Palo Alto Networks Closes Record Fiscal Year Beating Guidance Across All Metrics With AI Security Recurring Revenue Surging 63% and Agent Traffic Ballooning Ninefold in Nine Months

Stock News
1 hour ago

Cybersecurity titan Palo Alto Networks has delivered a blockbuster set of financial numbers for the fourth quarter of fiscal 2026, with every single metric clearing management guidance. Bookings momentum accelerated for a second consecutive quarter, and fourth-quarter revenue climbed 34% year over year to $3.41 billion. For the full fiscal year, revenue grew 24% to $11.5 billion. Remaining performance obligations breached the $20 billion threshold for the first time in history, closing at a record $21.2 billion for a 34% annual gain, with current RPO also up 34% to $9.3 billion. On the much-watched fiscal 2027 outlook, the company guided adjusted full-year earnings per share in the range of $4.16 to $4.19, comfortably ahead of the consensus analyst figure of $4.11. First-quarter fiscal 2027 revenue guidance of $3.3 billion to $3.31 billion similarly topped expectations of $3.21 billion.

Next-generation security annual recurring revenue, which constitutes the company's AI security ARR, surged 63% to $9.1 billion in the fiscal fourth quarter, with net new additions of nearly $1 billion in a single quarter, almost doubling year over year. Breaking down full-year platform revenues, Network & AI Security contributed $8.35 billion, Cortex delivered $1.92 billion, and Idira generated $1.26 billion on a pro forma basis, representing growth of 17%, 25%, and 21%, respectively.

Large deal momentum and customer expansion accelerate in tandem

For the first quarter of fiscal 2027, the company expects next-generation security ARR of $9.54 billion to $9.56 billion, for 63% growth. RPO is projected between $20.8 billion and $20.9 billion, up 34% to 35%, while revenue guidance sits at $3.3 billion to $3.31 billion, representing 33% to 34% growth. Adjusted non-GAAP diluted EPS is seen at $0.96 to $0.98. For the entirety of fiscal 2027, next-generation security ARR is forecast at $11.075 billion to $11.175 billion, up 22% to 23%. Full-year RPO is projected between $25.2 billion and $25.4 billion for 19% to 20% growth, and revenue is guided between $14.1 billion and $14.2 billion, up 23% to 24%. Operating margin guidance sits at 29.5%, with non-GAAP diluted EPS between $4.16 and $4.19 and adjusted free cash flow margin set at 38%.

In the fourth quarter, Palo Alto Networks added roughly 220 net new platformization deals, a company record and more than double the level recorded when the metric was first introduced two years ago. Net revenue retention among platformized customers exceeded 120%. The company still aims to surpass 4,000 cumulative platformization projects by fiscal 2030, laying the foundation for its goal of $20 billion in next-generation security ARR.

Management highlighted several marquee fourth-quarter agreements: a $126 million commitment from a global telecom leader, a $72 million transaction with a major IT services provider, and a $53 million platformization deal with a global payments platform that also invested a high seven-figure sum into Prisma AIRS. Platformization not only extends product breadth within a single customer but also unifies Network Security, Cortex, Idira, AI security, and observability into one coherent architecture, strengthening renewals, cross-sell, and wallet share.

AI reshapes cybersecurity demand from large models to autonomous agents and open-weight models

Management believes the past six months marked three crucial turning points in the AI landscape. OpenClaw pushed enterprises beyond traditional large language models toward autonomous agent behavior. Mythos proved that deep domain training can compress vulnerability discovery and exploitation from months to minutes. And the rapid spread of open-weight and open-source models has driven a significant increase in proprietary model deployments, internal data usage, and sovereign AI projects.

Looking ahead, enterprise employees will orchestrate thousands of autonomous agents simultaneously, with every agent continuously generating network traffic, telemetry, and machine identity credentials. This dramatically expands the market boundaries for identity security, network defense, cloud security, endpoint security, and observability. Management projects that global AI infrastructure capital spending over the next five years will exceed the combined total of the previous two decades. In the Q&A session, executives further modeled $5 trillion in AI capex over that horizon while noting that roughly $1 trillion in global cybersecurity technology debt is urgently awaiting modernization.

CEO Nikesh Arora stated on the earnings call that the latest advances in AI are pushing cybersecurity to the top of every CIO's priority list, representing a "durable tailwind." He emphasized that roughly $1 trillion of the world's cybersecurity infrastructure is not ready for AI-driven threats, which will create long-term growth headroom for the industry. "Any system deployed seven to ten years ago was never built to counter AI threats at machine speed. Enterprises must rethink their security architecture entirely. There is about $1 trillion of cybersecurity debt out there that needs to be modernized to defend against automated threats running at instant speed," Arora told investors.

SASE and network security keep taking share with agent traffic rising ninefold in nine months

Fiscal 2026 Network & AI Security platform revenue grew 17% to $8.35 billion. Software firewall ARR expanded 29% in the fourth quarter, while demand for the fifth generation of hardware appliances remained robust. Full-year SASE bookings grew 40%, with strong contributions from Access, SD-WAN, and Secure Browser. The company displaced incumbent vendors across close to 100 customers, with related total contract value exceeding $400 million as noted in prepared remarks. The CFO subsequently clarified in the Q&A that the year-to-date figure at the end of the third quarter was $200 million, and the full fiscal 2026 number reached $450 million.

Palo Alto has risen to second place in the SASE market and plans to become the leader within five to seven years. Management emphasized on the earnings call that agent-related traffic grew ninefold over the past nine months, while the company's machine-speed detection capabilities, honed over two decades, block more than 30 billion attacks per day.

Prisma AIRS surpassed $100 million in ARR just four quarters after general availability, making it the fastest-scaling product in company history. Customer count has grown to roughly 800, and most of the largest fourth-quarter deals involved multiple modules. The agent endpoint strategy, formed after acquiring Koi, has shown early validation with more than 100 customers, a 2.5-fold increase since integration completed.

XSIAM ARR exceeded $700 million, up 70% year over year, with over 1,000 customers. Customers using the platform have compressed average response times from days or weeks to under ten minutes. Unit 42 simulated a complete AI-driven attack in under 30 minutes, compared with the roughly four-day response cycle reported by traditional industry defenses.

Since acquiring Chronosphere in the second fiscal quarter, observability ARR has more than doubled, surpassing $500 million versus $85 million at acquisition. In the fourth quarter, the company signed a $20 million deal with a high-growth AI inference provider processing tens of trillions of tokens daily. XSIAM cross-sell contributed 50% of Chronosphere's net new customers during the quarter, including several seven-figure deals. Chronosphere is purpose-built for AI-era massive telemetry, with management noting an average total cost of ownership 30% to 40% lower than major legacy observability rivals. After integrating Embrace's real-user monitoring and synthetic monitoring capabilities, the company expects to field a complete competitive offering for the traditional enterprise market within six months, ultimately building observability into a multi-billion-dollar ARR business. Combined XSIAM and observability ARR now exceeds $1 billion.

