Palo Alto Networks CEO: "AI Found 5 Years of Bugs in 6 Weeks"
Chamath PalihapitiyaJason CalacanisDavid SacksDavid FriedbergNikesh Arora
- Arora says Mythos-level code analysis is real, compressing years of cybersecurity work into weeks. A six-week Palo Alto Networks test found vulnerabilities that normally would have taken five to seven years, for “low millions,” while persistent “ultra mode” could daisy-chain flaws into new attack paths. He believes comparable capability will be in the wild within three months, if it is not already.
- Analytical SaaS is “over” because enterprises can point language models directly at their data. Jason described cutting an unused 20-seat product to three accounts, connecting its data to Slack and Claude, and reducing the bill by 90%; the next step is querying sales, productivity, and SAP inventory data together rather than buying separate analytical modules.
- Infrastructure software becomes more valuable as AI destroys the analytical layer above it. Arora expects enterprises to store 10 times more data within three years, supporting databases and platforms such as Databricks, Snowflake, MongoDB, and Oracle. Systems of work and record are deeply embedded, but their interfaces and workflows could be rebuilt around agents over the next five years.
- The model layer trends toward metered utility economics while applications capture the profit pools. Buyers will purchase different levels of intelligence at radically different prices, while application companies arbitrate among models and supply the harnesses, memory, and business-specific reliability enterprises need. The fastest revenue comes from replacing an existing budget or charging consumers roughly $5 per user.
- Cyber risk rises asymmetrically because attack uses can tolerate errors that defensive systems cannot. Arora said the false-positive rate on MSO was about 30%—useful for finding possible attack paths, disastrous for paying claims or protecting a vehicle—whereas he wants 0.01% or ultimately 0% in his business. Meanwhile, 89% of attacks or breaches still begin with stolen credentials rather than sophisticated exploits.
- Arora argues Google can become the first $1 trillion company because it combines models, assets, infrastructure, and enterprise distribution. Model quality alone does not close customers; the hyperscalers possess the sales forces required to drive adoption. Hardware also persists because low-latency, high-throughput financial-services workloads cannot simply move to the cloud without sacrificing economics.
- PANW’s AI-enabled operating leverage could widen its acquisition aperture. Arora described the old playbook of buying product companies and pushing them through PANW’s go-to-market engine. He said that if PANW can run a much more efficient enterprise, what it buys matters less; Jason framed the possible economics as gross margins in the 90s and net margins in the 40s. Arora wants six to 12 months to see how enterprise AI settles. His caveat: AI transformation may require more technical employees, not fewer.
1. Mythos turns decades of bad code into an immediate attack surface
Arora’s framing starts with Google Search democratizing information; AI is now “democratizing intelligence.” It could make output 90% consistent across 250 marketers and give 5,000 customer-facing employees something closer to the performance of the colleague everyone specifically requests.
PANW’s six-week Mythos test found vulnerabilities that its existing process would have taken five to seven years to uncover—even though Arora considers PANW a top-percentile code tester. The cost was in the “low millions,” and persistent “ultra mode” could daisy-chain individual vulnerabilities into a new attack path through the company.
The hosts’ red-team challenge—what happens when this capability escapes—produced Arora’s blunt estimate: “We’re three months away, if not already there.” Although the hosts had assumed six months, he cited models 4.8 and 5.5 and noted that attackers need not crack the hardest target; an old industrial edge system is enough.
The resulting contest is defenders finding and patching vulnerabilities before attackers exploit them. Asked how defenders are doing, Arora answered, “Not as well as we should be doing, which is great for our business.” Jason described CISOs as juggling vendor patches, their own code, and an open-source problem that nobody quite knows how to solve.
2. Cyber’s most fragile edge is ordinary economic plumbing
Arora resisted framing every threat as frontier-model warfare: 89% of attacks happen because credentials are stolen. “I don’t think we need more models to go crack this stuff”—ordinary usernames, passwords, and neglected systems already provide ample openings.
His larger fear is not a heavily defended national-security target but the dentist or doctor running packaged software. When Change Healthcare was breached, physician offices stopped functioning and UnitedHealth had to provide billions of dollars in credits; that is the template for economic chaos.
There is “no silver bullet”: systems must be upgraded, renewed, and repaired over time. That lengthy remediation cycle “increase[s] the terminal value of the industry,” while effective AI defense will require enterprises to collect roughly 10 times more cyber data so models can learn organizational memory, context, and the difference between normal and malicious behavior.
