Research NoteEditorial thesis

If AI Escapes the Box, Who Sells the Shield?

After the rally, CrowdStrike, Palo Alto Networks and Palantir face a harder test: turning AI risk into durable business at a price investors can justify.

Research Note

The market has noticed

By early afternoon on September 14, CrowdStrike and Palo Alto Networks were already sharply higher. Stock Analysis showed CRWD up 14.56% at 14:28 EDT and PANW up 13.80% at 14:24 EDT. These are separate intraday snapshots, not closing returns.

After a move like that, it is easy to feel late. The useful question is what comes next: which company can turn the need for AI security into paying customers, and how much success is already in the share price?

We start with CrowdStrike because selling agent protection to existing Falcon customers is a business proposition we can follow. Palo Alto already has an available AI gateway and competes for some of the same work. Palantir brings AI into operational decisions. Choosing among them takes more than agreeing that AI needs protection.

Research Note

From AI warnings to a security budget

WIRED reported that researcher Jacob Coxon announced his resignation from Anthropic on September 8. On September 12, Dario Amodei proposed pacing frontier AI development and embedding outside evaluators. ITV reported supportive responses from Sam Altman and Elon Musk. The reports do not establish a causal link between the resignation and the proposal, or agreement on every remedy.

These concerns reach far beyond enterprise software, and the day’s stock moves cannot be pinned on one headline here. To assess the companies, we need to narrow the question to problems a customer might actually pay them to solve.

Research Note

Start with an agent’s permissions

An AI agent can use tools and take actions. Imagine an agent sorting your inbox. One email tells it to send confidential files to an outside address. This fictional example illustrates prompt injection: untrusted content trying to redirect the agent’s task.

Keep four things separate: people deliberately misusing AI, legitimate agents being compromised, failures during laboratory development or evaluation, and hypothetical loss of control over advanced systems. Anthropic’s September threat report describes increasingly autonomous cyber operations while humans still selected targets and reviewed stolen data.

Enterprise security can constrain access and detect some abuse. It cannot establish that catastrophic loss of control has been solved.

Research Note

Three routes to AI security

The boundaries overlap. A customer could use several of these products together, leaving vendors to compete over which controls deserve a separate budget.

CrowdStrike · CRWD
Agent discovery, activity monitoring and access controls around execution. Test paid adoption and supported coverage.
Palo Alto Networks · PANW
AI applications, gateways, identity and security operations. Test integration and incremental spending.
Palantir · PLTR
AI inside data-driven operational workflows. Test deployment economics and governance in practice.
Research Note

CrowdStrike: protecting agents where they run

CrowdStrike introduced Falcon Guardian on September 1. The company describes agent discovery, monitoring and response at runtime—while software executes. An endpoint is a device where that execution happens, such as a laptop. Connecting agent activity to existing security records could help defenders understand what went wrong.

Its September 2 Agentic Identity Provider announcement describes identifiable agents with limited, short-lived access tied to a responsible human or system. Think temporary visitor badges rather than permanent master keys. CrowdStrike also announced protection for supported Codex agents through its expanded OpenAI partnership; that is not evidence of universal coverage or partnership revenue.

There is still a gap between the launch and what we can confirm customers can deploy. Guardian is launched and marketed, but the primary pages reviewed do not clearly establish general availability for every core capability or Agentic IdP. The launch blog calls Guardian’s gateway pre-beta, with fiscal Q4 availability planned, and Falcon Complete for Guardian a later-fiscal-Q3 release. Both dates are roadmap commitments at this review date.

The attraction is straightforward: Falcon customers might add agent protection to a platform they already operate. That could make distribution easier. We still need evidence that customers pay extra, deploy broadly and renew.

Research Note

Will customers pay more?

For the quarter ended July 31, 2026, CrowdStrike reported revenue of $1.47 billion, up 26%, and annual recurring revenue of $5.84 billion, up 25%. ARR annualizes recurring subscriptions; it is not recognized annual revenue.

The period predates the September launches. Companywide growth therefore cannot demonstrate those launches’ success or isolate AI-security sales. The next earnings reports will be more useful if management describes paying adoption, contract expansion and retention specifically for these products.

Research Note

Palo Alto deserves more than challenger status

Palo Alto completed its Portkey acquisition on May 29. Its current product FAQ and fiscal 2026 annual filing say Prisma AIRS AI Gateway became generally available on July 16. That gives customers a product they can evaluate today.

A gateway sits between applications and AI services, routing requests and applying controls. This gives PANW a concrete answer to part of the same problem CrowdStrike targets. Its filing also describes endpoint and identity capabilities, so the overlap extends beyond network traffic.

For a buyer, the deciding factor may be how well a provider connects applications, identities and security operations. PANW’s available gateway gives it a credible claim on that budget. Integration quality and the return on its acquisition spending still need scrutiny.

Research Note

Palantir: who is allowed to let AI act?

Palantir’s Artificial Intelligence Platform, or AIP, connects AI with organizational data and workflows. Its documentation describes access controls, auditing and governance, with availability varying by customer. The use case extends to commercial operations as well as government work.

That is relevant to deciding who can authorize an agent and inspect its actions. It is a different investment case from buying endpoint protection. An audit trail cannot guarantee an ethical decision, and enabling more AI activity can create new risks alongside productivity gains.