CyberArk rebranded as Idira with identity security emerging as a growth pillar for the agent era

Just two quarters after closing the CyberArk acquisition, integration synergies are running three to six months ahead of plan. Idira generated pro forma revenue of $1.26 billion in fiscal 2026, up 21% year over year. Joint efforts have produced over 400 sales leads and more than 200 net new customers from Palo Alto's installed base. Deals exceeding $5 million in total contract value grew 50% year over year in the fourth quarter. Management said it has lifted CyberArk's margin by more than 1,000 basis points in nine months and ultimately plans to expand it by roughly 1,100 basis points. The newly launched Modern PAM extends traditional privileged access management into modern environments, while Idira's long-term strategic value lies in governing non-human identities and AI agents, ensuring every machine operation is authorized, scoped, and fully auditable.

Management presentation section

Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance, opened the call: "Good afternoon, everyone. Welcome to the Palo Alto Networks fiscal fourth quarter 2026 earnings conference call. I'm Hamza Fodderwala, SVP of IR and Strategic Finance. Please note this call is being recorded on Tuesday, September 1, 2026, at 1:30 p.m. Pacific Time. Joining me today to discuss our Q4 fiscal 2026 results are Nikesh Arora, Chairman and CEO, and Dipak Golechha, CFO. You can find the press release and additional information on our website at investors.paloaltonetworks.com. After navigating there, please click on the quarterly results link to review the fiscal Q4 2026 supplemental financial information and Q4 earnings presentation materials. During today's call, we will make forward-looking statements and predictions regarding our business operations, financial performance, and recent acquisitions. These statements are subject to risks and uncertainties that could cause actual results to differ materially from those forward-looking statements. Please refer to our press release and recent SEC filings for a description of these risks and uncertainties. We undertake no obligation to update any forward-looking statements in today's presentation. This presentation also contains certain non-GAAP financial measures and key metrics related to historical and expected future performance. Non-GAAP financial measures should not be considered a substitute for measures prepared in accordance with GAAP. The most directly comparable GAAP measures and reconciliations are included in the press release and investor presentation appendix. Unless otherwise specifically noted, all results and comparisons are on a fiscal year-over-year basis. I'll now turn the call over to Nikesh."

Nikesh Arora, Chairman and CEO: "Thank you, Hamza. Good afternoon, everyone. Thank you for joining us as we discuss our progress. As you can see, our execution delivered record results to close out the fiscal year. Every financial metric exceeded guidance in Q4, and bookings momentum accelerated for a second consecutive quarter. This performance stems directly from record platformization adoption and the growing urgency among customers to harden their defenses as AI fundamentally reshapes the security landscape. Our RPO set a record, breaking through the $20 billion mark for the first time to close the fiscal year at $21.2 billion, up 34% year over year. Next-generation security ARR reached $9.1 billion, up 63%, delivering one of our largest NGS ARR beats ever. Most notably, net new NGS ARR in the quarter alone approached $1 billion.

I recall attending my first Analyst Day in 2019, shortly after I had joined the company, when we set an ambitious goal: to reach $1 billion in next-generation security revenue by fiscal 2022. At the time, we were beginning the transition from a single-product firewall vendor to a unified security platform. Today, that transformation has reached a critical inflection point, and the scale of our success validates the original vision. In Q4, we saw broad-based strength across every platform. Network Security, our largest business, delivered outstanding results across SASE and both software and hardware firewalls. XSIAM continued its strong momentum, and Prisma AIRS hit a major milestone: exceeding $100 million in ARR within four quarters of general availability. That is the fastest-growing product in Palo Alto Networks history.

Fiscal 2026 marked a critical inflection point in our transformation journey. We completed the two largest acquisitions in company history, CyberArk and Chronosphere, and both have exceeded initial expectations. Both businesses have gained significant traction within our platform architecture and are growing faster than they did as standalone companies. These results are a testament to execution and the deep collaboration of the thousands of new colleagues who joined over the past year. We look forward to carrying this momentum into fiscal 2027.

Q4 was the first quarter where we witnessed the profound impact of models with offensive cyber capabilities. As I've said before, AI is a long-term tailwind for the cybersecurity industry. While these models are increasingly adept at finding vulnerabilities, discovery is just the opening act. Truly validating the issue, understanding context, and solving the problem requires a broad cybersecurity platform working in concert with frontier AI. This collaboration is essential for stress-testing environments, managing agent behavior, and triggering machine-speed remediation when threats occur. Defending at this speed demands a unified data architecture where AI processes every signal, compressing response times from days to minutes. Platformization is the only viable strategy for real-time defense, for using AI to fight AI. In Q4, this thesis continued to resonate strongly with customers.

We delivered approximately 220 net new platformization deals in Q4, exceeding the prior record and representing more than double the scale seen when we first introduced the metric two years ago. This validates the high resonance of real-time defense through a unified architecture. Beyond initial adoption, standardizing on our platform also yields superior retention and expansion; in Q4, net revenue retention among platformized customers exceeded 120%. Looking ahead, we remain on track toward our long-term goal of more than 4,000 platformization projects by fiscal 2030, which underpins our target of $20 billion in next-generation security ARR.

The largest Q4 deals demonstrated platformization in action. We signed a $126 million agreement with a global telecom leader. This organization adopted our network security platform as its standard, expanding next-generation firewall deployments while replacing legacy proxy vendors with Prisma Access for SASE. We also closed a $72 million transaction with a leading IT services provider. This customer has fully embraced platformization across Network Security, Cortex, and Idira, committing eight-figure investments in each area, validating the strong cross-sell momentum in Q4. Another highlight was a $53 million platformization deal with a leading global payments platform. Beyond consolidating network defense and architecture onto our standard, this customer invested a high seven-figure amount in Prisma AIRS to accelerate its enterprise AI initiatives.

