# Enterprise AI Strategy, Token Economics, and Cybersecurity Shifts

**Podcast:** The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch
**Published:** 2026-06-22

## Transcript

I think the long-term token pricing should be one-tenth of what it is today.
Mythos ended up, I think ends up being an accelerant to cybersecurity.
In technology, you miss one trick, you can survive.
You miss two tricks, you're partly impaled.
You miss three tricks, you could be obsolete.
I came to the United States with two suitcases, $200, and I was willing to do anything, anything at all, to make sure that I made a life for myself because there was no...
way to go back.
When I came to the United States, I was a security guard.
I took notes to the disabled.
I flipped burgers at Burger King.
I had $200.
I had to find a way of paying my tuition.
This is 20VC with me, Harry Stebbings.
In the hot seat today, we have Nikesh Arora.
Nikesh is the CEO of Palo Alto Networks.
They have a market cap of 225.
billion.
Nikesh is one of the most respected operators in technology.
Before, he was CMO at Google, of all things, and I questioned him on marketing in this show, and then he's like, well, I was CMO of Google.
God, there are some moments when I think, Harry, you should stop talking.
He's an old friend, but this was a very authentic and honest discussion in a way that I don't think you could have had without that friendship.
It was in person in London.
Nikesh, here, is one of the best that I've ever seen him.
But before we dive into the show today, you have the idea, but often with AI tools, you hit a wall.
Well, Base44 is where that friction disappears, turning how you talk into how you build.
Full stack web and mobile apps, sites, autonomous super agents, all built in minutes, not weekends spent on damn configuration.
Base44 ships it all out of the box, the backend, the database, the authentication, and the hosting.
It handles the heavy lifting, so you can just stay in the flow.
It doesn't just replace the busy work.
it multiplies you.
It makes you so much more capable, an effective version of yourself.
In this market, being fast is the baseline, but to win, you gotta be first.
And Base 44 is that edge.
It's the move that lets you skip the troubleshooting and get straight to the breakthrough.
Launch your next big thing at base44.com.
That's base44.com.
After Base44 helps you launch, Corgi helps you cover what comes next.
My word, what an arresting first line.
Get your ass covered with Corgi insurance, and I'll tell you why.
If you're running a business right now, you already know this pain all too well.
Getting insurance, it's really slow, it's confusing, and my word, it's full of paperwork.
Well, that's exactly why Corgi is here to change the game.
Corgi is the first and only insurance carrier designed specifically for tech companies, allowing you to get covered in minutes instead of- days, Corgi provides essential coverages for all growth stages such as DNO, E&O liability, cyber, commercial, general liability and more.
Get your ass covered.
I love the way we say ass with Corgi Insurance alongside thousands of other startups at corgi.com forward slash 20VC today.
That's corgi.com forward slash 20VC.
You won't regret it.
While Corgi handles the coverage, Turing handles the talent.
Frontier Labs keep face...
the same limitation.
Models perform well on benchmarks, but they fall short once they enter real coding tasks, real tools, and real workflows.
That disconnect between synthetic evaluation and actual system behavior is now a core blocker for organic models.
That's why NVIDIA, Anthropics, Salesforce, Gemini, and other leading lab partners partner with Turing.
Turing is the research accelerator focused on post-training reliability.
They build realistic RL environments, next-generation data quality systems built.
from real-world operational traces and coding datasets that stress models under conditions where failures matter, state changes, workflow branching, brittle tool calls, and the coding errors that break RL agents but never appear in benchmark reports.
In reality, a model may demonstrate correct reasoning in your evaluation setup, yet still select the wrong parameter or mishandle a code update in a realistic interface.
Turing makes that failure visible and gives teams the signal they need to fix it.
For labs, You have now arrived at your destination.
Nikesh, last time we did a show, I was 22 hours into a 24-hour fast.
And I listen back now, and I just think, my word, you had the audacity to be with one of the OGs of this business and be hangry.
Like, I was hangry with you and short-tempered.
Well, the good news is I told you earlier in the chatting, I have...
Total memory loss.
I have no recollection of what I said and what we talked about, so I have to go back to listen to it.
Just happy to be here.
It was a great show.
We got on blissfully well.
It was wonderful.
I don't know what that was about.
I think we should stop doing podcasts remotely.
God, I agree.
I think you should force people to come in here.
So I actually do.
Good.
And the nice thing about size is they do.
But A, the only challenge is they actually sometimes come quite jet-lagged because they come like all the day.
And that's a little bit tough.
Maybe you should do it at 11 p.m.?
Maybe.
Yeah, if you take people from California, it's a perfectly nice time for them at 10 p.m.
or 9 p.m.
Maybe you need to.
And maybe I need to adjust.
I'm the selfish one.
You know, Mark Andreessen said something to me.
Mark Andreessen said, I really actually embraced it.
I haven't even got the first question, but fuck it.
He said, you need to embrace, how is it all your fault?
If you embrace everything in life with, how is it my fault?
Actually, a lot of the world changes.
Actually, let's spin that a bit.
How do I make it better?
change the outlook is how do I make it better?
What can I do to make this better?
That's how I run my day and I run my life with my company.
How can I make it incrementally better today?
And how can I make it radically better in three years?
Have you ever had something that you couldn't make better?
Not for the lack of trying.
So all you can do is try.
If it works out, it's great.
And if you try a lot, you succeed more often than you think.
We were talking downstairs about your personal brand and speaking of making it better.
I don't think about it like you do because this is what you do for a living.
I think about running my business.
Okay, so I think this is fundamentally wrong.
I'm here to learn.
Teach me, Harry.
I'm here to learn.
Teach me.
The audacity of podcaster.
That's all right.
No, but I actually think your personal brand is your business.
I think if you build a great product...
a great company, people like your product, eventually your brand survives all of it.
I think you can have a great brand, shitty product, shitty execution, and your brand goes to hell in a handbasket.
So I flip around.
Do you think that is still the case today, though?
I think brand can be such an accelerant today, especially in a world where it's just so noisy.
See, I spent many years at Google, as you know.
I spent, I actually was chief marketing officer for five years.
And if you look historically in technology, there are companies which have died who had great brands.
Remember Sun Microsystems?
It's a darling 30 years ago.
It doesn't exist.
Why?
Because their brand went dead or the product went to hell?
What about Yahoo?
Remember that company?
It's a great brand.
Amazing.
Why?
It's way before Google.
I think it's probably a fraction, probably even two decimal point number versus what Google is.
So I think product helps make brands but i think those were founded and broke into the public diaspora when there was much less noise and so i think if you were to put that today you need to have a brand first to get into look they let me speak against my own thesis there's a spectrum okay on one end of the spectrum is when you have real differentiated product in which case the product helps build the brand google search is now you google something right on the other hand it's a commodity it's water i don't know why this is called evian right but this is a commodity here only brand matters So it depends where you are on the spectrum.
If all you are a commoditized product, yes, brand matters a lot.
If you are a differentiated product, then you build a brand on the back of the differentiated product, and you can decide where you want to be in that spectrum.
