Artificial intelligence is often discussed as a threat to existing technology companies.
For cybersecurity firms, it may be the opposite.
CrowdStrike shares rose more than 10% after the company reported a record fiscal second quarter, raised its outlook and argued that the rapid adoption of AI is creating a substantially larger security opportunity.
The financial results support at least part of that argument.
CrowdStrike generated $1.47 billion in Q2 revenue, up 26% year over year, while annual recurring revenue reached $5.84 billion, up 25%. Net new ARR hit a record $333 million, increasing 51% from a year earlier.
CrowdStrike Is Accelerating Again
Cybersecurity investors have watched closely for signs that CrowdStrike's growth could slow as the company becomes larger.
Instead, several underlying indicators improved.
Accounts using Falcon Flex represented more than $2.29 billion in ending ARR, up 101% year over year.
Operating cash flow reached a quarterly record of approximately $530 million, while free cash flow reached $377 million.
Management also raised its fiscal 2027 net-new-ARR growth outlook by 630 basis points to roughly 34% growth at the midpoint.
Full-year revenue is now expected to reach approximately $5.99 billion to $6.01 billion.
That helps explain the immediate stock reaction.
But the AI-security thesis is what could determine the longer-term story.
AI Creates New Identities, Permissions and Attack Surfaces
CrowdStrike CEO George Kurtz described securing AI as potentially the company's largest market opportunity.
That argument is based on a straightforward security problem.
Traditional enterprise security primarily protects:
- employees, - endpoints, - servers, - cloud workloads, - applications, - and corporate data.
AI agents add a new category.
An autonomous agent may have permission to read databases, modify records, execute code, purchase services or communicate with other software systems.
That means companies increasingly need to answer:
Who created this agent?
What can it access?
What actions is it authorized to take?
Has its behavior changed?
Has an attacker compromised it?
Those are cybersecurity questions.
CrowdStrike recently introduced Continuous Identity for AI Agents, extending its security approach across human, machine and AI-agent identities.
Attackers Are Also Using AI
There is another side of the equation.
AI can make defenders more productive, but it can also make attackers faster.
AI is increasingly embedded in modern adversary operations, while security vendors are expanding detection and response systems across AI platforms and gateways.
Even without assuming dramatic autonomous cyberattacks, AI can reduce the cost of:
- phishing, - reconnaissance, - vulnerability analysis, - malware modification, - social engineering, - and attack automation.
More attacks do not automatically mean more revenue for security companies.
But they increase the incentive for enterprises to consolidate security tools around platforms capable of monitoring large volumes of activity continuously.
That supports CrowdStrike's platform strategy.
Platform Consolidation Remains Another Growth Driver
CrowdStrike's results also show customers adopting more modules.
At the end of Q2, approximately:
- 51% of subscription customers used six or more modules, - 35% used seven or more, - 26% used eight or more.
That matters because CrowdStrike is no longer simply an endpoint-protection company.
It competes across cloud security, identity, SIEM, observability, data protection and managed security services.
AI gives the company another reason to expand that platform.
If customers prefer one security layer spanning employees, workloads and autonomous agents, CrowdStrike could capture a larger share of security budgets even without the overall market growing dramatically.
The Valuation Risk Has Not Disappeared
Strong results do not eliminate valuation risk.
Cybersecurity remains one of the most competitive software markets, with Palo Alto Networks, Microsoft, SentinelOne, Zscaler and others competing for similar budgets.
CrowdStrike must also maintain customer trust after the July 2024 content-update incident that caused widespread Windows outages.
And if corporate AI adoption develops more slowly than expected, some of today's AI-security expectations may prove premature.
The company still needs to translate new AI products into durable ARR.
Why CrowdStrike's Quarter Matters
The most important idea coming out of CrowdStrike's earnings is counterintuitive.
AI does not necessarily reduce demand for security software by automating security work.
It may dramatically increase the number of digital actors that enterprises must secure.
Every employee already has an identity.
Every AI agent may eventually need one too.
As those agents gain access to corporate systems, the cost of getting security wrong increases.
CrowdStrike's record Q2 does not prove it will dominate that market.
But it provides evidence that cybersecurity spending is still expanding—and that AI may become an additional growth engine rather than a replacement threat.