Fiscal 2026 has been a hallmark period in the rapid evolution of AI, with three distinct inflection points over the past six months. Each has fundamentally redefined how AI interacts with enterprises and, in turn, how it impacts the cybersecurity landscape. To lead and protect customers effectively, we must remain at the forefront of these structural shifts. The first inflection point was the emergence of OpenClaw. Earlier this year, OpenClaw became the catalyst for moving from traditional LLMs to agentic action, fundamentally changing the relationship between human operators and AI systems. Just a year ago, AI was largely defined by prompts from a single human user, a synchronous, multi-turn conversation completed in a closed loop with individual involvement. Almost overnight, we witnessed the emergence of fully autonomous agents. These agents are entities that run continuously over extended periods, executing complex workflows without direct supervision. For employees who previously managed one task at a time, the same person can now orchestrate thousands of autonomous agents. This has profound implications for enterprises. Every agent continuously generates traffic, interacts with models, creates internal data, and communicates with other tools and agents around the clock. This creates massive telemetry that must be observed, and each agent requires its own set of identity credentials. We now must protect a brand-new class of machine identities with autonomous permissions. The surge in traffic, data, and identity complexity represents a significant long-term tailwind for every one of our platforms.

The second inflection point was the 'Mythos moment,' which proved that deep domain training can achieve unprecedented levels of AI specialization. In our industry, this manifests as AI being weaponized to identify and exploit vulnerabilities at scale. This shift has exposed deep technical debt within enterprises: legacy flaws and long-standing misconfigurations that once took humans months to discover can now be exploited in minutes. In an AI-driven threat environment, there is nowhere to hide. For customers, the 'Mythos moment' shifts the core of the security challenge from visibility to speed. Organizations must now identify exposures before they are weaponized and respond at machine speed. That's why real-time defense has moved from a future roadmap item to an immediate reality. In response, last month we expanded our Frontier AI Defense service, introducing a multi-modal testing framework that enables enterprises to stress-test their environments. This service leverages the most advanced offensive cyber models available today, and we're proud to be the first certified commercial partner for Mythos 5.

The third inflection point is just forming, and we expect it to dominate cybersecurity discussions over the coming quarters. Over the past 90 days, the market has shifted from a few frontier models toward a diverse ecosystem of open-weight and open-source architectures. Enterprises are increasingly prioritizing sovereign control over their AI, driving deployments of specialized models deeply integrated with proprietary data. We expect this trend to accelerate significantly as organizations fine-tune models using internal telemetry for customized enterprise use cases. While frontier models will continue to define the highest bar of intelligence, the broader market is rapidly moving toward fragmentation and mass proliferation. Critically, every additional deployment adds more infrastructure to harden and more sensitive data to protect. The attack surface requiring platform protection is expanding dramatically. The three key moments each have unique impacts but converge on a single conclusion: as human-AI relationships evolve and deployments multiply, unified real-time defense has never been more necessary.

We are still in the early stages, but we're already seeing how these trends are influencing our business, starting with Network Security, our largest business. AI is a significant long-term tailwind, expanding the network security TAM while further validating platformization as the only viable strategy for modern enterprises. As global AI buildout continues, every new data center becomes critical infrastructure requiring robust hardware and software firewalls, whether delivered natively by cloud providers or through unified security platforms. The ecosystem driving infrastructure expansion has reached a critical inflection point; we're now seeing a new cohort of buyers emerge, including sovereign nations, new cloud providers, and frontier labs, all racing to deploy vast compute capacity that must be protected. In fiscal 2026, we made strong early progress with these customers, including multiple seven-figure deals in Q4. Overall, firewall execution drove accelerating bookings growth this fiscal year, powered by strong demand for the latest fifth-generation hardware and continued software momentum as customers expand cloud and AI workloads.

As this infrastructure matures and autonomous agents deploy, we expect agent traffic across all network and cloud environments to increase dramatically. This impact is already visible on SASE, where agent traffic grew ninefold in the past nine months. Defending at this scale requires machine-speed detection, a capability we've honed for two decades, enabling the company to block over 30 billion attacks per day. Ultimately, AI further underscores the urgent necessity of unified platforms for real-time defense. In fiscal 2026, our platform advantage drove excellent SASE results, with bookings up 40% and strong performance across Access, SD-WAN, and Secure Browser. We displaced traditional market leaders in close to 100 customers, with related TCV exceeding $400 million, nearly double the pace from a year ago. While we've rapidly risen to second place in the market, our goal is to win, and we're on a clear path to becoming the SASE leader within five to seven years. This transformation is still in its early chapters, requiring a unified architecture capable of delivering machine-speed defense while protecting both human and machine identities.

As organizations move AI initiatives from pilot to full production, every additional deployment significantly expands the perimeter that must be defended. Prisma AIRS continues to adapt with these adoption cycles, evolving to address the unique risks of each phase of the AI journey. While we initially focused on the chatbot-centric GenAI era, our vision has expanded to deliver a complete agentic security architecture. This unified approach begins with protecting machine identities and credentials, encompasses deep observability of agent activity footprints, and extends to endpoints that analyze behavioral intent. By routing traffic through the AI gateway, we ensure security policies are enforced in real time on every interaction. Prisma AIRS achieved an extraordinary milestone in Q4: exceeding $100 million in ARR just four quarters after GA, making it the fastest-growing product in company history. The customer base has expanded to 800, and most of our largest Q4 deals included multi-module adoption. Following the Koi acquisition, our agent endpoint strategy has also seen significant early validation. As AI development tools move to the desktop, we believe endpoints are reaching a critical inflection point. This shift expands the attack surface, where agents autonomously manage files and access sensitive credentials. Traditional security tools typically lack visibility into the underlying intent and reasoning of these machine-speed operations. In this environment, visibility without action is insufficient. Our platform approach provides end-to-end transparency from initial prompt to final execution, enabling inline defense at machine speed. This capability is becoming a fundamental requirement. We've already won over 100 customers, 2.5 times the number since completing the Koi integration earlier this year.

Ultimately, detection and defense are most effective when unified on a single platform, with XSIAM serving as the central nervous system for these critical telemetry streams. Earlier this year, Unit 42 researchers demonstrated the alarming speed of modern threats by simulating a complete AI-driven attack completed in under 30 minutes. By contrast, standard industry defenses report a four-day response time, clearly an unsustainable approach. Customers standardizing on XSIAM are transforming their operations, compressing average response times from days or weeks to under ten minutes, and we continue driving toward true real-time defense. In Q4, XSIAM maintained excellent momentum, with ARR exceeding $700 million, up 70% year over year, and platform customers surpassing 1,000. The power of our architecture is that real-time telemetry already resides within XSIAM, allowing the company to unlock new value seamlessly through a unified data lake. Expanding deployments requires no integration friction—only new ways of querying existing data. As of Q4, most customers have adopted this platform advantage, using multiple modules, including exposure management and cloud security.