False positives are the barrier between impressive models and dependable defense. Arora said the false-positive rate on MSO was about 30%; he called that “great for attack” but “horrible for defense.” Enterprise harnesses must push 10%-20% error toward 0.01%—and cyber toward 0%—without losing the false-negative performance. “I’m not putting my kids” in a self-driving car with a 10% error rate.
3. Analytical SaaS is over, but infrastructure gets more valuable
Arora’s categorical call: “If you’re an analytical SaaS company, it’s over.” Products that collect a customer’s data and sell analysis back as an incremental marketplace module lose their purpose when the customer can run an LLM directly against the underlying data.
Jason’s concrete example carried the economics: his company had 20 SaaS seats, almost nobody logged in, but the data remained valuable. It retained three accounts, connected the product to Slack and Claude, let everyone interface with it through natural language, and cut the bill by 90%.
The end state combines sales-rep performance, productivity, and SAP inventory in one data layer, enabling questions that previously crossed three SaaS products. Arora therefore calls infrastructure “undervalued”: Databricks, Snowflake, MongoDB, Oracle, databases, and storage benefit if enterprises hold 10 times more data within three years.
Arora calls the middle category the “system of work” or “system of record,” and says it is deeply embedded in how businesses operate. But if agents work, UI could go away: an agent should extract a sales call, update Salesforce or Oracle, and complete the paperwork automatically. He expects the whole system of work and record to be reinvented over five years.
4. Models become utilities while applications capture profit
Arora expects models to become a utility layer where companies buy intelligence “on the fly”: routine work could use a lower-IQ, lower-cost model, while harder tasks command a much higher price. A customer call does not always require the newest, most expensive model.
The hosts asked whether OpenAI and Anthropic should become the new Microsoft Office. Arora’s answer: specialized application companies will arbitrate among models and package harnesses, memory, and workflows—because 50,000 companies need similar applications and should not each rebuild them.
Arora said one model-company CEO told him that the complete weights of the newest model fit on a USB stick; he called the weights “the IP.” Jason then suggested that the data could be distilled in 24 to 48 hours and the model reproduced, but that was Jason’s framing rather than Arora’s claim.
Restricting frontier releases for three to six months will not resolve the safety problem in a global race, Arora argued, because somebody else can release comparable models into open source. Coding is already the breakout application, with cybersecurity another obvious pool and tens of billions of dollars in legacy application software awaiting reinvention. He sees two fastest routes to revenue: replace an incumbent product whose budget already exists, or collect roughly $5 per consumer user—“replacement apps are beautiful.”
5. Google has the assets for $1 trillion, and hardware endures
Playing armchair CEO, Arora called Google underrated and capable of becoming the first $1 trillion company in their lifetime. His mechanism was distribution: even the best model needs a sales force convincing enterprises to adopt it, and the three hyperscalers already possess the largest sales forces.
Hardware remains the cheapest way to handle low-latency, high-throughput bits. Large financial institutions still use it because moving financial-services workloads to the cloud adds latency, and “if you increase latency, you reduce profit.”
The bottleneck is production rather than design: components and factories are back-ordered by the GPU data-center buildout. Arora estimated rebuilding the U.S. supply chain could take 10 years, although the “bonanza of a lifetime” and commitments ranging from $10 billion to $100 billion can fund new capacity. Friedberg added that accelerated depreciation is part of the incentive, with a 100% first-year write-off for capex.
6. AI could widen PANW’s acquisition aperture while increasing headcount
PANW’s original acquisition playbook bought product companies, rewired their back ends, and pushed them through its go-to-market engine—turning a $10 million customer relationship into a potential $20 million one. Arora said that approach carried the company north of $150 billion before it bought a $25 billion company after identifying identity as important for agentic and security use cases; the deal closed three months earlier.
The newer opportunity is broader: if PANW can use AI to run a much more efficient enterprise, its operating margin could exceed the industry’s enough to make a wider range of acquisitions viable. Jason characterized the possible economics as gross margins in the 90s and net margins in the 40s; Arora agreed that if the company can crack that code, what it buys matters less.
Arora says the company needs the next six to 12 months to see how AI settles and how effectively it can be used in enterprises before expanding the menu. He also rejected the easy labor-reduction story: PANW has more technology employees today than it would have had if AI did not exist, because AI is prompting transformation across the business.
