Key points
- Anthropic withheld a model from public release
- Anthropic says 10,000+ high- or critical-severity flaws found
- CrowdStrike and Palo Alto got early access
- The six earnings releases do not separately report AI-security revenue
Anthropic kept Claude Mythos Preview out of public release because of its ability to find and exploit software vulnerabilities. It gave selected organizations access through Project Glasswing instead. By August, the model had become part of the sales pitch on a cybersecurity earnings call.
"The Mythos moment translated into mass-market acceptance that AI adoption needs security, and that's CrowdStrike," CrowdStrike founder and chief executive George Kurtz told investors on August 26.
CrowdStrike and Palo Alto Networks were Glasswing launch partners in early April 2026. The program gives organizations access to Mythos Preview to find and fix weaknesses in critical software. Anthropic expanded access on June 2 to about 150 additional organizations across more than 15 countries. It said the initial partners had found more than 10,000 high- or critical-severity flaws.
Six listed security companies are now reporting strong growth alongside new AI-security products. Their earnings releases do not show how much those products contributed. The comparison below separates what each company is selling from the financial results it has disclosed.
What the six companies are reporting
The companies reported within roughly five weeks of one another, although their fiscal periods differ. Acquisition contributions are flagged where discussed below.
| Company and quarter | Revenue and growth | GAAP operating margin |
|---|---|---|
| Palo Alto Networks, Q4 FY26 to July 31, includes CyberArk | $3.41B, +34% | 5% |
| CrowdStrike, Q2 FY27 to July 31 | $1.47B, +26% | -2% |
| Fortinet, Q2 2026 to June 30 | $2.05B, +26% | 34% |
| Zscaler, Q4 FY26 to July 31, includes Red Canary | $898.2M, +25% | -2% |
| SentinelOne, Q2 FY27 to July 31 | $292M, +21% | -31% |
| Cloudflare, Q2 2026 to June 30 | $696.1M, +36% | -29.6% |
Fortinet, Zscaler, SentinelOne and Cloudflare stated their GAAP operating margins. The Palo Alto and CrowdStrike figures are calculated from operating income of $172 million and an operating loss of $33.2 million against the revenue in the same releases, by our arithmetic.
Palo Alto Networks (PANW) is the largest of the six and sells Prisma AIRS, which enforces zero-trust runtime protection at the infrastructure layer where AI models run. Next-Generation Security ARR grew 63 percent to $9.10 billion, though that rate includes CyberArk, bought for $25 billion and closed on February 11, 2026, with no separate contribution disclosed. Chairman and chief executive Nikesh Arora attributed the demand to the buyer's priorities rather than to a product, saying in the September 1 release that "the latest advancements in AI are elevating cybersecurity to the top of the CIO priority list, and will serve as durable tailwinds as we progress towards our $20 billion FY30 NGS ARR target." The company also disclosed the purchase of Console, described as an AI-native platform for agentic workflows.
CrowdStrike (CRWD) sells Continuous Identity for AI Agents, which extends authorization across human, non-human and AI agent identities, and has extended Falcon AI Detection and Response across AI gateway partners including Databricks, Google Cloud and Microsoft Azure. It added a record $332.8 million of net new annual recurring revenue in the quarter, up 51 percent, bringing ARR to $5.84 billion, and raised its full-year net new ARR growth outlook by 630 basis points. Kurtz said in the August 26 release: "Every enterprise will run on AI, and securing it is the largest market opportunity in our history."
Fortinet (FTNT) is the profit outlier and the one whose chief executive did not credit AI for the quarter. Its product revenue, the hardware line, grew 52 percent to $773 million against 26 percent total growth, and it holds a 34 percent GAAP operating margin. Founder and chief executive Ken Xie attributed that in the July 29 release to Fortinet's "unique 'SASE Firewall'" running on its own operating system and purpose-built chip. The AI material in the release sits in the business highlights rather than the explanation of results, including the launch of FortiSOC, a cloud-delivered security operations platform.