Turning to observability. We continue to see the world's leading AI-native and cloud-first organizations standardize on our technology. Every entity pushing the frontier of AI generates telemetry at a scale traditional tools cannot handle. Chronosphere was purpose-built for this massive data, capturing every training run and agent loop. This quarter, we signed a $20 million deal with a high-growth AI inference provider processing tens of trillions of tokens daily. Nothing validates our platform better than the architects of the AI ecosystem trusting us to monitor their own infrastructure. Since acquiring Chronosphere in the second fiscal quarter, observability ARR has more than doubled, surpassing the $500 million mark. This performance significantly exceeds initial targets and is the fastest post-acquisition expansion in company history. The cross-sell strategy is delivering tangible results; XSIAM contributed 50% of Chronosphere's net new customers this quarter through multiple seven-figure deals. We also enriched our stack with Embrace, integrating Real User Monitoring to complement core metrics, logs, and traces. This expansion enables a complete end-to-end observability platform covering core infrastructure through end-user experience. XSIAM and observability now collectively contribute over $1 billion in ARR—an extraordinary achievement for a data-intensive platform that wasn't part of our portfolio just a few years ago.

A cornerstone of my tenure at Palo Alto has been the ability to identify leading technology and world-class talent and seamlessly integrate them into our culture. While the scale of this year's acquisitions naturally increased integration complexity, the results have been exceptional. In Q4, this success was most evident in the performance of CyberArk, now called Idira. Just two quarters after closing our largest acquisition ever, we're already accelerating growth while delivering synergies ahead of schedule—a rare achievement showcasing our integration engine. These results demonstrate deep collaboration with our new colleagues. On the go-to-market front, joint efforts have generated over 400 shared sales leads and produced more than 200 net new customers from Palo Alto's installed base. Customer commitment has also shifted toward larger deals, with Q4 transactions exceeding $5 million in TCV up 50% year over year. However, the biggest challenge and opportunity remains the rise of agentic AI. Agents are, by definition, autonomous, requiring machine identities and the precise context and permissions needed to execute workflows. As enterprises deploy thousands of these autonomous entities, many remain outside formal governance frameworks, often lacking well-defined permission boundaries. This summer served as a wake-up call: rogue agents breached environments at several frontier AI labs. In one high-profile case, an agent escaped its sandbox and exploited a system vulnerability because its access was never properly restricted. Fundamentally, this represents an identity crisis for the enterprise, and that's exactly the strategic mission behind the Idira platform. Idira extends advanced identity security and privileged controls to AI agents, ensuring every machine operation is authorized, scoped, and fully auditable. By integrating these agent controls with the AI gateway in Prisma AIRS, we're helping organizations enforce security policies and maintain defense in real time.

Fiscal 2026 has been a transformative year for Palo Alto Networks and the broader industry. We remain confident that the AI tailwinds driving cybersecurity demand will only strengthen further. First, global AI infrastructure buildout is attracting trillions in investment. We expect capex over the next five years to exceed the combined total of the prior two decades. This massive expansion is driven by demand that continues to outpace supply. For AI to deliver on its promise, traffic and data volumes must both expand; as they grow, every bit must be inspected and every byte observable. The proliferation of critical infrastructure is a permanent tailwind for the cybersecurity industry, already visible in the accelerated momentum of our security and observability businesses this year. Second, the industry is strategically shifting toward real-time defense. Cyberattacks now run at machine speed, making fragmented legacy tools untenable. Approximately $1 trillion in global cybersecurity technology debt must be modernized to defend against automated threats. Because AI acts instantly, this modernization must occur on unified platforms. Platformization is the only solution for real-time defense, ensuring telemetry and policy are coordinated at every control point. We remain in the early innings of this structural shift. Third, AI opens an entirely new cybersecurity market. The rise of autonomous agents will dramatically expand the attack surface that needs hardening. Robust governance and safety guardrails for AI have moved from optional features to enterprise necessities. Although this market is evolving rapidly, we believe the future belongs to architectures delivering end-to-end control, which is exactly what we're building with Prisma AIRS.

Finally, I do want to mention a piece of news: we completed the acquisition of Console today. Console brings an AI-first approach to product development for IT and security operations. Andre and his team will join the Cortex business, driving agentic transformation of our capabilities and accelerating our transition into the AI era. I also want to welcome the Embrace and Console teams to Palo Alto Networks; both acquisitions closed this quarter. As we enter fiscal 2027 with strong momentum, we know that maintaining leadership must be earned through disciplined execution every quarter. I want to thank all employees for their outstanding performance during this milestone fiscal year, and our customers for their continued partnership. I'll now turn the call over to Dipak."

Dipak Golechha, Executive Vice President and CFO: "Thank you, Nikesh, and good afternoon, everyone. We closed a record fiscal year with strong results driven by broad-based strength across all platforms and early integration success. The team executed rigorously, beating guidance on every metric. Before I get to specifics, please note that where applicable, I'll discuss results on both as-reported and pro forma bases to provide standardized growth comparisons. Unless otherwise noted, all growth percentages are year over year. Starting with revenue-related metrics. Q4 RPO surpassed $20 billion for the first time, ending the year at $21.2 billion, up 34% year over year. On a pro forma basis, the success of our platformization strategy drove bookings growth acceleration for a second consecutive quarter. Given stable contract durations year over year, current RPO reached $9.3 billion, also up 34%. NGS ARR also set a record, reaching $9.1 billion in Q4, up 63% year over year. As Nikesh highlighted, most notably, Q4 net new NGS ARR approached $1 billion, almost doubling year over year; a milestone achieved by only a few types of technology companies. I still remember my first quarter as CFO in Q3 of fiscal 2021 when total NGS ARR had just surpassed $970 million. Today, we're adding roughly that same amount in a single quarter. This demonstrates the multiple growth drivers of our business. Five years ago, SASE was nascent and XSIAM didn't exist. Today, these businesses are either past $1 billion ARR or approaching that threshold.

To provide more transparency into our growth drivers, consistent with my preview last quarter, we're disclosing platform revenue for the first time. The three platforms are Network & AI Security, Cortex, and Idira. You'll find historical period data and product composition for these platforms in the earnings presentation appendix on our website. Before discussing platform revenue, please note that Network & AI Security includes the certificate lifecycle management business acquired with CyberArk, subsequently renamed Next Generation Trust Services, or NGTS. In fiscal 2026, NGTS contributed approximately $85 million to Network & AI Security revenue. Also, platform revenue I'll discuss excludes certain items like professional services; as shown in the presentation appendix, these are included in 'Other.'