Full transcript
This might come as news to you, but humans have been writing bad code for a very long time.
I spent 10 years at Google and you know, Google search was democratizing information. If you take that analogy and think about what AI is doing, AI is democratizing intelligence.
Money is a way to keep track.
Yeah. It’s not the goal. You’ve been the CEO of Palo Alto Networks for 8 years?
Coming up on 8 years this week.
And I think when you started, it was a $17 billion market cap, if I remember correctly.
Thereabout.
And this morning I checked, and it’s $238 billion. If you listen to what we said yesterday, now that you’ve passed $100 billion, you’re more likely to actually 10X. So the first 10X was much, much harder. You’re on your way to a trillion dollars.
From your mouth to God’s ears.
Well, I think you are. Okay, let’s double-click into what you see, because you’re in a really interesting position to see all of it. You see the birth of AI. Maybe you’ve seen the rise and fall of SaaS.
The rise again, right?
The rise again. You were one of the first—and one of the few—to get access to Mythos. So let me just push the button. Go, Nikesh. Start.
First of all, thank you for having me here. I think AI is exciting. It’s exciting to see all the stuff that’s gone down in the last possibly 24 months. I think Sarah just said it: they were right in anticipating the huge amount of compute that was going to be needed. So all that stuff is going on.
But you can see this notion, which we talked about briefly last time, that AI is really democratizing intelligence. What that means is, I have 250 people in marketing. They produce varied forms of output. Now you can get 90% of the output to be consistent across those 250 people. I have 5,000 people who talk to customers. My failure mode is when 5,000 people do different things, where people say, “I want to talk to Joe because he knows how to solve the problem and Jim doesn’t.” Now you can get 5,000 people to act almost consistently in their interactions with people on the other side.
I think it’s going to have a phenomenal impact on how we run businesses and how we operate. It’s going to change the entire landscape. In that context, you touched upon Mythos, and Dave has been very involved with this. Mythos has shown us that all the bad code that humans have written over the last 50 years can be assessed by AI, and the vulnerabilities can be shown. We tested it for 6 weeks, and in 6 weeks we found what would have taken us 5 to 7 years.
Wow. Say that one more time.
In 6 weeks, we found vulnerabilities that would normally have taken us 5 to 7 years to find.
So, Mythos—but these are vulnerabilities where? In your own code base, your customers’, or your own code?
Sorry?
These are vulnerabilities in your own code base or in your customers’ code?
Oh, wow.
So Mythos was not oversold. It was legitimate.
The capabilities of AI to assess vulnerabilities in code are real. Not just that: if you put it on ultra mode, which is persistent thinking, so it keeps trying until it gets an answer, you can actually daisy-chain vulnerabilities—that is, find a new attack path into your company through your vulnerabilities.
We pride ourselves on being in the top percentile of companies that test our code because we’re in the cybersecurity business. If you take that and compound it across all the companies that exist in the world that write their own code, or the 10 million developers who write code, this thing is going to find stuff that would have taken us 10 years to find.
How much did it cost? Did you track the token cost? Was it $100 million, $10 million?
No, it was in the low millions. But again, as Sarah said, the cost curve is going to come down. Already, OpenAI has a model that’s cheaper and more consistent. Anthropic has come out with another model—
You buy the hype.
It’s not hype. It’s true.
That’s the point. The capabilities are—
The capabilities are true.
Yes. I mean, you saw IBM announce a $5 billion project to fix open source. That’s the biggest problem.
What would have happened if Claude didn’t have the restraint and they put it out in public? Do you think it would have been a real attack vector and caused chaos in corporations?
We’re 3 months away, if not already there, from this being available in the wild.
Okay, open source?
Yeah, just 3 months.
Yeah. Yeah, because we’ve been saying that it’s roughly 6 months away before Mythos-level capabilities are available in Chinese models, open models, whatever. But you’re saying it could be 3 months.
Well, look, 4.8 is already out, and 5.5 is already out. They have similar capabilities. You don’t need to crack the hardest code to crack. You just need to find a few vulnerabilities in code that’s out there. Take an old industrial system that’s running OT code on the edge. You can find that vulnerability reasonably easily.
So we’re in a race right now between the cyber defenders finding these vulnerabilities and patching them before the cyber attackers do the same thing.