Speaking of that brand, I saw your tweet, and I was like, this is masterful.
But you tweeted, the frontier model problem is a breadth versus depth problem.
Yes.
Can you explain that to me?
Yeah, look, I've been listening to some of your podcasts, and I've been paying attention to what happens to market because...
I want to understand where all this settles down, not just because I want to understand it, but it also impacts how I build my own business.
So you've got these phenomenal frontier models, and they keep sort of leapfrogging each other.
Every few days, there's a net new model that's delivered by OpenAI or by Google or by our friends at Anthropic.
And the question becomes, okay, fine.
These models are moving at this pace.
What do I need to build?
What do I need to do with these models?
And as we came to that Mythos moment when everybody was busy chasing Mythos, and that was kind of important, you realize even the best model has a high false positive rate.
But for some reason, in the consumer space, we don't seem to care.
I was talking to my sister this morning.
I just went to ChatGPT and asked all these questions.
It was very helpful.
So I guess what happens is the consumers are way more tolerant of false positives because it's always the person in the middle, right?
There's always somebody who's...
understanding what the model says and making their own judgment whether they believe the model or not.
And somehow people get rid of some false positives.
Somehow people don't care about the false positives.
Sometimes people believe the false positives.
So the consumer is highly tolerant on this notion of false positives and doesn't seem to distinguish.
And it just seems to get better and better.
I literally had...
Gem and I produced an investment memorandum for something I was looking at.
I looked at it, it looked pretty accurate, give or take, I'd tweak a few things, but it seems passable.
So on the consumer side, it's a breadth issue, right?
It wrote an investment memorandum for me, which is cool.
I would have had to hire a banker and a bunch of investment analysts that have taken me days and I did it in four minutes.
So the breadth is there, which means it's my go-to place.
And as you know, in consumer, if you become the go-to brand, talking about brands, it's hugely beneficial, right?
Whether it's YouTube, that's the only place to go look for streaming video, or Google, that's the only place to go do a search.
It becomes hugely multiplicative from a distribution perspective.
So our frontier model friends are chasing the consumer brand, and the false positive doesn't matter.
On the enterprise side, false positives matter a lot.
They matter because if you imagine a future...
where an agent's going to make independent decisions and act on it, you have zero tolerance for false positives.
Now, take Waymo.
In my view, Waymo is the biggest agentic product that is out there because guess what?
You've replaced a human being called a driver, right?
All decisions are made by AI machine learning.
It decides when to turn, when to stop, what to do.
But think about the amount of edge case training it took to replace that human agent with effectively an AI-driven agent.
I don't know, tens of billions of dollars.
So that's what it takes to take one use case and train the hell out of it.
And if you think about what happened there, they could have used equivalent of an AI model, but then they built so much context and intelligence and edge case training and proprietary data to make that happen.
That data is not available on the internet.
You can't stick the next model of Anthropic into your Mercedes and say, okay, drive me home.
It's not going to be able to do it.
And that's the depth issue, right?
Because you need the depth of the context and understanding and the intelligence around the model to make it useful for the truly agentic use case.
So I just think there's this constant tension.
The frontier models want the consumer attention because that drives post-training for models.
It drives the consumer brand of the model.
On the other hand, the real enterprise revenue is going to come from use cases that require a lot more context.
The one sort of standout use case we all know is coding.
Coding is a universal activity.
Everybody does it.
So everybody's data is helpful in training the model.
And that becomes sort of a large enterprise application.
Hopefully there's a few more out there.
But I think that's the tension that I wrote about.
When you think about the workflows and the way that enterprises are engaging with AI stand, specifically models.
What extent do you think we will be locked in a frontier model dominant world versus the majority of enterprise workflows can be done with open source and we will be more cost efficient moving towards them most of the time?
I think more than half the enterprises are still not getting it right on the use of AI perspective.
I think we're still busy trying to incorporate AI into our current business practices.
So how do I take what I do today, use a little bit of AI, get marginally more efficient because I don't want to do this.
the old way.
I think the opportunity is to rethink your workflow fundamentally with AI.
That's where the true benefit's going to come.
I think the winners in the long term are people who actually rethink their companies with AI, not people who adapt their current workflows marginally with AI.
How can you do that if you're an enterprise?
So we have thousands of CEOs of big enterprises that listen.
That sounds great.
What do I do?
Do I do a brainstorming session?
No, I think there's going to be...
perhaps two or three different categories.
One category is, let's take the workflows of today.
We have workflows around ERP.
We have workflows around sales team management.
We have workflows around human resource management.
There are existing workflows which have been SaaSified, as in some software company decided, we all have common processes.
Let me build a container where these common processes can be marginally customized by enterprise.
They can code their workflow into my SaaS application, and we're off to the races.
Now, that workflow...
require a lot of human judgment and human interaction.
The software is not intelligent.
It's been coded, right?
You define input, you define output.
I do the input, I know what the output will get.
The idea is imagine workflows where, in the hiring process, most of your workflows are containers.
Imagine where AI actually is helping you make judgments.
If I put every CV into AI and say, these are 20 people you should interview.
This look to the CV, you should ask this person these following questions.
Sends a note to Harry saying, interviewing this person, ask the following 10 questions because your three other colleagues only asked the following five.
We need no false positives of the human being.
So AI could be hugely helpful in informing and making the process more intelligent.
But that requires us to give up human control.
and let AI do 80% of the thinking for us.
That's not how we're doing it right now.
All we're doing is, let's take this invoice, let's scan it, abstract the data, put it into AI, and say, look at that, it's happening 20% faster.
Do you think we are willing to give up that human control?
You see cases like Matters today where I think 1,700 people have signed a petition that they are unwilling to let it track their mouse and keystroke behavior.
We are seeing resistance to giving the data.
Autogamous points.
I think two different points.
I think mass collection of data to inform AI.
is a little dangerous because people see the outcome of what that's going to happen, right?
And I've heard of companies where people are using cameras to track people, folding laundry, and ironing clothes because they want to be able to train physically in the future to do those things.
So that part aside, I think on the enterprise side, we can actually run a business much more effectively and efficiently if we decide where we are willing to relinquish control to AI.
Perfect example, marketing, right?
Anything that is required to train a marketing model.
is already out in public domain.
By definition, marketing is public domain, right?
If it didn't market it, it's not in public domain.
So I have the best training data in marketing.
I don't need to train an AI model with more marketing content.
I may need to train it for tone of voice and what my brand is.
And I'm pretty sure an AI model, if I throw my marketing collateral into it, will tell me, this is not consistent with your brand.
If I look at all the things you've been talking about the last 10 years, I think some people have done that.
They've actually analyzed earning scripts of companies and said, the last 20 years, what has company X done?
And when does the CEO start getting with?
from a topic because perhaps it's not going so well.
So this is really smart.
They can do that stuff.
So it's the best marketing training database in the world, the Frontier Models.
Why do I need 400, 600 people in marketing?
Because my biggest problem in marketing is I have 600 people, but I'm not sure they all fully understand how to consistently deliver my tone of voice, my value proposition, and how not to break my brand by having different collateral in the public domain.