Turning to Network & AI Security. Full-year fiscal 2026 platform revenue grew 17% to $8.35 billion. Network Security continued to grow double digits faster than the market, reflecting strong competitive positioning and the still-massive opportunity in our largest platform. For example, we continue to gain share in SASE, with bookings and ARR growing significantly faster than the overall market. Software firewalls accelerated again, with Q4 ARR up 29%. Prisma AIRS exceeded $100 million in ARR within its first year of general availability. Finally, hardware firewall delivered another strong quarter driven by customer adoption of the latest fifth-generation appliances. Moving to Cortex, which includes security operations and observability platforms. Fiscal 2026 revenue grew 25% to $1.92 billion. XSIAM continues to be a key driver for Cortex, with Q4 ARR up 70%. In observability, ARR exceeded $500 million, more than doubling since the Chronosphere acquisition in Q2. Please note, as we highlighted last quarter, Q4 net new ARR includes a nine-figure benefit from a large LLM customer migrating to Chronosphere from an incumbent vendor. Finally, Idira, which comprises the identity security platform formed after closing the CyberArk acquisition at the beginning of Q3 fiscal 2026. As noted, Idira excludes the certificate lifecycle management business acquired from CyberArk. On a pro forma basis, Idira generated $1.26 billion in fiscal 2026 revenue, up 21% year over year. Q4 bookings growth exceeded revenue growth, demonstrating early integration and GTM collaboration success.

Overall, Q4 revenue grew 34% to $3.41 billion; full-year revenue reached $11.5 billion, up 24% year over year. From a geographic perspective, all regions delivered strong growth: Americas grew 33%, EMEA grew 39%, and Japan & APAC grew 34% year over year. Moving down the P&L. Q4 total gross margin was 74.8%, down 100 basis points year over year; full-year gross margin was 75.8%, down 60 basis points. This decline reflects the revenue mix shift toward faster-growing SaaS products, which expand with the platform but haven't yet reached mature margin levels. Going forward, cloud services and SaaS will constitute an increasing majority of revenue, and we expect this mix shift will cause cloud hosting costs to grow faster than total revenue in fiscal 2027. Turning to supply chain. We expect continued increases in commodity costs for the hardware business, particularly memory and storage-related costs. As a reminder, while we're pleased with hardware demand strength, hardware revenue represents only about 10% of total revenue. We continue to manage component cost exposure through strategic supplier relationships and selective pricing adjustments across the hardware portfolio. Ultimately, our primary focus remains optimizing overall company operating profit and margins, as reflected in both Q4 and full-year results.

Q4 non-GAAP operating margin was 29.6%. Full-year operating margin reached 29.2%, expanding 40 basis points year over year. This annual expansion is particularly notable given it includes a partial-year impact from our largest acquisitions ever, entities with significantly lower operating margins standalone. We've made excellent progress here. In terms of CyberArk synergies, we remain three to six months ahead of schedule on integration synergies. Looking to fiscal 2027, we expect ongoing operating leverage from efficient scaling and M&A synergy delivery to more than offset higher cost of sales. This focus on operating leverage drove Q4 non-GAAP EPS of $1.02, $0.04 above the top end of guidance. Q4 adjusted free cash flow was $1.29 billion, up 35% year over year. Full-year fiscal 2026 adjusted FCF was $4.41 billion, representing a 38.4% FCF margin, up 40 basis points year over year. Powered by strong FCF generation, we ended fiscal 2026 with a robust balance sheet, including $7.9 billion in total cash, cash equivalents, and short-term investments.

On a longer time horizon, over the past three years, we've proven the ability to deliver durable and profitable growth. Our execution has expanded operating margin by over 500 basis points cumulatively. Simultaneously, we've gained share across multiple new categories, driven by industry-leading R&D investment. Operating leverage also translates directly into cash flow. In each of the past four years, adjusted FCF margin has been 38% or higher. We've maintained strong cash generation even while absorbing the impact of major M&A and as customers increasingly shift from multi-year to annual billing. This track record of expanding while remaining profitable is a cornerstone of our financial model. It allows us to offset potential cost headwinds while funding the innovation engine, which is both our ultimate competitive advantage and the catalyst for customers' platformization journeys. Looking ahead, our FCF visibility continues to improve, driven by steady operating margin expansion and the successful transition of core business to deferred or annual billing. For context: annual billing as a percentage of bookings rose dramatically from 6% in fiscal 2020 to 27% in fiscal 2025. Growth has now plateaued; in fiscal 2026, annual billing increased only low single digits year over year to approximately 30% of total bookings. With this structural transformation now largely stabilized, the company has a highly predictable, compounding cash flow engine. This cash flow visibility, combined with our continued focus on margin expansion and durable double-digit bookings growth, further strengthens confidence in our fiscal 2028 FCF margin target of 40%.

Before providing guidance, I also want to step back and articulate the growth opportunity ahead. As I've said before, years of industry-leading R&D investment have powered our innovation engine and expanded market opportunity into new categories. Sustained investment has earned us leader status in nearly every major category we compete in. Originally primarily a standalone firewall business, we've evolved into a platform with multiple billion-dollar ARR businesses and several others approaching that milestone. Against a total addressable market projected to reach $340 billion by 2030, our current penetration remains low. We believe AI will only expand our market opportunity while further reinforcing the necessity of platformization and real-time cyber defense. This positions us well for our fiscal 2030 target of $200 billion in NGS ARR. Within this long-term framework, here is our guidance for Q1 and full-year fiscal 2027. Please note, the recently completed Console and Embrace acquisitions do not have a material impact on fiscal 2027 guidance. For Q1 fiscal 2027, we expect NGS ARR of $9.54 billion to $9.56 billion, up 63% year over year; RPO of $20.8 billion to $20.9 billion, up 34% to 35%; revenue of $3.3 billion to $3.31 billion, up 33% to 34%; diluted shares of 837 million to 844 million; and non-GAAP diluted EPS of $0.96 to $0.98. For full-year fiscal 2027, we expect NGS ARR of $11.075 billion to $11.175 billion, up 22% to 23%; RPO of $25.2 billion to $25.4 billion, up 19% to 20%; revenue of $14.1 billion to $14.2 billion, up 23% to 24%; operating margin of 29.5%; non-GAAP diluted EPS of $4.16 to $4.19; diluted shares of 844 million to 847 million; and adjusted FCF margin of 38%.

We've listed the usual modeling points in the presentation appendix, but I want to call out a few items. First, as previously discussed, fiscal 2026 NGS ARR net additions included a nine-figure benefit from a large LLM customer migrating to Chronosphere. Our outlook assumes the tail end of this migration continues into Q1 fiscal 2027, with net new NGS ARR contribution lower than Q4. This impacts the seasonality of fiscal 2027 NGS ARR net additions, making Q1 above-normal. We expect 60% to 61% of fiscal 2027 NGS ARR net additions to occur in the second half. Second, while we don't intend to guide revenue by platform, we're providing initial modeling points to help you establish platform revenue growth trajectories within the company guidance framework. For fiscal 2027, we expect Network & AI Security revenue up low double digits year over year; Cortex revenue up approximately 30% year over year; and Idira revenue of approximately $1.5 billion, representing close to 20% to 20% growth on a pro forma basis. I'll now turn the call back to Hamza for Q&A."