Research Note

Also watch: Cloudflare · NET

Cloudflare adds another competitor at the application layer. It announced AI Security for Apps as generally available for Enterprise customers on March 11, 2026. Separately, its AI Gateway Guardrails documentation describes screening prompts and responses for harmful content, but still labels Guardrails beta. Coverage has limits: some streaming responses are logged rather than blocked, and some model types bypass response checks.

Cloudflare is worth watching for two reasons: these controls could bring it additional paid spending, and they give customers another option alongside CRWD and PANW. The investment case needs its own work on margins and valuation; this brief look at NET does not support a buy recommendation.

Research Note

A good shield can still be an expensive stock

At Stock Analysis’s September 14, 14:28 EDT snapshot, CRWD’s market capitalization was $243.04 billion. Dividing by the $6.0011 billion midpoint of FY2027 revenue guidance (year ending January 31, 2027) gives about 40.5 times forecast sales. This is our calculation using one dated market-data snapshot, not enterprise value or a profit multiple.

The July quarter also produced a $33.2 million GAAP operating loss versus $371.6 million adjusted operating profit. The reconciliation includes $399.0 million of stock compensation and related payroll taxes. Equity awards can dilute shareholders; excluding them does not make their economic cost disappear.

CrowdStrike’s July 19, 2024 update caused Windows crashes. The company says it was not a cyberattack. Security software can itself disrupt customers, making reliability and recovery part of the investment case.

For all three companies, competition and bundling could squeeze prices; protection may miss unsupported environments; slower AI deployment could defer demand. This note does not establish PANW or PLTR as cheaper alternatives through comparable valuation analysis.

Research Note

What would change our view?

What strengthens the thesis
  • Customers add and renew paid agent protection.
  • Credible tests show attacks prevented in supported environments.
  • Cash generation grows per share, after the cost of expansion.
What weakens the thesis
  • Launches remain roadmaps; integrations disappoint.
  • Comparable controls become bundled freebies.
  • Valuation outruns plausible earnings power.

We would follow CRWD’s paid adoption, compare it with PANW’s deployed gateway, and assess PLTR through the economics of its customer workflows. The rally makes the price harder to justify. The next useful evidence will come from customers paying for protection and staying with it.

Research Note

Disclosure

Personal holdings: CRWD, PLTR and NET; no PANW. Buteon uses Cloudflare for infrastructure. There are no sponsorships, affiliate arrangements, compensation for coverage or other business relationships with these companies. Infrastructure use does not imply sponsorship or endorsement. Educational research, not investment advice.

Research Note

Sources and dates

  1. CrowdStrike intraday quote (opens in a new tab)

    September 14, 2026, 14:28 EDT; dynamic market-data snapshot.

  2. Palo Alto intraday quote (opens in a new tab)

    September 14, 2026, 14:24 EDT; dynamic market-data snapshot.

  3. WIRED interview with Jacob Coxon (opens in a new tab)

    September 9, 2026; reports September 8 resignation.

  4. Dario Amodei: We Must Pace the Frontier (opens in a new tab)

    September 2026; primary statement of his proposal.

  5. ITV: Musk and Altman respond (opens in a new tab)

    September 12, 2026; reported responses, not universal agreement.

  6. OpenAI: Understanding prompt injections (opens in a new tab)

    Undated explainer; accessed September 14, 2026.

  7. Anthropic threat report (opens in a new tab)

    September 10, 2026; vendor investigation of selected detected misuse.

  8. CrowdStrike: Falcon Guardian announcement (opens in a new tab)

    September 1, 2026; vendor capability claims.

  9. CrowdStrike: Guardian launch and roadmap (opens in a new tab)

    September 1, 2026; gateway pre-beta; managed service release plans.

  10. CrowdStrike: Agentic IdP (opens in a new tab)

    September 2, 2026; announcement includes unreleased-feature caveat.

  11. CrowdStrike: expanded OpenAI partnership (opens in a new tab)

    September 2, 2026; supported Codex agents, no quantified revenue.

  12. CrowdStrike FY2027 Q2 earnings, SEC exhibit (opens in a new tab)

    August 26, 2026; quarter ended July 31; unaudited company results.

  13. Palo Alto: Portkey acquisition completed (opens in a new tab)

    May 29, 2026; acquisition completion and integration plans.

  14. Palo Alto: Prisma AIRS AI Gateway (opens in a new tab)

    Current product FAQ states general availability from July 16, 2026.

  15. Palo Alto FY2026 Form 10-K (opens in a new tab)

    Filed September 10, 2026; page 45 confirms July 16 gateway GA.

  16. Palantir: AIP documentation (opens in a new tab)

    Undated current documentation; customer feature availability can differ.

  17. CrowdStrike: July 2024 update incident (opens in a new tab)

    July 20, 2024; technical account of July 19 Windows crashes.

  18. Cloudflare: AI Security for Apps GA (opens in a new tab)

    March 11, 2026; Enterprise availability announcement.

  19. Cloudflare: AI Gateway Guardrails (opens in a new tab)

    Updated June 5, 2026; current navigation labels Guardrails beta.

  20. Cloudflare: Guardrails usage limits (opens in a new tab)

    Current technical restrictions; reviewed September 14, 2026.