Yes.
How do you feel like we’re doing in that race?
Not as well as we should be doing, which is great for our business, but that’s a different story.
So every company has to go look at its code base, figure out where the vulnerabilities are, and fix them. If you talk to CIOs today, their biggest problem is that all the vendors are showing up saying, “Please patch my piece of hardware that you have. Please patch my code that you have, because I found vulnerabilities. Fix it.” Meanwhile, the CISOs are busy finding their own vulnerabilities to fix, and then there’s this huge thing called open source that nobody quite knows how to solve.
Is it fair to say that as model capabilities go up, systemic business risk for large enterprises also goes up?
On the cyber side, yes. There are antidotes being built by people like us and others, where we’re going to provide some capability so you don’t have to patch everything. But cyber has done something very interesting around harnesses, memory, and context.
The part we don’t talk about here is that organizations don’t have memory and context of everything they do every day. That’s why you need to store a lot more data enterprise-wide to learn what good looks like and what bad looks like.
Right. The same problem is in cybersecurity.
We need to collect 10 times the data in the enterprise from a cyber perspective to be able to understand how to defend ourselves against AI attackers.
Do you think that traditional companies, like the SaaS businesses that have existed in this world, still have a place? As all this knowledge becomes more persistent and stored, what happens to SaaS?
Well, you see, SaaS is, as Bill said, different pieces, right?
Okay.
If you’re an analytical SaaS company, it’s over.
It’s over. What is an analytical SaaS company?
Somebody that says, “I’m going to collect a lot of data for you and analyze it for you.” I don’t need you to analyze it for me. I can run models against the data and analyze it myself.
Every SaaS company has a marketplace. You can buy from the Salesforce marketplace. What do they say? “You have Salesforce data. I’m a marketplace app. Take me, and I’ll help you analyze the data.” I don’t need you.
You don’t need that.
I can just run an LLM against the data. So the entire incrementality that has been sold as incremental software modules to all of us doesn’t need to be sold to us, because I’d much rather have LLMs running against that.
Interesting you bring this up. We had an instance with a SaaS product with 20 seats. Nobody was logging in and using it, but the data was there. So we created 3 accounts, got rid of 17, connected it to Slack, connected it to Claude, and now everybody can interface with it through natural language, and we’ve reduced our bill by 90%.
Well, not just that. What are you going to do next? As Jason said, you’re going to take data from different products, put it in one place, and run the analytics against that. I want my data for my sales reps, my productivity data, and my inventory data from SAP. I want it all in one place so I can run analytics against it and say, “Who’s selling a lot? Where do I have less inventory? Let’s build inventory in a region where my salespeople are extremely productive.”
To run that query, you’d have to have talked to 3 different SaaS products. Tomorrow, you can put all the data in one place. So that’s sort of category one.
Okay, category one: analytics is dead.
Yes. In the medium term, all these bolt-ons today and tomorrow are marginally irrelevant. Infrastructure software is undervalued.
Okay, what is infrastructure software?
Stuff that gives you databases. You collect data into it. Stuff that allows infrastructure to work, whether it’s database software—
Databricks, Snowflake, like that?
Databricks, Snowflake, MongoDB, Oracle—all these things. You need core storage infrastructure and core data.
You're going to need 10 times the data stored in an enterprise than we have today. Right—3 years, 10 times. So, anything that helps you collect infrastructure data and manage it, you need.
I think the category in the middle is called—let's call it—system of work or system of record. Those are deeply embedded in the way businesses work. I have 6,000 salespeople; they know how this works.
What's going to happen is, step 1, we will take away the UI and let agents do the work. UI in enterprise software and consumer software is the worst thing we did as technologists.
You had a couple of examples of this. You told me this story—I don't know if you want to repeat it—of this one company that tried to hold you hostage on a license.
You just pointed AI at it and you just—
Yes, that was analytics SaaS, so that's over. That's a different issue. But think about it. Today, we spend our lives having product managers design UI so all humans can interact with data behind the UI.
Yeah.
If you believe agents are going to work, I can just tell an agent, "Look, figure out from my sales call the key points and go post it into whatever sales-tracking system I have, whether it's Oracle or Salesforce." Conceptually, an agent should be able to do it.
We're spending $1 trillion building these agentic backends. We need these agents to be able to do it. If that happens, UI goes away. If UI goes away, I can rewire my system of work.