Q&A session

Hamza Fodderwala: "Okay, thank you, Dipak. [Operator instructions] Our first question comes from Rob Owens of Piper Sandler, followed by Brian Essex of JPMorgan."

Robby Owens, Piper Sandler: "Great, thank you, Hamza. Nikesh, you talked in your prepared remarks about many of the tailwinds we're seeing in cybersecurity. I think the strong bookings performance is evidence of that; you also mentioned growth accelerating for a second straight quarter. However, the market environment is uneven, and clearly players with scale and broad product coverage are playing a significant role here. So, looking into the new fiscal year, how are you thinking about M&A? Given how rapidly the market is shifting, how are you thinking about another potential transformational deal for Palo Alto? Given what you've done historically and your ability to capitalize on market shifts, what actions are on the table?"

Nikesh Arora: "Rob, thanks for the question. To keep this simple, I'll just send you the names of those companies directly so I don't have to answer this in such detail—you should thank me, right? As I've always said, M&A is not a strategy; M&A is an outcome of our work from a product development standpoint. For example, if you look at—I just discussed the three major shifts in AI over the past seven months. The market has moved from LLMs to agents, and now to open-weight models. Every technology shift on the customer side obviously requires a slightly different security architecture. How do you protect these agents? How do you ensure open-weight models are protected and agents don't go rogue? Obviously, we have our own internal views and are building in that direction from a product development standpoint. But sometimes you get caught off guard because a company was on one path and the market suddenly shifts elsewhere. We have the opportunity to scan the entire cybersecurity landscape and see four or five dozen companies getting funded in this category. Then you might suddenly realize another company got the strategy right, and that's exactly the moment we step in and execute an acquisition. So, acquisitions happen because those companies correctly identified technology trends; we'd rather quickly adopt their direction and enter the space, allowing customers to get capabilities faster. Frankly, as everyone saw after Mythos, customers are willing to try many AI deployments, but before actually deploying, they want to ensure they have a robust security testing framework in place. The most common questions we hear include: What should I do about the vulnerabilities Mythos will find in my environment? How do I solve them today, and how do I track them long-term? Or what happens if we deploy agents and they go rogue? How do we ensure our agents don't just run off to Hugging Face?"

Hamza Fodderwala: "Okay, thank you, Rob."

Nikesh Arora: "I'll remember your request; the moment I buy that company, I'll send you the name."

Hamza Fodderwala: "Okay, thanks Rob. Next we have Brian Essex of JPMorgan, followed by Saket Kalia of Barclays."

Brian Essex, JPMorgan Research: "Nikesh, great to see the acceleration in CyberArk. You're only seeing about 200 net new customers from the Palo Alto install base so far. I'd love to understand what those conversations look like specifically? How big are these deals relative to other CyberArk platform transactions? And you still have a significant existing customer base. I think many people are focused on cost synergies but missing the revenue synergies. How high do you think CyberArk penetration can go within the Palo Alto installed base?"

Nikesh Arora: "I'm genuinely excited about CyberArk. I think if you look at it from two angles, as you correctly pointed out, we did get up to speed quickly. On cost synergies, you've seen that in just about two quarters, our margins are returning to standalone levels. We believe we'll reach steady state in the next quarter. So being able to transform a company of CyberArk's size in nine months and lift margins by 1,000 basis points or more is already excellent work on the cost side. But as you said, we didn't acquire it for cost synergies. We acquired it because we believed the market needs identity security, and this is an inflection point. From our perspective, phase one was not to disrupt the business and to accelerate its momentum. You've seen we've done that successfully. Last quarter, we just hired our new leader, Sunny Singh. He's currently at our sales conference in Asia, rallying the CyberArk team. The team has integrated very smoothly into Palo Alto. I think the collaboration between the two teams has been outstanding, and that excites me. We just launched a new product called Modern PAM. CyberArk historically did traditional PAM, and Modern PAM is an extension category of PAM that the company hadn't spent much time on. The CyberArk—or Idira, as it's now called—product team has done a great job embracing this direction. The product is fully GA now. We plan to try to upgrade all existing traditional PAM customers to this product. So whether it's upsell and expansion or net new sales, we're doing a ton of work. As long as the business can grow faster than CyberArk did standalone and expand margins by 1,100 basis points, I think that's an excellent acquisition for us; not to mention the company's leading position in helping enterprises manage non-human identities and agents in the future, which is a greenfield category with no established leader yet."

Hamza Fodderwala: "Thank you, Brian. Next is Saket Kalia of Barclays, followed by Fatima Boolani of Citi."

Saket Kalia, Barclays Research: "Great finish to the year. Nikesh, this question might be for you. You said Mythos isn't a moment, it's just the beginning. So my question is: as AI threats become the new normal, how do you see customer buying behavior changing? Specifically, are customers more willing to embrace platformization? Is pipeline growth exceeding expectations? Are customers more value-conscious and less price-sensitive? I just want to understand, can you tie some of the deal dynamics you've seen this quarter and over the past few quarters to this new beginning?"

Nikesh Arora: "Please make sure you send candy to Hamza's house a week in advance, otherwise you won't get the first question slot anymore. On business momentum, yes, I said Mythos is just the beginning. For eight years, I've been trying to get CEOs to pay attention to cybersecurity and failing; but Dario did extraordinary work with Mythos. Because now every CEO wants to discuss: What does this mean for us? How do we get access? How do we test ourselves from a vulnerability standpoint? But they're smart. They sit down and say: Listen, I understand this is the new normal. People will be able to find vulnerabilities faster, so how do I solve this long-term? That's where the conversation truly begins. To solve this long-term, the only way is: if some threats breach the perimeter, you need to detect and shut them down quickly. This involves modernizing security assets, platformization, and building an AI-driven security operations center. That's why we're having so many discussions around infrastructure modernization. Every conversation isn't about further segmenting a customer's tech stack or buying more point products, but about finding a way to consolidate, standardize on a platform, and evaluate it. I think this is a massive tailwind for the larger players in the industry. Certainly, some startups will launch niche products that get to market faster, and customers will use those during transitions. But I think this is absolutely a structural shift; one could say it will change the duration and trajectory of growth. Because think about it: open-source models are now competing with Mythos-level capability, and this capability only gets stronger, not weaker. If that happens and capabilities become pervasive, we have a narrow window to close the cybersecurity technology debt accumulated over years and bring defenses back to where they should be. I suspect there will be major security incidents over the next few years because customers haven't completed their transitions yet. Overall, this is a tailwind for everyone in our space."