You have 600 people in marketing.
Give or take, I'm 21,000 people.
Well, it's not going to be 600.
No.
What is it going to be?
I don't know.
My rule of thumb is that in the next three years, we'll probably have half the people in G&A type activities in companies.
Things like marketing, things like finance, things like HR.
Because there's a lot of process management there.
A lot of process management can be made more intelligent using some version of an adapted future AI application, for lack of a better word.
So SaaS applications will give away AI applications.
The difference being SaaS applications have no opinion.
AI applications will have opinions.
That's a fundamental rethink we need from a workflow perspective.
Can you just help me out?
AI applications will have opinions.
What does that mean in terms of how you use them in terms of the output that they have?
Everything, right?
You're a scholar, whether you want to call it an AI assistant, AI marketing assistant, AI HR assistant is going to say, I looked at your copy.
It sucks.
It's not good enough.
It's not consistent with the tone of voice.
Here's what I would recommend.
This has an opinion.
That will make my average employee much smarter than they were today.
Then I don't need so many of them because they're doing most of the work for you.
What would you say to the people that say you're wrong?
We won't see that halving of those functions.
And actually, marketing teams will create more copy, more content, be in more places.
I think the places where people could be wrong is how many technical resources we need in the future.
I think we need more, not less.
I think there's this fallacy.
People believe we're going to have less people working because AI is going to take over our jobs.
I don't believe that.
I think what's going to happen is...
You can't imagine the number of people on my team who want more technical resources, more AI-savvy resources, because they want exactly these things.
It's like, oh, I've got an amazing project to transform marketing.
I've got an amazing project to transform HR.
What do you need?
Oh, I need more people who understand how to prompt frontier models, build harnesses, bring proprietary data into play, bring moats.
I need more compute, more storage, because I want to learn everything.
So I think we're going to need more technical resources.
I think we're going to need more sales resources.
Because if your product's really good, you need more people to go out there and cover the universe because not enough people know about it.
I'm in Europe.
I met 20 customers last week.
I still see half of them don't know all the stuff we have.
I'm like, dude, we've been around for 20 years.
Why is my team not out there pounding the pavement, telling them everything we do?
And the problem is not enough time in a day because I'm too busy dealing with some arcane piece of software at work, which I have to go feed.
Well, if I had that software be really intelligent, it'd tell me what to do.
In terms of wanting more technical resources, tokens I would put in them.
more technical resources camp.
How do you think about effective token allocations today?
You're seeing very different camps from your Metas and Ubers and Microsofts who put in budgets to your free-for-all, be creative.
How do you approach it?
I know this whole world of token maxing has kind of gone topsy-turvy with the whole conversation around how many tokens people are using.
The challenge right now is 90% of the enterprise employees are not AI savvy.
They're not.
They have to learn.
I can't send them to university.
There's no course you can take in any school anywhere.
They have to be able to learn of their own.
I think we're back to a Darwinian moment where everybody has to figure out who's really good.
Now, you've seen people like Brian Armstrong and Jack Dorsey go out and say, I'm going to decimate my organization.
I'm going to start building from scratch.
And they've gone to some version of 30%, 40% less people because they've figured out there is no redemption.
I can't train these people.
I'm going to just find the people who are going to come in and help me do this stuff.
That's one model.
The other model is sort of gradual.
We've been hiring people only through hackathons now.
We see natural attrition of 2%, give or take a month, and we just replace them with people who actually are AI-savvy people who are from hackathons.
Give me 12 months, I'll have transformed 20%, 25% of my team.
Give me three years, I'll have hopefully enough AI-savvy people working at Palo Alto.
So there are two different ways to get there.
I think part of what you're seeing in the token maxing world is people are learning, people are experimenting.
The risk is your smartest employee who knows how to use AI really well could be using 20 times the tokens that an average employee uses.
And if you get into this whack-a-mole moment saying, oh my God, I'm going to stop people spending too many tokens, you actually will hurt the best AI savvy people more than you will hurt the average employee.
And by the way, I think the best talent will want to go where they will be best equipped with the most expensive frontier models, the biggest budgets.
I think that will almost be like an employee benefit.
Yes, possibly.
But I think part of the challenge is, you know, right now, everybody's experimenting on everything.
And you have to figure out what is it that I need to build as an enterprise?
And what can I get off the shelf?
If I can get an AI-based thinking application that does marketing for me, I don't need to build it.
It's a generic problem everybody needs to solve.
I can tweak it, I can customize it just the way I did with SaaS applications, but I don't need to build mine from scratch.
So I've made sure that everything my team is building is proprietary to us.
This is where do we have unique, distinguished knowledge that we bring to bear, which nobody else can do on the outside.
Let's put that, let's package it, let's use it.
Where it's going to be a generic AI application 12 months, 24 months from now, let's just wait.
So you have a free-for-all on tokens, so to allow your team to do the best.
We have a...
use judiciously model for tokens.
It's not a free-for-all.
Free-for-all sounds like you can go token max the hell out of it.
We have to use it judiciously and we keep track of it to see what people are doing.
And if we find somebody who's using it well, we won't constrain them.
If we find somebody who's gone a little over the top, we'll find a way to.
Benioff said the other day that he spends $300 million on Anthropik a year for his devs and that works out to be about 3.8% of developer salary spend average.
If it stays there, The valuations of Anthropic and OpenAI are grossly overvalued.
And if it moves to 20%, they're actually very undervalued.
And if it becomes what Brandon at McCaw said, which is we'll spend as much on tokens as we do on salaries, they're grossly undervalued, grossly undervalued.
I want to talk about where you think percent of developer salary spent on tokens will be in three years.
That's still a narrow lens for me.
If I abstract, if I step back today, there's not enough compute.
for what the world is demanding.
Unequivocally, not enough compute.
You can't buy compute.
Compute is costing 2 to 3x or 4x more than it used to cost two years ago.
There's not enough compute.
That scarcity of compute and that excess cost required to build and deliver compute, which allows us to go make AI useful, is causing the constraint and forcing pricing.
And interestingly, more than half of the compute is going to feed the consumer, which is a fundamentally loss-making entity right now.
I don't think any of the frontier models make any money in trying to get you and me to use ChatGPD or Claude or Gemini every day.
It's free.
That's a lot of compute.
Imagine there's billions of people around the world using for all kinds of queries every day.
That's sucking away half the compute, which is making no return.
guess where the pressure goes?
The pressure goes on the other half of compute, which is being used for coding in enterprise applications.
So now you're saying enterprise applications coding have to pay until we build transaction models or advertising models on the consumer side because they're not ready.
Now, you can say, well, that happened in search too, right?
Google search was around, that happened to YouTube.
People used a lot of YouTube, a lot of compute, but it wasn't paying for itself.
The problem is the compute requirements and the cost is now 10x of that when we were in that era versus today.
That's forcing token prices to go up.
I think the long-term token pricing should be one-tenth of what it is today.
When that happens, you will see that people will consume more.
