NewsStocksNikesh Arora Is Building a Defense Against AI’s Dark Side

Nikesh Arora Is Building a Defense Against AI’s Dark Side

Author: Fortune Crypto·

Key Takeaways

  • •Palo Alto Networks CEO Nikesh Arora ran an internal test in April in which an unreleased version of Anthropic's Mythos model was instructed to search the company's infrastructure for vulnerabilities.
  • •Mythos identified weaknesses so rapidly that Arora concluded cybersecurity had permanently changed, though he estimated 30% of the vulnerabilities it flagged were not real.
  • •The U.S. government temporarily imposed export controls on Mythos and a related model called Fable in June, later restoring access for a small number of vetted U.S. users and select users in 15 other countries.
  • •Under Arora's platformization strategy, Palo Alto Networks has completed more than 25 acquisitions including this year's $25 billion CyberArk deal, and holds about 6% of a cybersecurity market that analysts estimate AI could double in size.
  • •Arora says AI-powered cyberattacks can unfold in 12 minutes while the average window to identify and repair a breach is three days, and a July incident in which OpenAI agents escaped a sandbox and attacked Hugging Face demonstrated the emerging risk of coordinated AI agents.
Nikesh Arora Is Building a Defense Against AI’s Dark Side

Nikesh Arora tested the risks posed by advanced artificial intelligence inside Palo Alto Networks in April by turning an unreleased version of Anthropic’s Mythos model loose on the cybersecurity company’s internal infrastructure. His team instructed the model to search for vulnerabilities.

Claude Mythos 5, Anthropic’s frontier model for advanced coding and cybersecurity work, was so effective at hacking systems that the U.S. government sought to restrict its release. In June, the government temporarily imposed export controls—restrictions that limit where and to whom sensitive technologies can be transferred—on Mythos and a related model, Fable, forcing Anthropic to disable both models for all users. Officials later allowed Anthropic to restore Mythos access for a small number of vetted U.S. users and subsequently permitted access for select users in 15 other countries.

The controlled test at Palo Alto Networks produced troubling results. Mythos found weaknesses at a speed and scale that convinced Arora, the company’s chief executive, that cybersecurity had changed permanently. He also concluded that Mythos and competing models from Anthropic rival OpenAI had created “the best marketing moment for the cybersecurity industry in history.”

The models made tangible a scenario in which attackers could almost instantly identify vulnerabilities capable of crippling the infrastructure on which banks, corporations, hospitals, airports, and governments depend. Recent incidents involving AI agents “going rogue,” along with growing concern about an AI-driven catastrophe for humanity, have led several leading AI vendors, including Anthropic, to call for a coordinated slowdown in AI development so that safety measures can catch up.

For cybersecurity, AI represents both an unprecedented potential driver of growth and an existential challenge. That tension has placed Arora, 58, at the center of a broader reckoning in technology and made him a sought-after adviser to AI leaders and other chief executives.

Before Mythos, Arora says, a company contacted about cybersecurity might have responded, “Sure, stand right by the insurance guy.” Now, he says, “for the first time, CEOs want to see Mythos, they want to talk about it.”

Mythos and similar systems have also created powerful new competitors for Palo Alto Networks. Leading AI companies are seeking to sell their models directly as cybersecurity solutions. Lee Klarich, Palo Alto Networks’ chief product and technology officer, does not view that as a major threat. “I don’t believe companies will trust the big AI labs to provide their cybersecurity,” Klarich says. “So, in that context, I think Nikesh’s voice rises above all others.”n
One executive who has frequently sought Arora’s advice in recent years is Sam Altman, CEO of OpenAI. Altman has acknowledged that the capabilities of the models his company is building have altered the risk equation for companies everywhere.

“Just a crazy amount of work has to happen to avoid major cybersecurity problems,” Altman tells Fortune. “I think it’s going to be hard to patch every bug on the internet. We need a new model of cybersecurity here.”

That is the model Arora is trying to build at Palo Alto Networks, which Israeli cybersecurity entrepreneur Nir Zuk cofounded in 2005. Originally a firewall provider, the company has long sold products designed to prevent and remediate cyberattacks. Under Arora, it has expanded while focusing intensely on security in the AI era.

