Earnings + AI security demand signals
The market finally got a measurable answer to the “hype vs. billings” AI-security question
The fastest way to separate AI-security hype from real budgeting is to look for the accounting proof: subscription revenue growth, backlog/RPO strength, and guidance raises—not just product announcements.
In the latest reporting cycle, CrowdStrike and Okta both put up results that fit that test. CrowdStrike reported Q2 FY2027 total revenue of $1.47B with record net new ARR of $333M and ending ARR tied to Falcon Flex adoption that exceeds $2.29B. Okta reported Q2 FY2026 revenue of $728M (+13% YoY) and raised FY2026 guidance (10%–11% revenue growth). Those are the financial traces that AI-driven threat pressure is translating into new security and identity commitments.
CrowdStrike (Q2 FY2027)
$1.47B
Total revenue, reported for the quarter ended Jul 31, 2026
CrowdStrike (net new ARR)
$333M
Record net new ARR, reported for the quarter ended Jul 31, 2026
CrowdStrike (Falcon Flex adopters)
$2.29B+
Ending ARR from accounts that adopted Falcon Flex (as disclosed in earnings materials)
Okta (Q2 FY2026)
$728M
Total revenue, for the quarter ended Jul 31, 2025
Okta (subscription revenue)
$711M
Subscription revenue, for the quarter ended Jul 31, 2025
Okta (FY2026 revenue outlook)
10%–11%
Raised total revenue growth guidance for FY2026 (company outlook)
What changed under the hood
CrowdStrike’s “Falcon Flex” and Okta’s “agent identity” framing both point to the same spending mechanism
AI is changing breach economics. Attacks are increasingly automated, and the blast radius expands when AI agents gain access to multiple back-end identities and service accounts.
CrowdStrike’s earnings narrative links AI adoption to a “largest market opportunity” and shows how that narrative is getting monetized through Falcon Flex adoption—explicitly disclosed as ending ARR exceeding $2.29B from Flex-adopting accounts. On the identity side, Okta’s earnings call discussed AI-agent connectivity pain (“every agent wants to connect to 10 service accounts”), and tied identity compromise as a common start point for cyber events (“over 80%” start with compromised identity). That combination describes a supply-chain shift in how incidents move: AI agents increase identity exposure; security vendors monetize faster when the exposure becomes paid deployment, not just trial interest.
Supply-chain read-through
Why this matters beyond CrowdStrike and Okta: it reframes the security budget as an AI-driven “risk line item”
- Identity compromise as a starting point supports broader ZTNA/identity governance demand rather than narrow endpoint-only purchases, helping explain why Okta’s RPO and guidance stayed constructive.
- Falcon Flex monetization suggests bundle-resistant security modules can still expand when customers treat AI risk as a deployment requirement instead of a one-off add-on.
- Agent/service-account coupling makes “token hygiene” and access controls inseparable, increasing the chance security buyers consolidate across identity plus detection/response stacks.
Investors often debated whether large cloud suites—especially Microsoft—would compress standalone security. The investor-relevant nuance here is not whether suites can bundle; it’s whether AI-era incidents force customers to buy capabilities that suites either don’t fully cover or don’t satisfy end-to-end fast enough.
Based on the disclosed metrics in these two earnings cycles, the market is treating AI-related cyber risk as a measurable, recurring budget line. That increases the odds that specialized vendors keep earning incremental share even inside heterogeneous, multi-vendor enterprise stacks.
Fundamentals check: what the numbers imply about durability
The beats aren’t just quarter-specific—they include guidance strength and adoption metrics investors can underwrite
| Company | Period | Revenue / ARR metric | What it indicates |
|---|---|---|---|
| CrowdStrike | Q2 FY2027 (ended Jul 31, 2026) | Total revenue: $1.47B; Net new ARR: $333M | Strong subscription momentum and recurring monetization |
| CrowdStrike | Q2 FY2027 (ended Jul 31, 2026) | Ending ARR from Falcon Flex adopters: $2.29B+ | Adoption metric tied to AI/security bundling resistance |
| Okta | Q2 FY2026 (ended Jul 31, 2025) | Total revenue: $728M (+13% YoY) | Identity spend staying resilient and accelerating |
| Okta | FY2026 outlook | Raised total revenue growth: 10%–11% | Guidance strength consistent with sustained demand |
For investors, the underwrite is in two places. First, subscription economics (CrowdStrike’s ARR and net new ARR). Second, visibility (Okta’s raised FY2026 growth expectations and the call’s quantified identity-linked threat framing). When both sides point to recurring adoption rather than one-off projects, the probability of multi-quarter security budget reallocation rises.
Horizons
Near-term winners are the security vendors who can quantify adoption; the long-term risk is overestimating how fast suites will fully respond
Short term (days to quarters): these reports should shift earnings quality expectations across the group. If AI-driven incidents are now translating into paid deployments, investors may reward backlog/adoption disclosures more than product headlines.
Long term (1–3 years): the sustainability hinges on whether enterprises keep treating AI risk as an ongoing controls upgrade. CrowdStrike’s Flex adoption ARR metric and Okta’s raised FY2026 outlook support that path, but the counterforce is suite bundling—where Microsoft and other platforms could accelerate native controls. The key variable to watch isn’t whether bundling exists; it’s whether standalone vendors continue to show measurable incremental adoption within recurring revenue.
Where the AI-threat-to-revenue read-through is most investable
- CrowdStrike’s Q2 FY2027 record net new ARR of $333M reinforces durable recurring momentum into near-term investor underwriting.
- Falcon Flex adoption exceeds $2.29B ending ARR from Flex adopters, supporting the thesis that AI-driven security demand monetizes via new packages.
- Okta’s Q2 FY2026 revenue hit $728M (+13% YoY), indicating AI-era security and identity budgets are still expanding.
- Raised FY2026 guidance puts revenue growth at 10%–11%, making the AI-threat-to-identity spend read-through more than a one-quarter story.
- If identity-linked compromises keep rising, Zscaler’s ZPA/ZIA demand could track broader zero-trust deployments—but proof will depend on upcoming quarters’ billings/backlog.
- Near term, investors should watch whether AI-agent risk translates into repeatable subscription expansion rather than project timing.
- Bundling pressure can limit standalone pricing power for some security modules when suite-native controls satisfy buyer requirements.
- But CrowdStrike/Okta results suggest buyers still pay for specialized stacks—making MSFT’s net takeaway dependent on suite coverage breadth and time-to-remediation.
