Earnings | AI security demand turns into contract momentum
Billings are the scoreboard—but Zscaler’s “agentic” narrative is getting reflected in the recurring lines that billings ultimately feed
Investors want to know whether “agentic cyber” is turning into real contract demand—especially inside Secure Service Edge (SSE) and adjacent Zero Trust Security spend. In Zscaler’s latest reported quarter, the recurring metrics investors track (ARR, net new ARR, and deferred revenue) move in the direction you’d expect if sales motion is actually converting into billings—not just marketing momentum.
Revenue (quarter)
$815.8M
Q2 FY2026, reported Feb 26, 2026
ARR (run-rate)
$3.359B
Q2 FY2026, reported Feb 26, 2026
Net new ARR
+$155.5M
Q2 FY2026, reported Feb 26, 2026
Deferred revenue
$2.355B
Q2 FY2026, reported Feb 26, 2026
What changed vs. the AI-security “demo” argument
Zscaler’s agentic AI security emphasis is tied to governance and identity—so it can land as security controls, not just content
“Agentic cyber” can become noise if vendors merely show threats and not operational controls. Zscaler’s framing in its Q2 materials focuses on securing autonomous/agent activity via governance, monitoring, and treating non-human identities as first-class citizens inside its Zero Trust Exchange approach. That matters for conversion because enterprises buy controls they can operationalize: policy enforcement, access segmentation, and identity governance are measurable deployment items that can drive expansion within SSE/Zero Trust security footprints.
- Zscaler appointed a leadership role dedicated to agentic AI security engineering to build defenses against autonomous AI threats, aligning product development with enterprise governance needs.
- The company referenced an ecosystem partner for agent identity security, signaling that its agent-security concept is being treated like an identity/governance surface rather than a standalone model showcase.
- The easiest investor interpretation is that “agentic AI security” is being used to deepen existing Zero Trust Exchange adoption—so billings conversion should express itself in ARR and deferred revenue over time.
Data check: the quarter’s conversion signals
Beat-and-raise logic: recurring momentum + deferred revenue growth are the closest publicly verifiable path from ARR to billings
Billings can be volatile quarter to quarter, but for subscription-style security platforms, investors often use ARR and deferred revenue as higher-confidence indicators of contracted demand. In Zscaler’s Q2 FY2026 disclosure, revenue growth and the ARR/deferred-revenue combination strongly suggest customers are not pausing Zero Trust/SSE deployments even as AI threat narratives intensify.
| Metric | Value | What it implies for billings conversion |
|---|---|---|
| Revenue | $815.8M | Top-line growth alongside recurring metrics |
| ARR | $3.359B | Contract run-rate expanding |
| Net new ARR | +$155.5M | Gross-to-net expansion momentum |
| Deferred revenue | $2.355B | Customers are prepaying/contracting, not just evaluating |
Supply-chain aware: how “AI security demand” actually gets transmitted
The demand transmission path runs through identity, policy enforcement, and analytics—not through “agent demos”
To make this full-stack, it helps to map what enterprises must buy when they adopt AI-driven workflows. The immediate needs usually include (1) identity and access for users and non-human actors, (2) policy enforcement at the edge (SSE/Zero Trust), and (3) telemetry/analytics that can make security decisions. Vendors that package AI risk into these operational layers can show billings conversion earlier than vendors who only emphasize AI threat content.
- Upstream layer (platform enablement): identity and agent frameworks—buyers can’t secure “agents” until identities and policy surfaces exist.
- Core layer (edge enforcement / SSE): enforcement nodes and policy delivery determine whether deployments stick and expand.
- Downstream layer (enterprise buyers): security teams convert AI risk into contract renewals, expansions, and new seat/site commitments when controls reduce breach risk.
What to watch next (two horizons)
Short-term: whether ARR/deferred revenue remain resilient while AI threats intensify; long-term: whether agent governance becomes a durable expansion driver
In the short term, the key investor question is whether Zscaler can keep ARR growth and deferred revenue trending up while revenue scales—because that’s the operational sign of billings conversion. In the longer run (1–3 years), the durable test is whether “agentic AI security” becomes a repeatable expansion motion: customers add governed agent access and policy controls as they operationalize autonomous AI workflows.
- Next quarter check: continued ARR growth and deferred revenue increases, not just headline revenue.
- 1–3 year check: whether agent-security governance becomes a new attach motion across ZIA/ZPA and adjacent segmentation/cspm-style controls.
How other listed security platforms may show the same “AI-to-contract” test
- If enterprise endpoint consolidation continues, CrowdStrike should convert AI-driven breach urgency into higher renewal and expansion in coming quarters.
- A continued focus on operational protection is likely to show up first in contract momentum (not just threat intel marketing).
- Over 1–3 years, persistence of platform-based expansion should pressure peers that lack governance/containment depth.
- AI-era identity complexity can increase demand, but Okta faces churn risk if buyers treat agent governance as optional.
- In the next 1–2 quarters, watch for whether recurring revenue lines re-accelerate alongside identity-security attach.
- Over 1–3 years, agent identity could be a tailwind if it becomes a governed policy surface rather than a standalone add-on.
- Palo Alto Networks tends to monetize platform breadth through upsell, which can translate AI security urgency into higher contract value.
- If breach-prevention spend rises, next-quarter revenue mix should reflect more platform consumption.
- Over 1–3 years, platformization should keep margins supported relative to single-control vendors.
- Netskope is exposed to SSE/visibility budget cycles, so its billings conversion will likely hinge on whether AI-related deployment becomes standardized.
- Near term, watch for whether retention and expansion stabilize as buyers move from AI pilots to production controls.
- By 1–3 years, success depends on turning AI-driven risk into repeatable policy enforcement modules.