Zscaler (ZS) names Agentic SecOps and Security for AI as two of the four platforms it says are driving adoption. Revenue and ARR both grew 25 percent, to $898.2 million and $3.771 billion, but that ARR rate includes Red Canary, which contributed $141 million of ARR on its own; excluding it, ARR grew 20 percent. Founder and chief executive Jay Chaudhry put the company on both sides of the problem in the September 3 release, saying it can help customers "both combat the threats created by agentic AI and securely deploy AI agents and models."
SentinelOne (S) is the smallest and slowest-growing, at $292 million of quarterly revenue and $1.218 billion of ARR, up 22 percent. Customers paying $100,000 or more a year grew 13 percent to 1,715. Chief executive Tomer Weingarten described AI-native runtime protection as fundamental to the Singularity platform's architecture and claimed "undisputed technology leadership for both AI for Security and Security for AI."
Cloudflare (NET) sells to the traffic rather than the endpoint, and grew fastest of the six at 36 percent while posting the second-deepest operating loss as a share of revenue. Co-founder and chief executive Matthew Prince described the shift in the August 6 release: "As the web shifts to AI answer engines and agent-driven commerce, we are seeing a fundamental rewrite of the Internet for machine-to-machine traffic."
Who has early access, and Nvidia's backing
Three different things get described as AI partnerships, and they are worth separating. Access to a restricted frontier model is one. A validated product integration with Nvidia (NVDA) is another. Being named by Jensen Huang from a conference stage is a third.
| Company | Frontier-lab model access | Nvidia integration | Named by Huang on stage |
|---|---|---|---|
| Palo Alto Networks | Glasswing launch partner | Prisma AIRS, January 2026 design | No |
| CrowdStrike | Glasswing launch partner | SafeMind, built on Nemotron | Yes, September 10, 2026 |
| Fortinet | Says it works with Anthropic and OpenAI | FortiGate VM, January 2026 design | No |
| Zscaler | Not on these lists | Not on these lists | No |
| SentinelOne | Not on these lists | Not on these lists | No |
| Cloudflare | Not on these lists | Not on these lists | No |
The Nvidia column draws on the Enterprise AI Factory validated design, published January 5, 2026, which names nine software partners including Fortinet and Palo Alto Networks, and on a separate list for industrial systems announced at the S4x26 conference in February 2026, which also includes Palo Alto. CrowdStrike's entry is different in kind: it launched SafeMind at its Fal.Con conference on September 1, built on Nvidia's Nemotron models, with no pricing or general availability date given. The stage column covers one event, the Goldman Sachs Communacopia conference on September 10, 2026, where Huang called cybersecurity the next major use case for AI and named CrowdStrike alongside Cisco (CSCO) and Palantir (PLTR).
Fortinet is the only one of the six to name both frontier labs, listing Project Glasswing with Anthropic and Project Daybreak with OpenAI in its July release. It was not on Anthropic's April launch list.
A "no" in this table means only that the company was not named on the specific lists reviewed here. It is not evidence of no relationship. A vendor may also have built the same capability without a partner.
What the numbers don't establish
Profitability separates the group differently than growth does: on GAAP operating margin, Fortinet is the only one of the six earning a wide margin, at 34 percent.
Zscaler's free cash flow fell to $60.8 million, 7 percent of revenue, from 24 percent a year earlier. Its release attributes that to capital spending and internal-use software rising to $218.5 million from $78.7 million in the quarter, and does not say what the spending is for.
None of the six earnings releases reviewed here separately reports AI-security revenue. There is no AI segment in any of them, no AI-attributed bookings figure, and no unit count for Prisma AIRS, Continuous Identity for AI Agents, FortiSOC, Agentic SecOps, Singularity or anything else named above. The ARR figures each company breaks out, CrowdStrike's $5.84 billion, Palo Alto's $9.10 billion, Zscaler's $3.771 billion and SentinelOne's $1.218 billion, cover broader businesses or platforms; they do not isolate AI products.
In the June expansion note Anthropic wrote that "within 6 to 12 months, we expect that many other AI companies will have Mythos-class models," and that "cheap, fast AI models with powerful cyber capabilities are around the corner."
Early access may give these companies time to develop and test products. The earnings releases do not yet show how much revenue that access generates, or whether the advantage will last once comparable models become widely available.



