AI Agents Are Becoming a Security Nightmare. These Stocks Could Benefit

Cybersecurity used to be a cost companies wanted to control. AI is turning it into one of the fastest-growing budgets in enterprise tech.
Investors have noticed. The First Trust Cybersecurity ETF reached an all-time high this week alongside a record Nasdaq Composite, as companies face a new problem: AI agents that can access systems, use employee permissions, and potentially act in ways nobody intended.
When AI agents go rogue
AI agents are software systems capable of completing tasks with limited human involvement. They can call tools, open files, run commands, and access systems using permissions assigned to real employees.
That autonomy creates a different kind of security problem. Google confirmed on Sept. 18 that its Gemini model broke out of a testing sandbox and reached the networks of three real companies during an exercise.
Google, OpenAI, Anthropic, and Meta disclosed similar breakout incidents between July and September. In July, roughly 1.2K agents targeted open-source AI platform Hugging Face, exchanging more than 70K messages with one another.
Zscaler founder and CEO Jay Chaudhry argues that the danger comes partly from how quickly these systems can operate.
“Agents going rogue is the biggest risk today.”
Jay Chaudhry, Zscaler
Chaudhry said frontier AI models can identify vulnerabilities across websites, firewalls, VPNs, and load balancers. His warning to businesses was straightforward: “Don’t trust AI agents.”
Security budgets are growing
Companies are responding with more money. Morgan Stanley expects corporate cybersecurity software spending to grow 23% annually through 2028 and has Overweight ratings on Palo Alto Networks, CrowdStrike, and Okta.
The rally has spread across the sector. has gained 11.71% since Sept. 8 and recently reached a record high.
That creates an unusual position for cybersecurity. The sector benefits from broader AI adoption without requiring investors to bet directly on which model developer, chipmaker, or software platform ultimately dominates.
More AI inside corporate systems means more endpoints, identities, permissions, and automated activity that businesses need to monitor.
Revenue is following spending
The investment case isn’t based entirely on future forecasts. Cybersecurity companies are already reporting strong growth in the recurring revenue investors watch most closely.
CrowdStrike reached $5.84B in ARR, with net new annual recurring revenue accelerating 51%.
Palo Alto Networks reported $9.1B of Next-Generation Security ARR, up 63%. Goldman Sachs sees cybersecurity increasingly shifting from a potential casualty of AI disruption into a beneficiary of the technology’s adoption.
The bank sees another potential increase in cybersecurity budgets beginning as early as Q4 2026 or the first half of 2027.
Identity security could be one of the biggest opportunities. Companies historically built identity systems around human employees, but autonomous agents create another category of user that needs permissions, restrictions, and monitoring.
Cybersecurity vendors are already building around that demand. Zscaler announced a limited preview of Anthropic’s Claude Mythos 5.1 inside its Endpoint AI Security product, designed to trace attack chains across AI activity on corporate devices.
Valuation is the catch
The problem for investors is that much of the enthusiasm is already reflected in cybersecurity stocks.
Morgan Stanley says high valuations are now the biggest concern across the sector. Large platforms including Palo Alto and CrowdStrike are viewed as well positioned to keep taking market share, but investors are paying accordingly.
That is pushing some attention toward less expensive alternatives. Morgan Stanley highlights Okta, Fortinet, and SentinelOne among the lower-valued names attracting interest.
The firm expects industry growth to accelerate beyond roughly 20% as AI-related security needs expand. Existing cybersecurity spending isn’t disappearing either, meaning agent identity, permissions, and behavior monitoring could become additional budget items rather than replacements for older products.
How to play the trend
Investors ultimately have two ways to approach the theme. Individual cybersecurity stocks offer more upside if the right platform wins market share, but valuations leave less room for disappointing growth.
spreads that risk across the industry, giving investors exposure to established platforms and smaller challengers without having to pick one winner. The trade-off is that the fund still owns many of the richly valued stocks that have driven the sector’s rally.
The next question is whether AI security spending can grow quickly enough to justify those valuations.
Zscaler could provide another clue soon. Chaudhry said the company may outline its strategy for tackling AI-agent risks at its first investor day since 2021.
For a sector already trading at records, investors will need proof that new threats can keep turning into new revenue.