Right.
My sales guy should have to say, "I had the sales call. Do all the paperwork and all that needs to happen in the back of the company, and I'm done."
And it's also happening passively, which is really interesting. It's looking at email, it's automatically taking the Zoom transcript and summary. So, the sales system of record is now—you don't even need to input it. It's like, "I already have the Zoom call notes. I have the deck. The deck was made, the sales deck was made by AI."
We're all going to be looking at a chat window and just saying, "Here's what I want."
Your audit trail becomes a lot better because humans are not touching your data. It's always being managed by agents, so I think the whole system of work, system of record, gets reinvented in the next 5 years.
Yeah, there's no data entry. That's an interesting point. Let's talk about national security for a second. I just want to maybe zoom out. So, one side of Mythos, as you said, is the value that it has to you and to enterprises. The red-team version of Mythos is where foreign state actors can essentially create economic havoc inside of a country.
Yes.
As these models escalate in their capability, what do you think should happen when these models are ready?
The sad truth is, there are a few thousand breaches or attacks that happen. They happen for pretty rudimentary reasons. It's not because somebody cracked a hard-to-crack thing. It happens because 89% of attacks happen because credentials get stolen.
Or your username and password.
That's it.
I bet my password is password.
Yeah, I'm sure it is. Did you have a dollar sign?
Dollar sign password.
Fantastic. Well done. See? You're already ahead of everybody else.
So, 89% of breaches happen because of simple things. I don't think we need more models to go crack this stuff. Now, these models can attack critical infrastructure and things we try to protect from a national-security perspective. Yes, we need defenses there.
I'm not worried about the national-security part being protected because they're very on it. They're the right people. They spend 10% of their budgets on IT security. I'm worried about the small offices across the country where they're using some piece of packaged software, and you're running a dentist's office or doctor's office.
Remember when Change Healthcare got breached?
Every physician's office shut down.
Shut down, and it's ransomware.
Because of ransomware at Change Healthcare.
That was the clearinghouse system. That's when UnitedHealth had to actually give billions of dollars of credits to the physicians to be able to run their businesses at that point in time.
That's what one should worry about. It's less about—
The big nuts will get cracked.
—about cracking some PG&E power-generation facility. It's more economic chaos. Yes. And so, what do we do?
I don't think there's a silver bullet. I think this will basically take a while until every system gets upgraded, renewed, and fixed over time. I just think it increases the terminal value of the industry.
Do you think that there's a world in which these models become so good that you could see yourself advocating for more nationalism around how they're controlled, how they're managed, and where we point them? Or do you think there should be a set of these models that never see the light of day, that only the NSA and other folks get access to, or guys like you?
I have a slightly differentiated view about models and how they will evolve versus what we heard earlier from an OpenAI perspective. I still believe models are going to become a utility layer. You'll be able to buy intelligence on the fly.
You can say, "I don't need a 180-IQ person to go do this task. Give me a 120 IQ, and I need a 250 IQ to do this task. I'll pay $10 for this, or for this I'll pay 1 cent." So, I don't know that there's a one-size-fits-all model that gives you the most up-to-date intelligence to answer my customer call, saying, "Sorry, sir. I have no idea how to solve your problem."
I think models will get differentiated from a utilitarian perspective. If you look at what's already happening in the market, the profit pools are in applications, not in models.
Sarah talked about Codex running away. She didn't say OpenAI is running away. She just said Codex is running away. I'm sure Dario says Claude Code is running away. So, you're seeing that—
They're attacking profit pools.
They're attacking profit pools because that's where the money's going to come from. The profit pools are in applications that companies can use. The profit pools are not in model usage by companies because most companies have no idea how to use the models.
Are these companies, in a way—OpenAI and Anthropic—the new Microsoft Office, coming in and doing all applications, all productivity software for organizations?
No, I see there's going to be application companies that are going to arbitrage between models and solve your business problem. If I'm a company, I don't want to write every piece of software myself. I want my HR system software, which is agentic-enabled and AI-enabled, to be delivered by some application company. It'll be a new AI application company.
I want my sales-management system built by the new agentic AI sales force of the world, whether it's Salesforce or somebody else. I want applications. Now, what Sarah said is the profit pools are in the application layer. That's why they want to be the application layer.