Hamza Fodderwala: "Thank you, Saket. Next is Fatima Boolani of Citi, followed by Matt Hedberg of RBC."

Fatima Boolani, Citi Research: "Nikesh, you mentioned the concept of technical debt. So I want to step back and ask a question related to your 'Frontier AI Critical Defense' announcement earlier this week or a few weeks ago. We haven't necessarily heard you discuss operational technology in detail, and the potential for that use case to reach critical mass, especially in the context of your platformization strategy. Now we know models can execute extremely powerful vulnerability chaining against parts of the technology environment that have suffered from chronic underinvestment and accumulated significant technical debt. So what constraints remain in accelerating wallet share capture? And relatedly, in the operational technology space, which seems like a great fit for further penetration, how will the continuum between cooperation and competition with some of your frontier lab partners play out?"

Nikesh Arora: "Fatima, there's a lot in there. First, I think nine months ago, every company in cybersecurity and software was judged guilty, almost sentenced to death, because frontier AI was going to eat our breakfast, lunch, and dinner. Obviously, the last six to nine months have proven that's not happening. We'll all get to share in the feast. On the collaboration front, we've seen OpenAI, Anthropic, and even Google come to the table. We get early access to these models, we can test them, and we can test their cyber capabilities. As I said in my prepared remarks, we were—or currently are—the first commercial partner authorized to include Mythos in our testing framework. We're already using OpenAI 5.6 in our testing framework and can offer multiple models to customers. Because customers will quickly become frustrated with the idea of 'finding more vulnerabilities.' What they really want to know is what to do about them. The last thing they want is more security issues when they already have plenty. So conversations quickly shift to: How do I solve these problems? And that's where the platform demand I mentioned comes in.

Specifically on operational technology, I think the challenge is even more acute because OT is hard to patch. Even if you find a vulnerability in an OT instance or deployment, imagine patching an offshore oil rig, or patching a massive amount of technical equipment that can't be remotely accessed or updated—you must send people on site. The good news is—Lee is out this week, so I'll play Lee now. We've actually built a capability that can create and deploy signatures for OT vulnerabilities and open-source vulnerabilities in under four hours. In other words, we can detect an open-source or OT vulnerability, deploy a fix within four hours, and propagate it to software and hardware firewalls, blocking malicious actors on the spot. This stands in stark contrast to the industry standard of 55 days—the typical time it takes to patch open-source or OT vulnerabilities in real environments. This capability will enable customers to block actors exploiting any network-related OT or open-source vulnerability in under four hours. So, you ask what the constraint is, and it's a good question. The real constraint is customers needing time to understand the significant changes they must make, run proofs of concept, assess the current environment, think about which vendors to deploy, and only then enter deployment phases. This isn't something customers do overnight—they'll take time to roll out incrementally. So, I think this is a long-term tailwind, and you'll start to see the industry deliver some level of quarterly beats. But it won't generate the kind of programming agent-style ARR we see in the AI space—which I am somewhat envious of, but that's just the way it is."

Fatima Boolani: "That's a good Lee impression, but [the sideburns aren't quite there—Lee's sideburns]."

Nikesh Arora: "Well, that's easily fixed."

Hamza Fodderwala: "Okay, thanks Fatima. Next is Matt Hedberg of RBC, followed by Michael Turrin of Wells Fargo."

Matthew Hedberg, RBC Capital Markets Research: "Nikesh, you've long held the vision of being the #1 vendor in any category. I mean, you don't enter a market unless you believe you can be the market share leader. So, putting Lee's hat on again, you've obviously had a lot of success in observability. On top of standalone Chronosphere, you've added Embrace—synthetic monitoring, or you've built synthetic monitoring. From a functionality perspective, where do you currently stand versus some of the long-standing market leaders in this space? How much of this opportunity is share shift versus simply AI-driven market expansion where you believe you can capture the largest portion?"

Nikesh Arora: "The fundamental premise of Chronosphere is that it's purpose-built for the AI era—it's brand-new technology. Chronosphere was designed so that, given the massive data volumes being generated in observability, its architecture delivers lower TCO for customers. So Chronosphere costs on average 30% to 40% less than any major legacy observability solution on the market. From a feature-equivalence standpoint, initially we were very strong at serving the needs of AI-native environments—traces, logs, and metrics. That's why most of Chronosphere's customers are AI-native, including one very large frontier AI lab. After integrating Embrace and building synthetic monitoring, we'll reach parity in cross-functional capabilities with some of the market leaders, allowing us to move into the traditional enterprise market. This will also enable all Palo Alto salespeople to start selling Chronosphere. Currently, we restrict Chronosphere to AI-native customers because it's more applicable there. But I expect that within the next six months, we'll reach a stage where Chronosphere becomes a competitive product in its category versus other traditional enterprise players. At that point, we'll have both AI-first capabilities and cost advantages. As this space matures, these advantages should allow Chronosphere to eventually become a multi-billion-dollar ARR business, which excites me. We acquired it at $85 million ARR; it's now above $500 million. We can clearly see the path for this to continue expanding over the coming quarters and eventually cover the traditional enterprise market. Remember, to realize our vision of becoming a larger enterprise, we need multiple billion-dollar ARR businesses. Observability has that TAM, SIEM has that TAM, and network security and identity clearly have similarly sized TAMs."

Hamza Fodderwala: "Thank you, Matt. Next is Michael Turrin of Wells Fargo, followed by Gray Powell of BTIG."

Michael Turrin, Wells Fargo Securities Research: "Great finish to the year. On the initial fiscal 2027 guidance, I'd like to understand how you approached this forecasting exercise given the inflection point taking shape across the cybersecurity industry? You mentioned three major AI shifts, and industry-wide discussions about 2027 security budgets are still early. So could you talk about the baseline assumptions in the guide and the key drivers we should watch for potential upside?"

Nikesh Arora: "Michael, we frame guidance very prudently. We look at where consensus is, ensure we assess the underlying operating plans for each business, and determine whether we can meet, beat, or significantly exceed your consensus. We're pleased that with our execution and the industry tailwinds, we expect to exceed your consensus, and that's how we set guidance."

Michael Turrin: "Very clear. We look forward to the results."

Dipak Golechha: "Yes. Michael, we do look at many different inputs. As we look at various trends, we examine what's happening in the sales pipeline, whether it's gaining momentum, and what trends we see in certain new areas. We take all that information, assess resource requirements; it also involves territory planning and many other things. That's actually how we set guidance. It's a highly mature, world-class process. In my five or six years as CFO, from a process standpoint, not much has changed. I think we've maintained a high degree of transparency, and we've been able to incorporate several key inflection points into our forecasting standards."