You can decide if 3.8 or 15.8 is not sure we can tell the answer right now, because pricing will move very drastically in the next three to five years.
Sorry, so you think we'll see dramatic reductions in token prices?
I think so.
I think in the next three or five years, we will see reduction in token pricing.
I think at some point in time, the consumer use of AI will get constrained by these Frontier AI companies because they have enough post-training data, more than they need, and each user is inherently unprofitable in their activities they do in Frontier AI models.
Do you not think they just build advertising engines like OpenAI is doing now to pay for that business?
You know, that's an interesting question.
It has to come from somewhere.
When I started Google in 2004, we were 2% of the global advertising revenue, and global advertising revenue, the estimated between $500, $600 billion.
I think online is about 70% by last count of total advertising revenue.
And I don't think the overall number has changed by more than 3% a year or 5% a year.
So I don't think the total advertising pie is going to increase.
We've already taken away 60%, 70% of the advertising pie in the online world.
Unless you tell me there's going to be an explosion at the top where more people are going to spend more money in marketing, that money that you're hoping to fund consumer AI from advertising will have to come from current advertising revenues.
So I don't think that changes the equation drastically to make the consumer profitable.
I do think there's an opportunity that AI ends up taking more transaction revenue, which has not been into the purview of AI.
Can you explain that to me?
Well, think about the marketing chain, right?
We do advertising.
Advertising is inherently efficient.
What's the best conversion rate you get?
in online advertising, you think?
1%, 1.5%.
That's fine.
The thing the best of breed is 7% to 10%.
The average is probably 1.5% to 2%, which means 85% to 90% of your marketing is wasted.
So now if you get really smart, you have memory, you have context, and you get smarter than targeting Harry when he's trying to buy something out there in the world, then your conversion rate goes up.
If you look at the entire value from the time you decide to buy something till the end, you get the product.
You take the case of consumer goods.
Today, I want to say the cost of consumer goods is probably in the 5% to 8% of total list price.
The 92% is distribution and marketing.
It's highly inefficient.
So you could imagine a world where AI makes marketing really efficient, and you get more dollars coming from traditional marketing into the online world because it's coming in the form of transaction.
If tokens get cheaper, why are we not seeing frontier models get cheaper?
We all thought that this would be cheaper, this would be cheaper.
Well, right now they're figuring out that...
All your frontier model companies are value maxing, not token maxing.
They're raising money at a trillion dollars.
At some point in time, they realize, oh my God, where's the next $100 billion of compute going to come from?
Financial markets are not going to...
bear the cost of another $100 billion that are trillion dollars or trillion and a half because I'm going to need it again the following year.
So you say, well, I'm going to build a sustainable business model which starts showing some degree of gross margin profitability.
The only lever they have is to take the fastest growing thing that they have in their portfolio from an economic perspective and charge us more for it.
That's where you get the price of tokens from.
I think the price of tokens is high.
Now, you can imagine if the price of tokens is high, every technologist is trying to figure out how do I make my compute more efficient in the future.
So I'm sure we'll see a whole bunch of advances in the world where memory and computers are going to start getting used more efficiently from a modeling perspective.
I still believe I don't need Fable 5 or Mythos 5 to do 90% of what people do with AI today.
Why is the last model not good enough?
Certain tasks.
I think I'm wavering it.
I think the model overhang in terms of capabilities and especially consumer and most enterprise demand, but the models from two years ago were good enough for most of the queries that we asked.
That's right.
The problem is they were inefficient from a computer perspective.
Totally.
So you're seeing the efficiency come in.
The problem is the cost of R&D is now being spent in terms of what the tokens have to pay for.
So I think token prices come down.
I think the amount of compute that we need is going to be huge the next 10 years.
I think the frontier AI models are in a position to capture a significant amount of the future economic value of the use of AI.
Everyone is fundamentally looking at the stack.
And this is me being very open as a venture investor, but that's why the show has been successful.
And I'm just saying what every venture investor feels.
We're all looking at it going, oh, Jesus, I have no idea where value is accruing.
And you've got, essentially you've got infra, which is kind of top, and then you've got models and apps to be totally- Yes.
Look, infra is making money.
Infra is more expensive than it's ever been.
That's where you're seeing trillion-dollar market caps in the infraspace because of the scarcity of compute and this need for speed.
Do you think we're in an infrastructure bubble, like people think or suggest?
I have a question which I don't know the answer to, and you can tell me so you spend more time with people here.
I have to go do my day job.
Is at what point in time does physics kick in and we just can't produce the computer as fast as we want to?
Like infrastructure people are gearing up for large amounts of capacity, large amounts of demand on the infrastructure side.
And you come to a point where it says, you know what?
It's only so many data centers we can build.
There's only so much energy we have.
Well, I mean, now, I mean, shortages of copper.
The Panthalassa, which is building data centers at sea.
We've got Elon building them in space.
So I think there may be a digestion period at some point in time when we think the demand for compute is there, but the capacity to execute is now limited by physics, and the infrastructure players have built up too much capacity for this demand.
I don't know when that rationalizes.
Maybe it rationalizes and causes us to go think about a different sort of...
timeframe for putting all this compute out.
That doesn't take away for the need of compute.
We'll still want as much compute as we can deliver, as fast as we can deliver.
I think some of the model companies have outstripped anybody else's ability to build frontier AI models of that capacity at that speed in the trainings.
I think you are seeing perhaps a settling down of who's going to be the frontier model player in the future.
The question becomes, in the economics, what value accrues to the model?
What value accrues to the application layer, as you said it?
And I think the application layer is probably a simplistic term.
Because for the first time, you have memory in applications.
Applications understand context.
They understand context as specifically as to what you want, what I want.
You're seeing that in the consumer space.
That has not yet come to the enterprise space, funnily enough.
I think that shows up in the enterprise space, which means the demand for computer memory goes up on the enterprise side.
I haven't used all the coding models myself, but over time, these coding models have to get really smart about understanding individual context of enterprises and humans.
That's how they'll be more effective and more efficient.
For that, we're going to still need more compute and more memory.
So I think that will start defining where the value accrues.
I think the value gets shared between Frontier AI models and the context that gets created in enterprise play.
I think the Frontier AI models are fully understanding that this is where the gap is.
I suspect the Frontier AI models, as a crystal ball, they will spend a lot more time in the next year or two building memory around consumption.
Building memory around consumption.
What do you mean, like expanding context windows?
More than that.
If you look at the consumer interaction that you have with your favorite frontier model, it's starting to remember, oh, you asked about this yesterday.
You asked about that.
Should I take the question you just asked me in the context of everything I know about you?
Or should I just limit the answer to as if I don't know anything about you?
Now, having context of what I said to you over the last 30 days, the last 60 years, 90 days, requires you to store a lot of information.
It requires a lot of personalized interaction that needs to have.
Now, if you want to maintain your moat, with Harry and Nikesh in the future, the more context you have about me, the easier it becomes for you to give me the answers in the future.
And as you start building context on a user basis, you create stickiness, and that becomes your mode.
