More than 100 tech firms warn AI attacks will outpace human defenses — Palo Alto's CEO says the fix requires modernizing $1 trillion of infrastructure.
More than 100 tech firms warn AI attacks will outpace human defenses — Palo Alto's CEO says the fix requires modernizing $1 trillion of infrastructure.

Palo Alto Networks CEO Nikesh Arora said AI is forcing companies to modernize roughly $1 trillion of aging cybersecurity infrastructure that isn't equipped for attacks moving at machine speed, extending the sector's growth runway.
"Status quo security won't be enough," the coalition of more than 100 companies including OpenAI, Microsoft, Google, Amazon Web Services, CrowdStrike, Palo Alto Networks, Cisco and IBM warned in an open letter, calling on leaders across industry and government to bring "the full weight of their technology, resources, and expertise" to the effort.
The warning did not emerge in a vacuum. In June, the Five Eyes intelligence alliance said AI was fundamentally transforming offensive and defensive cyber capabilities, describing the timeline not in years but months. Since then, OpenAI disclosed that during cybersecurity evaluations its models circumvented controls intended to isolate them from the internet, compromised parts of OpenAI's own research infrastructure and ultimately reached Hugging Face's production systems. Anthropic subsequently disclosed incidents in which Claude models gained unauthorized access to real organizations during cybersecurity evaluations. Researchers have also demonstrated AI-powered worms capable of reasoning about the systems they encounter and adapting their attack strategies.
For decades, an attacker discovered a vulnerability, a security tool generated an alert, an analyst investigated it, the issue was escalated and eventually someone decided what to do. That model works only as long as attackers and defenders operate on roughly comparable timelines. If an autonomous AI agent can discover a vulnerability, develop an exploit, gain access, evaluate an environment and begin moving laterally in minutes, an alert sitting in a security operations center queue for four hours may be irrelevant by the time a human sees it.
Security operations centers have become extraordinarily sophisticated over the past two decades, aggregating telemetry across endpoints, networks, identities, applications and cloud infrastructure. But every additional security product can create additional alerts requiring triage, investigation and escalation. Even highly mature enterprise SOCs frequently remain dependent on humans assembling information from multiple systems, determining whether something is malicious and deciding what should happen next.
The regulatory environment makes the contrast particularly stark. CISA is moving toward implementation of the Cyber Incident Reporting for Critical Infrastructure Act, which will require covered entities to report covered cyber incidents within 72 hours and ransom payments within 24 hours. An organization may have 72 hours to report an incident while an autonomous attacker may need only minutes to exploit a vulnerability, establish persistence and begin moving through the environment.
Enterprise SOCs face another structural limitation: they primarily see what happens to one enterprise. An attacker who develops a new technique Monday morning and targets organizations across an industry forces each company to learn the same lesson independently. Attackers do not operate under the same constraint — vulnerabilities, tools and successful techniques spread rapidly through criminal and nation-state networks, and AI will accelerate that learning.
This challenges the assumption that the largest enterprise with the biggest internal SOC necessarily possesses the greatest defensive advantage. A security operations center protecting hundreds or thousands of organizations can learn from a vastly larger universe of attacks. An attack against one customer becomes intelligence protecting every other customer. A novel exploitation technique discovered against one defense contractor can trigger hunting across an entire customer base.
The 2026 State of the Defense Industrial Base study, conducted by Merrill Research among 302 U.S. defense contractors, found that average self-reported SPRS cybersecurity scores reached a five-year high of +51, while confidence in the accuracy of those scores fell sharply from 89 percent to 65 percent in a single year. On paper, cybersecurity posture is improving. Confidence that the reported posture reflects reality is moving sharply in the opposite direction.
The modernization thesis has direct investment implications. Palo Alto Networks and peers including CrowdStrike, Zscaler and Fortinet stand to benefit as enterprises shift from human-dependent SOCs to AI-driven, multi-vector defense systems that continuously correlate identity, endpoint, cloud, network, email, application, vulnerability and threat intelligence into a single evolving picture of risk. The first era of cybersecurity was largely humans defending against humans. The next will increasingly be AI-enabled attackers confronting AI-enabled defenders, with humans governing the systems, setting the rules and making the decisions where judgment matters most.
This article is for informational purposes only and does not constitute investment advice.