a transformation." - Nikesh Arora