Citi Wealth CIO Warns “Infinite AI Agents” Will Accelerate Cybersecurity’s Share of Enterprise Spending

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Cybersecurity budgets are dangerously undersized relative to the threat surface AI is creating, and the revenue growth at the sector’s leading vendors is starting to prove it. Kate Moore, CIO at Citi Wealth, framed the AI-driven expansion of enterprise attack surfaces as a structural spending shift, not a cycle. CrowdStrike posted 26% revenue growth with $5.5 billion in ARR, while Palo Alto Networks grew next-generation security ARR 60% year over year to $8.1 billion. The numbers confirm that enterprises are already accelerating security spend, and the vendors capturing consolidation deals are widening their leads fast.

What this means for your business

The “infinite AI agents” framing is doing real analytical work here, not just generating headlines. Traditional threat modeling assumes a countable number of adversaries probing a bounded perimeter. Agentic AI breaks both assumptions at once, because automated attack tooling scales horizontally across every exposed API, credential store, and data pipeline without human pacing. If your current security budget was sized against last year’s threat volume, it was already wrong before your organization deployed its first AI workflow.

The vendor performance data points to a consolidation dynamic worth watching. Palo Alto’s 60% next-gen ARR growth and 89% year-to-date stock appreciation aren’t being driven by net-new security spending alone. Enterprises are collapsing point solutions into platform contracts, and the vendors with the broadest platform coverage are capturing the consolidation premium. Zscaler’s 91% growth in enterprise AI usage across its network, set against a 33% stock decline, is the signal inside the noise: the underlying demand is real, but execution on go-to-market and platform breadth is deciding who captures it.

The budget question this reframes isn’t whether to spend more on security. It’s whether your current vendor mix positions you on the winning side of platform consolidation before your next renewal cycle. A point-solution portfolio that made sense in 2023 may now be carrying redundant coverage in some areas and genuine gaps in others, specifically around AI workload visibility and agentic access controls. The CISO who can map that gap clearly owns the internal argument for reallocation. The one who can’t will get the argument made for them, from the outside, after an incident.

Concept deep-dive: Agentic attack surface

An agentic attack surface is the total set of entry points created when AI agents, software programs that autonomously execute multi-step tasks across systems, are operating inside or around an enterprise environment. Unlike a human attacker, an AI agent can probe thousands of endpoints simultaneously without fatigue or pacing. For security architecture, this matters because controls designed around human-speed intrusion detection miss threats that move at machine speed across distributed systems, which is exactly why SentinelOne’s CEO frames the response as requiring “machine speed defense.”

Based on reporting from Citi Wealth CIO Warns “Infinite AI Agents” Will Accelerate Cybersecurity’s Share of Enterprise Spending, originally published 2026-07-21 14:59:00.

TAGGED:
Share This Article