I think we're still waiting for that layer of companies to be invented or created, where applications will sit. Fifty thousand companies need the same application. Why would I build it myself? It's highly inefficient. It's silly for me to use OpenAI directly and rewrite my entire sales system because I'm smart. Right? I'm not. I want somebody to do it for me.
I think that layer of companies is still not fully formed.
So, we're going to be waiting for it.
Control plane, a harness, and then—
That's right. They will build the harnesses and the memory into those application layers. Now, the question is, how big is the application layer? Is it one application? Is it one enterprise application that does everything, or is it a specialized application?
And you kicked out this software vendor. You did it because they were being abusive in pricing. So, that—
Use a different vendor.
What's that?
We swapped out for a different vendor. We just took more control.
Love it. So, it really is a pricing issue. That's why the SaaS apocalypse, in some ways, makes sense. They're not having pricing power because you could say, "Well, I'll just put 10 developers on this and I'll save $10 million."
Yes.
I think the part goes back to what Chamath said about regulation, or whether you want to regulate these higher-powered models. The question is, at some point in time, when these newer models, which are even more powerful, get built, they will come at a different price point, and they might have to go through a certain vetting process to understand what their capabilities are.
But I think we're in a global race. I don't think holding back our models for 3 to 6 months is going to help us any. Somebody else is going to put them out in open source. I was shocked to hear, when I was talking to the CEO of one of these model companies—
He says, “The entire weights of their most recent model can fit on a USB stick.”
Say that again.
The entire model weights of their newest model fit on a USB stick. That’s the IP.
That’s incredible, because all the data can be distilled in under 24 to 48 hours and the model comes out. I’m curious.
That’s the IP. So, are you telling me that we can hold on to that for 6 months?
Right. We have a debate about how difficult it is to make a frontier model. Some companies are starting to think about making frontier models using their data advantage to build their own. Have you thought about that at Palo Alto? It does seem like you have proprietary knowledge on how security works. Could you build your own large language model or an SLM, a small language model, that would give you some advantage in the future?
One thing that nobody talks about is the false-positive rates on the models. What is the false-positive rate on 4.8 and 5.5?
No idea.
You guys don’t talk about it. You should. The false-positive rate on MSO was 30%.
Oh, wow.
Right? So, it thought it found something, but it hadn’t.
Yes.
The problem is, it’s great for attack and horrible for defense. You find something 30% of the time that says, “I found a problem,” and you say, “Let’s plug the hole.” Wait, there wasn’t a hole there in the first place.
No missile inbound.
Right.
Yeah.
The same problem applies in enterprise. If you use a model without the right harnesses and the right training, you could be running into 10% or 20% false-positive rates. Let’s use the model to pay, I don’t know, insurance claims.
Yeah.
Oh, great. A 10% or 20% false-positive rate. I just lost money. The sycophantic nature of these is ridiculous, too.
So, the problem is not who wants the newest model. The problem is, how do you take that model with a 20% or 10% false-positive rate and make it a 0.01% false-positive rate? In my business, I want 0%.
Without losing the false negative.
Sorry?
Without losing the negative—the false negative.
Yes, but it’s like saying, “Hey, let’s take the new self-driving car. Mercedes is going to use Opus 4.8, and you can just sit in the car and it’s going to drive you.” I’m not putting my kids in that car with a 10% false-positive rate. Are you?
There’s a lot of work that happens after a model, which needs to happen to make this thing useful and effective in the business context.
Let me slightly pivot for a second. You were, for a very long time, the chief business officer at Google. You were the president of SoftBank. Now you’re the CEO of Palo Alto Networks. So, let’s play armchair CEO.
Armchair CEO.
I’m still bristling from David Friedberg trying to create a distinction between founder CEOs and non-founder CEOs. Just saying, David.
By the way, false positives.
Sorry?
And false negatives, too.
Give us what you would keep, what you would change, and what you like about the following companies.
This is going to get recorded and put out there. I don’t know.
Give us your thoughts. You’re one of the smartest business people.
You don’t get to live with the glory of these All-In podcast sessions.
Ready?
Yeah, sure.
Okay. What you keep, what you change, what you like, and what you don’t like. Uber.
I’m on the board of Uber. I’m not going to talk about Uber.
I didn’t know that. Sorry. Okay.
Dr. Dara—he’s the CEO. He’s a great guy.
Okay. Waymo.