To what extent does Mythos cannibalize a business for you?
To what extent does it make a business for you?
Mythos ended up, I think ends up being an accelerant to cybersecurity.
I think what happened when you saw Mythos came out, it demonstrated that all the training we've been giving these models on how great code is written, The models are able to turn around saying, well, I also know how to find bad code.
So what happens is you point the gun the different way and the model says, oh my God, look at all this code that you have.
There are so many flaws in it.
As we talked about, the challenge is, like every model, it also suffers from false positives.
If you're an offensive actor and I point the model against, let's just say, 20 VC enterprises and I go look at everything you've done, somebody's left a web socket open, somebody's done some mess up with IP addressing, et cetera.
So it finds the flaws outside in.
That allows the bad actor to go figure out how can they daisy-chain vulnerabilities and get into your infrastructure.
It's not good enough from a defensive perspective because I can't use the model and say, go take every vulnerability you found and build a patch and go patch my system and protect me.
So guess what?
It's going to patch 30% of things which are not wrong.
Who knows what that's going to do to blow up your infrastructure.
So when Mythos came, we looked at it.
We treated it with respect.
We ran it against our code.
We discovered it finds bad stuff much faster than humans can.
We found in six weeks what would have taken us five to six years.
So we got it.
We run around, we patch it, but Cloud Code helps build the patch, but you still have to run it through human evals, through testing, through production testing, to sandboxing, to see, does this patch break anything in the infrastructure?
Only then, after six weeks, we were able to go patch everything.
So what does this mean?
This means that every enterprise better fix their stuff faster.
Because if I point the next generation of models against your infrastructure, it's going to find security flaws, security vulnerabilities, misconfigurations, things that you've not been paying attention to.
So it creates a bit of an urgency on the parts of the customers to improve their cybersecurity posture, which I think generally is a good thing for cybersecurity companies.
This is not fundamentally bad.
Like when we just summarize what you just said, it allows you to weaponize bad actors to find holes, but isn't good enough to provide the solutions.
Well, look, the solutions are there.
The challenge is sometimes getting the attention and focus of the customer saying, listen, I got to go fix my stuff because it's important.
What this has done is it lit a fire under the security practitioners around the world saying, this thing is not good.
This is going to weaponize the bad actors.
I better make sure my defenses are in place.
Now remember, the way cyber defense is done is it's fundamentally just cybersecurity is two fundamental things, right?
One thing is if it's bad and I'm at the gate, I'll stop it.
which means you have to have somebody at the gate.
Now, we have 150 million sensors in the world where we stand at the gate protecting our customers.
If I can find a way of infusing AI at the gate and taking all these vulnerabilities and finding a way to protect you, I'm good.
I don't have to chain the gatekeeper because there's no cloud endpoint agent that exists out there.
There's no opening endpoint agent that exists out there that I can replace Palo Alto or the other people in the space with.
The problem is not at the gate.
What happens is, despite all the perimeter defense you put in, things come in, things leak in, people make mistakes, people's passwords get breezed, there are vulnerabilities people get in through.
Then the question becomes, all right, oh shit, the bad actor is in my infrastructure.
How quickly can I find him and get rid of him?
That becomes an AI task.
That becomes the same conversation I'm having so far is, I need context, I need intelligence, I need to know what this means.
So creating the context, that intelligence within the enterprise.
of what this intrusion means and how to protect against it becomes a challenge.
This is the AI cybersecurity challenge.
Again, this is not trying to pitch my book, but we spent five years trying to build that capability inside enterprises.
So in the net net, it ends up being accelerant.
Does that mean I have everything I need?
Not everything.
Does that mean I need to get AI models to start helping me?
Yes.
So we're going to infuse more AI into our defense infrastructure.
Do you think it is good or bad to have government intervention when you have models as powerful as we have them?
I think we're going through a discovery process.
I think this notion of guardrails has not been built robustly enough because these models seem to be easy to get past.
Remember the early days when I used to read about somebody had this conversation with a model and found a way to, you know, albeit the guardrails because it asked questions differently and the model was able to get sort of...
jailbroken, it became a hobby amongst people.
And they had all kinds of conversation with models.
It's the same challenge.
How do you make sure that you can put enough guardrails around the AI model that you've built to make sure it's only used for the purpose that you had?
That's the challenge that there is.
I think the guardrailing needs to get better.
To the extent the government feels the guardrails aren't robust enough, it's trying to tell us it's a national security issue.
They need to go fix the guardrails.
But I think it's a simple matter of trying to fix or treat the guardrails as a real problem and solve it.
Is it possible?
I'm hoping it is.
I hope it is, too.
If you were starting, and this was, I spoke to one of the world's best cyber investors, who will remain nameless, because he asked some spicy questions, too.
Oh, okay, he asked questions for me?
Yeah, he asked questions for you.
He asked some interesting ones.
But he asked, if you were to start Palo Alto Networks for a cyber company again today, starting today in the age of AI, what would you do differently that you're not doing now?
The paranoia I have, if I look at self-driving, there are broadly two or three approaches out there, right?
One was, my car is not going to have a human in it.
It's called Waymo.
I'm going to keep pounding it.
I'm going to keep pounding it, training it until it learns by itself to drive.
And no human shall be holding the steering wheel ever when my customers are in it.
You see it's out there.
Many cities have Waymos.
I saw one down the street from here.
So that's one way of doing product development.
And what you do is every edge case gets discovered.
You build training around it.
Every experience is a learning experience.
You build training around it.
You keep training it.
You keep training it.
You keep training it.
You get to a point of total autonomy.
The other version is I'm going to start taking segments of the driving.
and start automating that segment where I get really comfortable.
So my car drives 50% of the time, the other 50% of the human gets in on the edge cases.
That's my Tesla.
Tesla used to drive just the highway for me, and now it's getting better at other streets.
It's slowly getting better.
But still, I'm holding the steering wheel very often.
It'll tell me you're not paying attention.
Look at the camera, otherwise you can't drive.
And I know FSD gets better, but that's another way to get there, okay?
I'm going to keep training.
I'm going to fix this.
I'm going to start working the edge cases as my business continues to evolve.
The third one is...
I'll infuse some degree of self-driving into my car because I've come from the traditional model of having amazing cars, great V8 engines, beautiful, sleek cars, and I'm not into the technology aspect.
You see them out there on the street.
They have all three versions out there.
My fear is, do we all need to stop and start thinking the Waymo way as enterprises, or is there room for the Tesla approach to self-driving in our businesses?
Because we have an existing set of customers to satisfy.
We're not going to take kindly from me saying, you know, guess what?
I changed my product.
It's right 80% of the time.
And I'm going to take another three years to train the product to be right 100% of the time.
So my fear is, am I pivoting fast enough in my product strategy that over time, my products become more self-driving than they are today?
Or do I need to go faster?
And can I get there by automating or AI enabling certain parts of my product where I can apply the models that are capable to do certain aspects of cybersecurity today and keep doing the others through machine learning and managing edge cases through machine learning?
Or is it time for me to pivot?
