Palo Alto Networks CEO Nikesh Arora said approximately $1 trillion of global cybersecurity infrastructure must be modernized to defend against AI-driven threats, according to the company's Q4 FY2026 earnings call held September 1, 2026.
Arora framed the figure as "cybersecurity debt" that enterprises cannot defer as artificial intelligence accelerates the speed and sophistication of automated attacks. Existing defenses were built over decades for human-paced threat detection and response and cannot handle adversaries that operate at machine speed without human intervention at each step.
The $1 trillion estimate encompasses legacy infrastructure across enterprises, government agencies and critical infrastructure operators worldwide. It includes firewalls, intrusion detection systems, security information and event management platforms, and endpoint protection tools deployed before large-scale AI weaponization became standard in threat operations. Most were designed to flag anomalies for human analysts to review; none were architected for continuous, autonomous defense against adaptive algorithms.
AI-driven attacks have compressed decision windows from hours to seconds. A human security team cannot manually respond to thousands of simultaneous, morphing attack vectors. Palo Alto and competitors including CrowdStrike, Fortinet and Cloudflare have begun embedding AI into their own platforms to automate threat detection and response. Arora's statement positions that shift as a business necessity: the alternative is obsolescence of the installed base.
The earnings call occurred as enterprises face dual pressures. Regulatory bodies including the Securities and Exchange Commission and the European Union's regulatory framework have begun holding boards accountable for breaches involving AI-enabled attacks. Insurance underwriters simultaneously have begun pricing in AI risk premiums and tightening coverage terms for firms still running legacy infrastructure.
Arora did not propose a timeline or mechanism for the modernization. Palo Alto itself is among the beneficiaries of any such cycle, with its own AI-native offerings positioned to capture market share from vendors unable to adapt legacy products fast enough. The company reported $1.7 billion in Q4 FY2026 revenue, up 13 percent year-over-year.
If $1 trillion enters a modernization cycle over five to seven years, the average annual spend would be $142 billion to $200 billion, compared to current annual global cybersecurity spending estimated near $180 billion. Arora argued that the existing market size itself is insufficient to absorb the necessary upgrade burden.
Enterprise budget cycles and board approval timelines will determine whether modernization accelerates or stalls. If half of the $1 trillion in legacy infrastructure remains in active use without upgrade by 2032, the cybersecurity installed base will remain vulnerable to attacks its operators cannot defend against at machine speed.