Summary of the Key News Content in Plain Language
This report discusses the most dramatic reversal in the AI industry this year: just half a year ago, the entire market believed that AI would directly compete with traditional cybersecurity companies, as AI could automatically scan for code vulnerabilities and detect signs of hacker attacks, with efficiency dozens of times higher than that of humans. As a result, the stock prices of all leading cybersecurity companies plummeted. However, recent developments have shown the complete opposite. AI has now become the biggest source of security risks. For instance, the core operating instructions for the latest Anthropic model were stolen within hours, and various large models can be easily “hacked” to perform malicious actions, making AI the biggest “task assigner” in the history of the cybersecurity industry.
The latest financial reports from leading American cybersecurity companies show record-breaking results, with revenue growth reaching new heights in a decade. While domestic cybersecurity firms have also secured many AI-related security contracts, they have not yet benefited from this trend due to their reliance on the traditional project-based procurement model. The fundamental logic of the industry has completely changed. In the past, cybersecurity focused on preventing hackers from exploiting known vulnerabilities in software; now, it involves managing the unpredictable behavior of AI. A new market worth hundreds of billions of dollars is being created by AI.
---
Detailed Analysis Point by Point
1. The Dramatic Reversal: From “AI Will Destroy Cybersecurity” to “AI Has Become the Biggest Customer for Cybersecurity”
In February this year, when Anthropic launched an AI product capable of automatically scanning for code vulnerabilities, the stock prices of leading American cybersecurity companies such as CrowdStrike and Palo Alto dropped by more than 10%. Investors reasoned that if AI could complete what used to take dozens of security engineers weeks to do in just minutes, who would still buy traditional security software? Wouldn’t that mean cybersecurity companies would lose their jobs?
Seven months later, however, it became clear that the greater AI’s ability to find vulnerabilities in other systems meant that AI itself became a much more significant security risk. Advanced models can be easily hacked to perform malicious actions, and even the core operating instructions for top AI companies like Anthropic can be stolen within hours. It’s as if AI, which was originally seen as a “security guard,” can’t even protect itself and might be manipulated by attackers. Therefore, the primary need is no longer to use AI for tasks but to provide additional security measures to protect it.
2. The New Business Opportunities Brought by AI for Cybersecurity
The financial reports of companies like Palo Alto demonstrate that the new demand generated by AI is substantial and has significantly expanded the market. There are three types of new orders:
- AI infrastructure protection: Building AI data centers requires significant investments in GPUs. If the models are stolen or the training data is tampered with, the losses can be in the tens of millions of dollars. As a result, AI labs, cloud service providers, and governments are placing large orders for firewalls to protect AI server clusters.
- Traffic protection for AI entities: AI entities can operate independently on the internet, using various tools and accessing internal systems. The amount of machine traffic generated by these AI entities has increased by nine times in the past nine months. This creates a new market for security products designed to protect against such activities.
- Security products specifically for AI: These products prevent AI from being manipulated and monitor its behavior to ensure it doesn’t steal data. Palo Alto’s new products in this category have generated over $100 million in annual revenue, representing the fastest-growing product line for the company.
3. The Fundamental Change in the Security Industry: From “Preventing Known Vulnerabilities” to “Managing Unpredictable AI”
AI has not only created new orders but also overturned the underlying rules of the cybersecurity industry. Traditional software had fixed, predictable logic, but large models are inherently unpredictable. Cybersecurity must now manage the potential mistakes and errors of AI. Companies that previously focused on managing user accounts and passwords are now having to specify which data AI entities can access and which systems they can use.
4. Why the Gap in Performance Between Chinese and American Cybersecurity Companies
The reason for the significant difference in performance between Chinese and American cybersecurity companies is the difference in business models. American companies transitioned to a subscription-based model more than a decade ago, generating stable annual revenue from additional AI security features. In China, most cybersecurity businesses still use the traditional project-based model, which is time-consuming and inefficient. Domestic firms are struggling to adapt to this new model, while American companies are designing new products tailored to the new risks posed by AI.
5. The Unavoidable Question for All Enterprises
The Anthropic incident highlights a critical issue: you can’t keep the operating logic of AI secret to ensure security. Even the world’s top AI companies can’t protect their core instructions. This means that any AI system you use, whether purchased from a third party or deployed internally, can be manipulated. Enterprises must find ways to control AI’s behavior and ensure it doesn’t cause damage. This is a critical challenge for all companies using AI and will drive growth in the cybersecurity industry for the next decade.
In conclusion, the AI revolution has transformed the cybersecurity industry, creating new markets and business opportunities. However, the transition requires significant changes in business models and approaches.