My view right now is you have to have the Tesla approach if you're an enterprise that is building AI-infused capability.
But you can't have the approach of traditional car manufacturers, which are trying to stick a little bit of AI and sort of AI washing their cars and saying, I'll get there eventually.
Would you like to do the Brian Armstrong Jack Dorsey?
I often think a good question is, what would you like to do?
But you're held back from doing.
Different courses for different horses, right?
I don't think in our business we can go implode the organization because I don't think the underlying application software is there.
I don't think all the things that we've talked about that we need to get done.
are ready from an AI software perspective.
I don't want to build a lot of software that is proprietary to me for things that should be available for everyone.
I don't want to build an AI marketing stack.
I don't want to build an AI HR stack.
I don't want to build an AI ERP stack.
I'm hoping that somebody goes and does that much more effectively and efficiently for the world at large.
Perhaps it's the next iteration of Salesforce, the next iteration of SAP, or the next iteration of Workday that is going to help me do that because I do believe it needs to become more intelligent.
We talked about it needs to be more AI enabled or AI controlled.
I do want to build things that are particular to me.
There I have all the information, all the intelligence, the context, and the memory from an organizational perspective.
I think the right way to get there is to hold people accountable.
And I run a meeting twice a week now called AIO.
It's kind of funny.
It's like, oh, my dog had a farm.
AIO, because everybody in my company wants to do AI.
So if we use it as a converging function, as a function to do brainstorming across my team, how do we think about this?
Why are we building this?
What happens in that meeting?
Everybody comes and shares how they're adapting to the new world of AI.
What are they doing from a product development perspective?
How are they thinking about it?
How are they including agents in their products?
How are they going to go build the backend infrastructure?
How do we think about how are they using tokens?
How do we think about the capability of resources?
Remember, for me to transform a 21,000 people organization, I have to get the hearts and minds of the leaders to make sure we're all swimming in the same direction or pulling in the same direction.
So this is my way of ensuring the top 15 or 20 technical leaders in my company are pulling in the same direction.
What would the direction be?
And as you know, if there's no expert, then a group of smart people do better than an expert.
I don't think there's an expert for future enterprise design yet in terms of here is the blueprint.
Like you said, as a VC, you're saying, holy shit, where's the value going to accrue?
Is it going to be in models?
Is it going to be in the application layer?
Trust me, we have to have a point of view on that stuff and what's going to emerge in the future before I can start.
re-transforming my company.
Like, how should I build my products?
Are your leaders AI-pilled?
I interview CROs as well, some of the best CROs, some of the best CPOs.
And in all honesty, the bigger the company, the less AI-pilled, AI-maxed they are.
To the extent where one the other day, a public company doing 5 billion-plus in revenue, CR goes, you know, we don't have that AI talent internally, but we'll bring it in.
Yeah, like, I discovered this in 2004 when I was...
In Europe, I ran Google Europe.
I used to go around and meet CEOs.
You know, there was this fad where CEOs would hire this 24-year-old Sherpa.
They were called the Web Sherpas or Internet Sherpas, right?
It's like chief internet officer.
Remember, those companies had chief internet officer at one point in time.
I was eight, so no.
You don't remember.
Well, the Jews, we've seen this movie before.
And sometimes it's fine to have seen this movie before.
And the task of the chief internet officer was to make sure the organization was ready for the internet because I'm too busy in my traditional business and I don't know who Amazon is, I don't know who Google is, so this wonderful 24-year-old who understands this stuff is going to help be my savior.
And then CEOs would wash their hands about the internet because they have this wonderful team of people who would be frustrated because they can't get anything done because nobody's giving them attention.
The risk of that happening is true with AI as well.
I'm so busy doing what I did yesterday, I have no time to think about tomorrow.
So meet my chief AI officer who's probably a researcher at some amazing university before and has low execution skills.
So until I can get my leadership to understand and agree, the extent of the AI challenge and the AI opportunity, we're not going to make progress.
What specifically are you not focusing on today because of the burdens of today's problem?
Like everything, when you go talk to a product manager or any large company, I'm pretty sure they have a product roadmap that exists in their heart, in their hands.
It's six months or 12 months long.
I gotta go fix all these things.
I'm like, what's interesting is in the six to 12 month thing, there's nothing called agents in there.
How come like the world is talking about agentifying everything and your product roadmap doesn't have that?
I'll get to it once I get this done because it's what customers want right now.
I'm like, nope, that doesn't work.
How do I get you to do more agentic work?
How many people are you gonna free up doing development the way you're doing it today so I can use that excess resource to go make new things happen?
So those are all important conversations.
I can have them one at a time across 14 or 20 people, or I can have them twice a week with them and people demonstrate how they are.
And what's fascinating, remember, you have to make sure your leaders are ambitious.
You have to make sure they're competitive.
You have to make sure they want to win.
You have to make sure that they have a learning mindset.
When they watch their peers around them do cool shit, they want to show up with cool shit the next time.
So for me, it's getting 14 people together and saying, hey, Harry, tell me today.
What have you done for AI in the last three days since I last talked to you in your organization?
And whatever motivates you, whether the fear of Nikesh asking you three days again what you did or your sort of inherent learning ambition or it's your team pushing you, you will show up with something.
Then you'll see what the other guys are doing.
Say, oh my God.
I'm doing a lot or I'm not doing enough.
So it creates a little bit of Darwinian competition amongst them.
It creates this urge to go embrace this new technology.
And I think hopefully I get 14 people fully motivated and then they go to that to the next set of people.
Because I need to transform from the top down, not from the bottom up on this topic.
There's a bottom up experimentation, of course, right?
People using tokens to see who's really good at it.
That allows me to find the best talent.
So it's got to find a way of transforming 20,000 people over the next three years in that direction.
Bottoms up, top down.
You've got to get into these organizations.
That sounds naughty.
Clearly I need to get out more when that's...
I just sit in this dark room all day, Nick, I'm sorry.
The question is, how do you get in effectively and how do you get implementation and adoption done well?
I've had guests on the show say before, you cannot do enterprise adoption without FDs today.
And then I've had Matan come on the show, a friend from Factory, and say, If you need FDs, you have a shit product.
Bold.
And I love Matan.
And I think it was a great clip.
So grateful for the virality that came with that.
Got it.
Okay.
Is that one viral?
That did very well.
Yeah, Cheyenne from Palantir then obviously chimed in.
Of course.
My job is to create a discussion.
What is true and what is right?
Do you have to have FDs to sell into enterprise?
What is true is we've only been chasing the enterprise dream for AI for the last 12 months at best.
If you think about...
everything that happens on a weekly basis, we see new things come which we don't quite fully understand and grasp, right?
We were all busy trying to get our arms around LLMs and how they're going to be great for chatbots to talk to our customers as an enterprise.
And suddenly agents showed up.
It's like, oh my God, I got to figure out agents.
I'm going to start working internally.
Agents are going to do a lot of stuff.
I'm pretty sure you could still have a agent fest and have everybody tell you what an agent is.