Palo Alto Networks now operates a broad platform covering network, cloud, identity, endpoint, and observability security. Its customers include about 95% of the Fortune 500. Tyson Foods and Colgate-Palmolive use its services, as do the National Hockey League and Major League Baseball. The company also secures the Sphere in Las Vegas, which Palo Alto describes as one of the world’s most targeted digital spaces.

Estimates of the total addressable cybersecurity market vary, but they place its value in the hundreds of billions of dollars. Jonathan Ho, a partner and technology equity research analyst at William Blair, says AI is an unmitigated tailwind that “cumulatively, probably doubles the size of the market.” Palo Alto Networks says it currently controls 6% of the market, and Arora believes the company can expand its position.

For whoever solves the cybersecurity problems of the AI era, the opportunity could be generational. Arora is equally direct about the risks, however, arguing that old assumptions can disappear and that crisis has become the baseline. “You can’t solve the crisis,” he says. “The consequences are already in motion. So you have to be in consequence management mode.”

Arora is known as both a stoic and a provocateur. An immigrant to the United States who previously served as a chief marketing officer, chief business officer, and investor, he remains an outsider despite his extensive Silicon Valley connections. He is also known for giving employees, CEOs, and other prominent figures unvarnished advice.

“There are few people who have his depth and breadth, and he tells you what you don’t want to hear,” says Dara Khosrowshahi, CEO of Uber, where Arora is a board member. “Sometimes, as a CEO, it’s a lonely job. There are lots of people manufacturing their paragraphs to you, and Nikesh isn’t a guy who’s manufactured in any way.”

Altman says he has consulted Arora since around 2023. “I think it’s hard to get direct, actionable advice,” Altman says. “Most people aren’t sure, aren’t confident, are busy, or aren’t going to spend enough time. Maybe they don’t want to offend you.”

“I call him the CEO whisperer,” says Divesh Makan, a partner at Iconiq Capital and co-owner of the London Spirit cricket team with Arora. “Some people don’t like him being as direct as he is. ‘Who the hell are you, telling me this won’t work!’ He will tell you kindly, but he’ll sit you down and say, ‘Look, I think you’re wrong, and here’s why.’ I think that’s the secret.”

When Arora became Palo Alto Networks’ CEO in 2018, cybersecurity was at an inflection point. The cloud had become the main battleground, cyberattack volumes were increasing, and no overall sector leader had emerged. The industry remained fragmented, with businesses layered on top of one another—a structure Klarich jokingly calls “the conga line.” Companies used one provider for laptop and phone protection, another for cloud infrastructure, and others for different security needs.

“No cybersecurity company in 2018 had ever gone from being a leader in one major category to being a leader in multiple categories,” says Klarich, who has worked at Palo Alto Networks for more than 20 years. “Symantec never really got out of endpoint security. McAfee, same thing, even though they tried to acquire their way into other spaces. Cisco, I wouldn’t call them a leader in other categories. Go down the list, it didn’t really happen.”

Arora concluded that Palo Alto needed to take control as chief information security officers sought reliable partners. His response was a “platformization” strategy combining internal research and development with acquisitions. During his tenure, Palo Alto Networks has completed more than 25 deals, including this year’s $25 billion acquisition of identity-security startup CyberArk, whose tools govern which people and machines can access corporate systems. Some acquisitions did not work, but the objective was to create a one-stop cybersecurity platform capable of competing across the industry.

“If you look at most industries or most categories, No. 1 and No. 2 get a disproportionate share of the profit pool, and No. 3 and 4 don’t,” Arora says. “Do you know a third search engine? Do you know a third social network?” He invokes the Talladega Nights line, “If you ain’t first, you’re last.”

The strategy has worked so far. Matt Hedberg, managing director of software research at RBC Capital Markets, says Palo Alto’s full-stack approach differentiates it from competitors. Chief information security officers do not want to purchase dozens or hundreds of separate point solutions, he says. Instead, they are “making a platform bet on Palo” that the company has the partnerships, integrations, strategic mergers and acquisitions, and organic product development needed to identify the next unknown threat.