You’re trying to get me fired.
Waymo.
What do I like about Waymo? The cars work. It’s amazing. They should have more in many more cities around the world, faster. I would say that at the rate I’m going, I’m going to be fired.
Google.
I think Google’s underrated. I think it’s going to be the first trillion-dollar company in our lifetime. I think they have all the assets that are needed to make this successful.
People underestimate that you can be a model company, but you still need to have a sales force that convinces customers to go out there, embrace these models, and buy them. If you think about it, the 3 hyperscalers have the biggest number of salespeople out there, so they should—
One of the reasons why they’re a little bit undervalued is just the conglomerate nature. It’s hard to understand.
I don’t know. You guys are smarter than I am. I’m just a hired-hand CEO.
I didn’t say that. Reed said that. Let’s just be clear.
I know. I know.
I was providing a thesis on recovery out of the SaaS pack, let’s just say.
Okay. Okay. Got it.
Just to be clear, there’s a way to segment that basket, okay? And you’re not in that basket.
I thought you were making a distinction about how founder CEOs have the right to take more risk and are allowed to take more risk.
I wasn’t saying that. I think you provide a unique counterpoint to that, and there aren’t a lot of people like you. I think the same would be true of Jeff Weiner. I think there are a few other really great CEOs, but they are like Neo in The Matrix—type anomalies.
I think you’re one of those people. There’s a very rare kind of personality profile of someone who’s willing to take risk and take ownership of something that wasn’t theirs in the first place and make it theirs. It’s an extraordinarily unique trait, far more unique, actually, than being a scalable founder.
That’s an incredible save.
You’re forgiven.
Yeah, good save. Incredible save. Back to armchair CEO.
Wow, that was incredible. He’s more sycophantic than ChatGPT. He’s like, “Actually, I’m actually the best.”
Let’s go back to armchair CEO.
I’m liking this. He should use OpenAI more often.
OpenAI.
They should sell faster, right? They should sell faster.
I mean, you said it. Didn’t you just say it when Sarah was here, that—
Anthropic seems to have improved its ARR much faster than OpenAI.
I mean, that’s just the statistics.
They kind of went all in on enterprise.
I think that’s the conversation right now. It’s a race to take over the profit pools. If you’re going to need tens and tens of billions of dollars every year to get—what is that? 1 gigawatt is 10 billion of revenue.
It costs $50 billion, so this is not a great deal.
So, what are the most exciting profit pools, then?
You’ve got coding. That’s been the breakout application over the past year. It’s massive. You’ve got infrastructure, like you said, the new databases. I think cybersecurity is clearly one of them because of the threats and the patching cycles being so much more dynamic.
There’s a slight difference. As you can see, these models are trying to be the enablers of better cybersecurity, which is good because all of us need to use them to test. You’re probably going to see—I mean, Anthropic has already made its cyber-capable model generally available, so everyone can use it. OpenAI has one. I’m sure Google has one, too.
They understand this is a place where CISOs, or chief information security officers, want to use it to test the code. So, this is another profit pool. I think we haven’t seen the onslaught against the application-software companies yet.
There are tens and tens of billions of dollars in application software waiting to get reinvented, as we talked about. I think eventually you’ll see these people saying, “What if I took this $40 billion, $50 billion, $100 billion TAM down? I can build a whole brand-new backbone with generative AI, and it would be so differentiated that it would cause customers to move.”
We’re seeing it as a playbook in the accelerators now. The year-zero and year-one companies—people are coming to us with the pitch: “This is $1,000-a-seat-per-year, $500-a-month-per-seat SaaS software. We can do it for less. We’re going to charge them based on consumption. We’re going to take 80% or 90% of the cost out as—”
What are the 2 fastest places to make revenue?
The 2 fastest places to make revenue? In enterprise, replacement apps. If you replace something I already have a budget for, it’s easy. I take something bad, I replace it with something better, and I get money. Replacement apps are beautiful.
If you can replace an industry or replace a profit pool, it’s great. The second place is consumer revenue. It’s a lot easier to get $5 per user on the consumer side.
Netflix.
So, that’s where—I mean, look at it. I think we collectively probably pay more on subscriptions per month than we ever did historically, and you thought your cable bill was high.
Yeah. Do you think that you’re going to end up building more or less hardware in the future, if you had to guess?