You'll still walk out and say, I'm not quite sure that his agent or her agent is the same as what the last guy said.
So because AI is moving so fast, I don't think the products are fully there yet.
Like the enterprise products at the application layer don't exist in their entirety because we haven't been tested against the enterprise ask.
So FTE is a short form for saying my product's not fully there because it's evolving as the technology evolves.
I'm going to send some people across who are going to sit in your office and build my product.
while I adapt it to your needs.
That's what it is, right?
That's what we saw from Palantir.
That's what we're seeing from all these companies.
So what you're seeing is, I'm going to send my product engineers or developers to your enterprise.
They're going to build my product.
If you do it right.
Again, FDE is a different version.
Some people are just trying to get you to consume AI, which is actually not an FDE.
It's just a technical sales consultant who's trying to help adoption.
On the other hand, an FDE truly is somebody who actually brings the code back from a customer side and goes back to your...
Product AI has said, listen, I built this at the customer side because they had this need.
We should incorporate this into our product because everybody's going to need it.
That's an FTE in my mind.
I think FTEs are needed for the short term because remember, all the enterprise AI startups are hungry for revenue.
For some reason, we've created this notion that don't worry, just keep selling it.
There's a huge sort of pent up demand around AI applications.
Sell it before the product's fully ready.
That's what we're seeing.
Do you think that's right?
I think that's the case.
I think as...
We think things evolve in the next 12 to 24 months.
People will switch from one set of products to another because something will emerge as a better product.
Look at the coding conversations, right?
How many coding companies have you heard of the last 24 months?
I think we had Winsurf, we had Devon, which is now Cognition.
Winsurf got sold.
Those are the early guys in coding.
They don't exist in there.
then form.
Now you've got Codex and Claude and anti-gravity, Factory doing SDLC, you've got Cognition doing SDLC.
So you can see as the market evolves, people who have concentrated on different parts of the value chain around coding are getting formed.
The product's getting more and more formed over time.
Who knows in two, three years who's going to be the leader in that space?
Because the product's not fully ready when you start.
Do you want to make a bet on who you will?
No, you do that.
That's what you do for a living.
I just need a good one that my teams can use.
I need to make a bet.
How do you choose who you decide to help?
You know, I spoke to your daughter Aisha before, and she said one thing that, no, she said lots of things that many people don't know about you, but she said one is you help a lot of people, a lot of founders, and you ping them.
Yes.
How do you choose who you ping and who you help?
Matan obviously being one of them.
Well, my current paradigm, as I told you, is This market is moving so fast that based on what you read, that open clock comes out.
Suddenly there's this thing that people are going to have agents.
There was a moment if you heard, if you saw, there was agentic browsers, remember?
You don't hear about them much, but there was a moment when everybody was going to have an agentic browser.
Your browser was going to be your computer, and that's going to be sort of do all the agentic tasks.
When I hear about these things, I'm trying to assess which one's going to work.
If it works, how does it impact my product portfolio?
What do I need to build in anticipation of this technology becoming mainstream?
And that window from the idea to execution is shortening in the AI world, as you can see, right?
Like the way these companies are coming out and getting formed in 12 months and 24 months and getting 100 in AR is probably the fastest ever.
Which means if that's what my enterprise customers are using, I have to figure out how to secure that stuff.
Well, my team doesn't fully understand all this stuff.
So I'm busy listening to podcasts, listening to people, watching people tweet, watching people on LinkedIn and saying, this is an interesting technology helping the founder.
So my first step is to ping somebody who's doing something interesting, which I don't fully comprehend.
They seem to be getting to a degree of success, which gives me a feeling this could be something relevant, perhaps not this company, but the construct that they're working on, the concept they're working on.
I'm an investor in a world of investing, in a world of uncertainty.
You go later where there's more certainty.
Yes.
We spoke about this downstairs.
You know, I have that luxury in terms of a flexible mandate to do that.
You have that luxury too in terms of the benefits of scale and acquisition budget.
Can you not just sit on the sidelines and wait for the right things to percolate and then buy them at a billion?
Yes and no.
Yes, we can wait.
That doesn't mean I don't need to learn.
If I'm not paying attention to eight different players in the space, which I'm sure you do too, if I'm not paying attention to eight of them, trying to see who succeeded, why, what did they do wrong, what are the guys who got it right do, it's very hard for me to assess what made it work.
Was it a fundamental, it was a bad idea?
The technology is bad.
Agents are not good.
Agents are not going to work.
It could be that, or this company didn't implement, right?
The agents are still a phenomena.
Somebody else is going to execute, right?
I need to understand the underlying technology for sure to make sure that my team's thinking about it.
Do we adopt it, adapt it, and secure it in the future, right?
We bought a agentic AI company, Gateway, six months ago.
It didn't cost a lot of money.
But I figured out saying, listen, if everybody's going to agentify the enterprise, how are we going to know how many agents you have running around the enterprise?
How are we going to keep track of them?
How are we going to govern them?
How are we going to secure against them?
I said, the only way to do that logically is to find a way to aggregate agent traffic somewhere.
If it goes through a certain gateway, a firewall, or some router, I can watch all the traffic and I can stop an agent from acting.
That's the only way it works.
So I said, the first thing you need to be able to do agentic security is to have some sort of a gateway.
So we bought a gateway product.
Now I got it at the right price.
If I wait, look at what's happening now.
Suddenly people are waking up to the idea we need some sort of a router or gateway that all traffic needs to go through because of optimization reasons, because of routing reasons, because of token maxing reasons.
Would you have paid double?
Maybe.
It wasn't a big price, but I could have paid double.
That's not the point.
The point is things I buy, either they're going to help me 10x or 100x.
I wasn't going to fail spectacularly.
It doesn't matter if I paid 1 or 2x at that point in time.
Of course, I shouldn't be paying 2x and having it fail spectacular all the time.
But the 1, 2x doesn't make a difference.
The 1 is to 10, 1 is to 100 is what you do.
That's what we'd like to do as well.
Not from an economic return perspective, from a business value perspective in our business.
Are you more involved in Corp Dev today than you've ever been?
No, I've been always more involved in Corp Dev.
This is not a problem.
Is that normal?
I think I'd say I'm more involved in trying to learn what's happening out there from a technology perspective than I've ever been because the stuff is moving so fast.
And if I don't have a point of view and if I don't encourage my teams to pay attention to it and we talk about it, I think there's a risk we miss a trick.
And if you miss a trick, remember in life, in technology, you miss one trick, you can survive.
You miss two tricks, you're partly impaled.
You miss three tricks, you could be obsolete.
A lot of SaaS providers are feeling obsolete today.
Their share price is telling them they're obsolete.
Do you think that the majority of SaaS vendors have been oversold?
Or do you think that is an accurate reflection of where markets are moving?
I think what the market is telling us is that the system of work or the systems of record will see a reimagination of workflows, as you and I talked.
Going from software that doesn't have an opinion to software that has an opinion and expresses an opinion and also does a lot of work for the human, so the human doesn't have to do repetitive tasks.
I don't think those AI applications have been created.