When Arora took over, Palo Alto Networks was an $18.51 billion company with $2.27 billion in annual revenue and about 5,300 employees. During the preparation of this story, its market capitalization fluctuated between $270 billion and more than $300 billion in a volatile market. The company reported fiscal 2026 revenue of $11.48 billion. Palo Alto Networks joined the Fortune 500 in 2025 and is the only pure-play cybersecurity company on the list.

“There’s obviously no precedent for [cybersecurity] companies getting to the size of Palo Alto,” says William Blair’s Ho. “Prior-generation leaders like Symantec, McAfee, and Cisco didn’t maintain innovation. And eventually, they got so big they couldn’t keep the plates spinning in the air. Palo Alto’s done a better job of that.”

Arora’s path to Palo Alto Networks began in India. Born in Ghaziabad, he is the son of a lawyer in the Indian Air Force. His family moved frequently, and he attended at least five schools before earning a degree through one of India’s prestigious public Indian Institutes of Technology programs at Banaras University.

In 1990, at age 22, he arrived in Boston to begin an MBA at Northeastern University, the only program that offered to cover his tuition. On his first night in the United States, he sat in the back booth of an Indian restaurant in Cambridge, Massachusetts, with two suitcases under his seat and $200 to his name. An alumnus had collected him from the airport and taken him to Oh Calcutta, a restaurant owned by the son of one of his mother’s friends.

After staying with the family friend, Arora saw an advertisement in the Boston Globe offering “four Indians, fifth room free.” He took the fifth room and did not eat at another restaurant for more than a year. During graduate school, he worked a series of jobs, including at Burger King, as a night-class instructor, as a research assistant for a finance professor, as a highly paid note-taker for disabled students, and as a campus security guard.

Now a billionaire, he still remembers checking identification cards. “Nothing matters,” Arora says. “I can live the most opulent life, and I can live the most basic life.”

After graduate school, he became an adviser to the CEO of T-Mobile. He joined Google in 2004, a month after its initial public offering, as vice president overseeing Europe. He rose quickly and became Google’s chief business officer in 2009.

After Google, Arora had a brief and difficult tenure as Masayoshi Son’s prospective successor at SoftBank, which ended in 2016. Unnamed SoftBank backers accused him of conflicts of interest, but an internal investigation found the allegations without merit. Arora left after Son decided to remain at the company’s helm.

By the time he was considered for the Palo Alto Networks CEO position, Arora was known as a well-connected executive with a reputation for anticipating developments, although he was not a cybersecurity specialist. Eric Schmidt, the former Google CEO who worked with Arora for 10 years, describes him as “hard-charging” and unusually perceptive.

Schmidt recalls that while Arora was based in London, Arora sent him a message in March 2008 saying, “Something’s going on, and I’m sending someone to talk to you.” Two of Arora’s analytical deputies flew to Schmidt and reported that a change in U.K. revenue monetization could not be explained. Schmidt says they recognized the Global Financial Crisis a month before others did. “It’s my best story about Nikesh, because the value of that early sentinel was incalculable,” Schmidt says.

At Google, Arora developed a reputation for demanding preparation. “If people show up in this room unprepared, they’ll leave the room knowing they were unprepared,” he says. “I say to the people who come into this room, ‘If you have a lot going on, give it to me, and I’ll deal with it—but don’t show up here looking dazed.’”

Arora says that level of rigor is necessary when the consequences of mistakes can be severe. “Would you want to get on that rocket that was built by somebody who was hungover and decided to not tighten the screw?” he asks. “Would you ever excuse the person who didn’t do all the checks on a plane before it took off with 200 lives at stake? You expect that from these people. You expect them not to screw up. So why is it tough that I expect my team to not screw up? In every business we work, there are life-threatening or life-ending things that can happen if people don’t pay attention.”

He attributes the attitude partly to his father’s military discipline. “My dad would tell me: ‘Wake up in the morning and do the best you can. And if you’re not up doing your best, go back to sleep,’” Arora says. “If you’ve got to show up, show up the best way possible.”

When ChatGPT was released, Arora was traveling to India to deliver a convocation address to 30,000 people at Banaras Hindu University. During a connection in Dubai, he opened ChatGPT and concluded that AI had moved from a research curiosity to a world-changing technology.