Hardware, even today, is the cheapest way to manage low-latency, high-throughput bits. You still need a data center.
Yeah.
What’s a data center doing? It’s just managing high-throughput, low-latency bits.
Yeah.
That’s why, if you look at financial services, it’s the most reluctant industry to go to the cloud, because you increase latency.
If you increase latency, you reduce profit. So, if you look at every one of your largest financial services companies, whether it’s Goldman or JPMorgan, Morgan Stanley, or these guys, they’re using hardware. Try to get them to run their business in the cloud; they can’t because they’ll have higher latency and lose money.
Right.
So, hardware is still being made. I remember when I used to advise Silver Lake, and I had thought Dell was done. Nobody wanted hardware. I think Dell might be back to a $300–$400 billion market cap. So, hardware is still going to be around. We’re going to need it. It’s the fastest way to move it.
Are our hardware development cycles changing because of AI? Are you seeing a lot of generative design stuff moving in silicon that historically was manual and long-cycle?
Yeah, but the long pole in the tent is the design, right? The long pole in the tent is production. Today, you can’t get a box produced because every piece of hardware componentry is backordered. Everything’s expensive, and every factory in the world is backordered because we’re trying to build all these GPU-based chip cards for every data center in the world.
Do you think the U.S. is equipped to fill that supply chain need? Can we do that here, or do you think we’re just done?
10 years.
With a firm top-down commitment.
Well, I mean, the good news is that I think the hardware industry is seeing a bonanza of a lifetime. Generally, when you see a bonanza of a lifetime, you can go commit $10, $20, $50, or $100 billion. I’ve seen a CEO on television committing to a $100 billion plan to build more memory. So, that’s good. That means they have the money to put the money in the ground, literally, to build these things for the future. So, I think that gets us more certain.
I think the tax incentive has a lot to do with that. The accelerated depreciation on the capex—you get a 100% write-off in the first year, right?
Just a final question as we wrap up. Over the last 8 years, you’ve grown organically very aggressively, but you’ve also been pretty acquisitive. You’ll take shots, and they’ve generally worked. So, you have a ton of permission in the market. When you hear what Bill Ackman said about how there are these kind of overbeaten companies, there are a few that get celebrated, that’s a ripe pool for you to pick from.
But some of that would require you to go maybe a little horizontally far afield, some would say. How do you maintain the discipline, or do you see yourself at some point considering things that are not nearly so much right down the middle of cyber?
So, I’ll tell you what. Until about a year and a half ago, we used to buy product companies and throw them into our go-to-market engine. We could rewire their back end so they could work better with our go-to-market engine. So, for me, if I’m selling $10 million to a customer, next time I go to them later, if I can sell them $20 million, it’s the most efficient way for me to amortize my go-to-market spend, right?
So, that was the model. We ran that playbook to north of $150 billion. Then we got to a point where we said, “Oh, we see an inflection arriving in identity. It’s going to be important from an agentic perspective, a security perspective.” So, we bought a $25 billion company, which we closed 3 months ago.
Um now it's actually a very different opportunity has presented itself. And the different opportunity sort of goes like this. If you can be the best at leveraging AI to run the most efficient enterprise business in the world, your operating margin can be far in excess of the industry. And if you can if you can crack that code
Gross and net, you’re saying? Gross in the 90s, net in the 40s.
Yeah, if you can crack that code, then it doesn’t matter what you buy.
Yeah.
I think the problem right now is the execution problem. Most subscale companies cannot afford to optimize their company and run it better. So, if we can run our company much better than everybody else and have a higher operating margin, then the Street will say, “Fine.”
Your first M&A was really tough, no? They were pretty skeptical, and then you kind of shoved it in their face.
They were pretty skeptical when they found a guy who didn’t know cybersecurity, didn’t know enterprise, show up, who worked at Google. The track record of people leaving Google and being successful out of Google is still—
Yeah.
—varied.
So, basically, you’re saying the menu’s open.
I think we need the next 6 to 12 months to figure out how this AI settles down and how we can use that effectively in enterprises. I think, if you think about it, people keep hoping that we’ll need fewer people to run companies. I actually have a counterview.
I think we’re going to have more people at Palo Alto on the technology side than we’ve ever had before because I think AI is causing everything to ask for a transformation. So, I have more technical people today than I would have had if AI didn’t exist.
Thank you, guys.
Thank you, sir.