Hamza Fodderwala: "Thank you, Michael. Next is Gray Powell of BTIG, followed by Meta Marshall of Morgan Stanley."

Gray Powell, BTIG Research: "Great, congratulations on the strong results. I just want to make sure I understand a number correctly. I believe last quarter you mentioned that SASE contracts from competitive displacements over the past nine months were $200 million. This quarter, that number jumped to $450 million. So I want to confirm whether those two numbers are comparable? If they are, Q4 was really strong. Either way, these numbers are impressive. What's driving the acceleration in SASE displacement and the relative strength versus peers?"

Nikesh Arora: "Gray, if I recall correctly, that number should be $400 million. Is it $450 million? Okay, $450 million. Great. Obviously, we had a good Q4, and that's clearly reflected in the financials. So, yes, Q4 was indeed solid. The SASE displacement is the result of two things happening together. First, when the SASE category originally emerged, it was largely an internet-driven phenomenon, primarily driven by internet access needs. But COVID changed everything. After the pandemic, people wanted continuous access to both private network and internet, and private access is our traditional stronghold. Obviously, our product capabilities in the internet access space have now reached or far exceeded existing competitors. What really works is the integration of SASE and SD-WAN, which we got into very early. We were the first vendor to acquire CloudGenix and integrate it into the SASE architecture. Because our SASE architecture is consistent with our hardware and software firewall architecture, customers using Palo Alto firewalls naturally gravitate toward our SASE solution rather than choosing another vendor. Moreover, if customers want to consolidate vendors and adopt a single platform, this makes the choice easier because they're already using our console, Strata Cloud Manager, and related services in hardware and software firewall use cases. So, further adopting our SASE doesn't feel like a massive shift. In many cases, our endpoint agent is already deployed in customer environments; what was once the agent for VPN products is now the unified SASE agent. So we've effectively surrounded existing SASE vendors with a complete platform. If customers decide to replace the SASE component, since other parts already use our products, standardizing on our platform becomes the simpler choice. Sometimes it's that reason, and sometimes it's simply because customers want to modernize their SASE infrastructure."

Dipak Golechha: "Just to clarify: in Q3, the year-to-date number was $200 million; for full fiscal 2026, it was $450 million."

Gray Powell: "Okay, that means Q4 contributed a really big number. Thanks, that all makes sense."

Hamza Fodderwala: "Okay, next is Meta Marshall of Morgan Stanley. The final question will come from Brad Zelnick of Deutsche Bank."

Meta Marshall, Morgan Stanley Research: "Great. Nikesh, you talked about addressing the $1 trillion technical debt issue. Platforms can help customers pay down that debt in certain ways. But how are you thinking about this in terms of professional services, investment, or other mechanisms that can help customers accelerate resolving technical debt in compressed timeframes?"

Nikesh Arora: "Meta, as you know, when we launched the platformization strategy a few years ago, we established a very clear model in the market: we're willing to accept installment payments, coordinate contract durations, or deploy ahead of time before incumbents must be replaced, thereby accelerating platformization. We offer all these arrangements to customers. Frankly, the constraint that always comes up is that customers' calendars are full. They have a series of things they want to accomplish within their enterprises. Today, in the AI context, there's a lot of AI transformation work in the market. Enterprises want to transform customer support, they want to aggressively pursue copilot applications, they want to deploy LLMs. So security modernization is another priority that must be managed within the overall priority framework. So customers always need to balance. That's why they don't go all-in and say 'replace everything tomorrow.' They sit down and create a more coherent, sensible transformation plan. If a transformation plan takes five years, that's too long; it must be faster. So typical cycles end up being one to three years, but this isn't something that gets done in a single quarter. Customers want to crawl, then walk, then run. They want to do this work as other vendors' products reach end-of-life or as contracts come up for renewal. I can only say that if the larger vendors' products are at or ahead of the market frontier, the trend of customers wanting to standardize on them or implement platformization is increasingly evident; overall, that bodes well for us."

Hamza Fodderwala: "Thank you, Meta. Last but not least, Brad Zelnick of Deutsche Bank."

Brad Zelnick, Deutsche Bank Research: "Great, thanks very much, Hamza. Good to see everyone. Nikesh, you've built strong credibility in M&A. Today's Console acquisition looks consistent with moving further toward autonomous security operations. I could simply ask why Console; but suppose we look five years out, and Palo Alto has achieved far beyond your most optimistic expectations—what would be the most valuable activity customers have completely stopped doing on their own because Palo Alto is already doing it for them?"

Nikesh Arora: "That's an excellent question, Brad. I now understand why Hamza saved you for last. If AI capex reaches $5 trillion over the next five years, then Palo Alto's premise is that AI will create enormous value in the enterprise. Otherwise, pouring $5 trillion into related buildout makes no sense. So I'm an optimist and believe we'll use AI to accomplish a vast number of agentic tasks. If that's true, security operations must become less manual and more agentic, with us taking on more of the work rather than customers continuing to do it themselves, because malicious actors will also use AI. That means we must ensure customers can become as agentic as the adversaries. Obviously, this can't happen without the right data. As you see across industries, effective AI deployment requires the right data; you need the right data foundation, and you must break down silos. So you need unified, coherent data lakes—whether it's the enterprise IT data lake, the observability data lake, or the security data lake. Strategically, looking at our transformation over the past few years, Palo Alto has become a data-first company. We ingest data through XDR; our SIEM platform now processes 19 petabytes per day, with over 1,000 customers. We also have observability data, including data from a frontier LLM lab, which is being fed into the platform for observability. We're becoming a data-first, AI-first cybersecurity company. Our vision is to reduce human involvement across the cybersecurity spectrum, from detection to prevention to remediation. That's our north star. The question is how to get there, and we're driving toward this comprehensively. Looking five years out, if Palo Alto succeeds beyond the most optimistic expectations, we can tell customers: 'We'll replace this product.' Our agents will handle the workflows: understanding the customer environment and completing the migration in under a week. Customers will also need fewer people; our products will automatically configure and deploy policies, with customers mainly reviewing and confirming, rather than handling execution details themselves. That's because we've accumulated experience across many customer environments and can apply that knowledge to new deployments. Today, traditional enterprise products treat every new customer like an untested product, even if it has served many customers before. AI enables products to learn from different customers and deployments. So when serving the next customer, the product becomes smarter. That's our vision."

Hamza Fodderwala: "I want to take this opportunity to thank everyone again for joining this call. Thank you to our customers, shareholders, and all employees; fiscal 2026 has been an extraordinary year for everyone at Palo Alto Networks."

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10