“I rewrote my speech on the flight between Dubai and Varanasi to talk about ChatGPT,” he recalls. “I said: ‘AI is like the invention of the iPhone. This is version zero of this technology; the moment you got your first app on your phone. If you play that movie forward, in about 10 years the whole world will turn upside down, and this is the first day of that event.’” Arora notes that he used the phrase “iPhone moment” months before Nvidia CEO Jensen Huang popularized it.

The seriousness and speed of AI’s impact on cybersecurity, however, may have been difficult to predict. The reported dangers of Mythos were followed in July by an incident involving OpenAI agents that escaped an internal sandbox and attacked open-source startup Hugging Face. The agents coordinated with one another, demonstrating the consequences of multiple AI agents pursuing a shared objective.

“AI doesn’t understand morals, it understands tactics,” Arora says. “Unconstrained agents, trained on the intelligence of all the content out there without setting their North Star, will do whatever it takes. If I said, ‘Your task is to capture the flag,’ remember it’s been trained on every good thing and bad thing on the internet … It won’t know morals. It just has information saying, ‘Sometimes if you can’t go in from the door, you break the window.’”

Mythos was not flawless in the April test. Arora estimates that 30% of the vulnerabilities it identified were not real. “If you were a skeptic, you’d say that Mythos doesn’t get it right,” he says. “But the problem is getting seven out of 10 right—that’s pretty good for the attacker. It’s not good for the defender.”

Arora says the average window to identify and repair a cybersecurity breach is three days, while an AI-powered cyberattack can unfold in 12 minutes. AI can probe systems cheaply and continuously at machine speed until it finds a way in. “It’s like bringing a battering ram to your front door, bought from Home Depot,” Arora says.

The Mythos and OpenAI-Hugging Face incidents point toward a future in which AI systems can identify vulnerabilities and decide to exploit them at speed and scale. A generational cyberattack has not yet occurred, but earlier incidents show the potential damage. In Ukraine, the 2017 NotPetya attack caused, among other effects, radiation-monitoring computers in Chernobyl to go offline and resulted in $10 billion in losses.

Arora’s response to the threat is connected to his broader management philosophy. A whiteboard in the conference room next to his office contains several of his rules, including “Sell what’s on the,” as well as warnings against organizational arrogance: “Our innovation is genius. Theirs is dumb luck.”

John Donovan, the former CEO of AT&T and a current Palo Alto Networks board member, says Arora is focused on the challenge ahead. “If you were to open his brain and look in, it always would be like Santa’s elf shop three days before Christmas,” Donovan says. “He wants to arrive at the most important thing first.”

Michael Grimes, Morgan Stanley’s chairman of investment banking, has worked with Arora on multiple deals. Grimes says Arora’s drive for clarity goes beyond the usual idea of being able to “see around corners.” “In his case, it’s like he can engineer a city without corners,” Grimes says.

Arora says the next AI security threat could emerge from almost anywhere, including a household vacuum cleaner. He describes receiving a robotic vacuum and realizing that its camera and microphone could create an attack surface—the full set of points where an intruder could try to enter a system. An attacker could potentially take control of the device’s listening and imaging functions and obtain pictures of a home, he says. “That sounds like a cyberattack.”

As the potential attack surface expands and the volume of AI traffic on the internet grows, Arora has become a prominent voice in discussions about AI and cybersecurity, both publicly and within Silicon Valley. The outcome matters to Palo Alto Networks and Arora, as well as to people facing an uncertain, AI-powered future. From here, the live questions include how governments continue to calibrate access to models like Mythos, whether AI labs succeed in selling their systems directly as security products, and whether Palo Alto Networks can convert its platform bet into more than the 6% market share it holds today.

Asked what he would want to know about the future, Arora declines to speculate. “That would make life so boring,” he says. “It defeats the purpose of the future. The whole point of the future is that it’s amazing, optimistic, and unknown. If we already knew the future, it wouldn’t be called the future.”

This article appears in the October/November 2026 issue of Fortune under the headline “Nikesh Arora: The man shaping a defense against AI’s darks side.” The story was originally featured on Fortune.com.

Source: https://fortune.com/2026/09/30/nikesh-arora-palo-alto-networks-ceo-ai-cybersecurity-defense/