I think the SaaS versions exist.
We all use them.
I think at some point in time, we'll see AI applications that do a lot of the tasks and workflow gets reimagined.
I do think a lot of SaaS has built a lot of analytical capabilities to sit on top of the systems of work and system record.
I think it's a lot easier to abstract that data into some large data lake and have LLMs analyze that data for you and give you the answers.
I think the analytic world is getting reshaped already.
where you can see people like Snowflake or Glean or Databricks.
All these people boast enterprise data lakes where you can bring the data and run LLMs against it and get you much more synthesized analytics and outcomes than you ever had before.
I think the third question which we started off with is people are not sure how many people are going to work in these enterprises in the future.
So if you take the confusion on how many seats are going to survive in the SaaS world, take the confusion around analytics are going to get done differently and system work gets reimagined.
What do you mean analytics done differently?
Again, disclaimer, I'm a podcaster.
Oh, you get it.
Yeah, you're a successful investor managing a lot of people's money.
That's true.
But disclaimer, podcaster.
I understand the seats question.
I understand the workflow.
Can you just help me understand the analytics?
Well, if you look at most SaaS software, right, in the past many years, once you're fully deployed at a company, somebody says, listen, I've got all this cool data about all your employees in my HR system, and I can help you get more insight in the HR system.
If you take a Salesforce, they have a Salesforce marketplace with 300 apps you can use, which are analytical apps that feed off your own system of record, go-to-market data, and it helps you analyze that data.
You know Neil Mater?
Yes, of course.
Yeah, I love Neil.
I do too.
I think he's one of the most phenomenal people.
He always says the one question is like, are the companies best days ahead or behind it?
And that's a very helpful one.
That's a very good question.
Good question, yes.
Are Salesforce's best days ahead or behind it?
I don't know.
That depends on how they execute from here on.
If I were to paint a bear case for you, what would that be?
The bear case is we don't get this transition right of the world going to an AI-first future.
Because look, these false positives will keep reducing over time.
Agents will become a real thing.
Agents will do a lot of work for humans, which humans have been doing manually in the past.
All that needs to get embodied in your product.
If I can't make that transition happen with my team in the next three years, yes, there's a bear case because somebody else will build a better mousetrap.
And the bull case is you understand it better than any other security provider and you become the default.
Bull case is that we get that transition right.
There's already a trend in our favor underlying that where people are realizing they can't have 40 to 60 cybersecurity companies that they have to manage themselves.
So we've been driving this trend of platformization already for the last 24 months to 36 months.
We already see the fruits of that where people say, you know what, I don't want 40 people solving my problem.
Let me put Palo Alto.
It solves the problem that 20 different companies do together on one platform.
The good news is because...
We are all coming to our senses and saying, yes, we need a lot more enterprise context, enterprise data.
It has to be stitched.
It has to be seamless.
That's what we deliver with our current proposition.
I just need to embrace the right AI capabilities and that stuff.
Does the platformization remove the ability for venture scale returns?
Remember, I need like $10 billion companies.
This is the big thing that I think most founders still don't kind of fully comprehend.
It sounds awful.
A billion dollars doesn't do it anymore.
It needs to be 10, it needs to be 20, 30.
With the platformization, I can get the billion dollar exit to you, hopefully.
Please buy any of my companies for a billion in cash.
I'll give you the catalog.
You can take them.
But you're not going to pay 10.
I'm not going to fight against innovation.
I think there will be venture-scale returns in cybersecurity because remember, we're the most innovative industry in the world.
The bad guys are always looking for a new way in.
They're not saying, oh, I exploited that two years ago.
Let's try it again.
Maybe somebody hasn't deployed a patch again.
Sure, we fixed that one.
You got to go find a new way to attack people.
I'm far too tired to come up with an innovative way to hack into it.
Let's just try it.
Do Westlifes again.
Exactly right.
So it's highly innovative.
There are new attack vectors.
People are going out there trying to chase them.
I'm not going to build everything myself.
People will build great stuff.
And sometimes people will create stuff and build a platform around it.
And that's fine.
Remember, we come to a different vantage point.
When I started at Palo Alto, we were less than 2% market share in the entire revenue of cybersecurity.
We're closing in on 8% or 9% right now.
There's still a lot of room between 8% or 9% or 20% or 30% or 40%.
That means there's still 60% of market cap out there to go.
enjoy in different companies.
And that's not all going to be existing players, including us.
There is room to build companies which have tens of billions of dollars of market cap in the next 10 to 25 years.
Fucking enormous market, eh?
Beautiful.
You're like, wow.
Well, think about it.
The S&P, what percent of the S&P is tech now?
Compared to that from 20 years ago.
Year-to-date gains, like 86%.
Of the total S&P market cap, what percent is tech?
And what was that 20 years ago?
What will that be 20 years from now?
If it was less, it'll be more.
No, 100%.
I'm realigning that.
So the entire tech space, what do you call marketing tech in the future?
Or marketing spend or tech spend?
What do you call HR tech in the future?
HR spend or what do you call the spend on all the tokens which replace repetitive human tasks?
All becomes tech spend.
You said the word bad guys is China in many people's eyes.
And we see a huge amount of incredible open source models which are being used extensively today at a much cheaper cost.
Do you think the proliferation of...
Chinese open source models is something to be concerned by or is an inevitable feature of a burgeoning ecosystem?
So for a second, let's play the thought experiment.
Take the word China out for a second.
Answer the question.
Do I think open source models?
No.
I don't think open source models are dangerous.
Right.
So does it matter where they come from?
Yes.
Okay.
So you're not worried about open source models.
You're worried about Chinese open source models.
100%.
I'm not saying I am.
Remember, there's a large tech company which also had open source models for a while.
Sure.
So it's interesting to watch open source models.
The question becomes in the future, do we end up with...
you know, horses for courses?
Do we end up with models that are very task-specific and very helpful in certain tasks?
And do we always need to use this mega frontier AI model for everything?
And you already see that with 11 labs and, you know, the voice models that are out there, which are specific to a task.
And they probably do that task better than what the frontier AI model does.
So over time, if you believe the world bifurcates into many task-specific models, which are going to be useful for that task, that task-specific model could be better training across the depth.
in a vertical space.
That's going to happen with physical AI, for example.
I don't think physical AI will be as easy as having a generic frontier model because there's no consumer use case for physical AI, right?
It's a depth use case only.
The question is, is your physical AI model that helps you fly planes going to be the same physical AI model that helps you drive cars?
Most likely not.
It will be the same physical AI model that does robotic manufacturing?
Probably not.
So you're going to see depth in these models.
You're going to see a world of bifurcated models.
It's some sort of orchestration layer.
as we've talked about, and you're busy finding orchestration layer companies that can allow you to pick the best model for the right task, that those orchestration layers have to get smarter and smarter.
They have to understand the context.
They have to understand the memory.
So the question is, do I store my memory and context in the orchestration layer, or do I store that in the frontier model?
Which one do you think it will be?
I know I'm the investor.
I should know, but I don't.
No, I think that the challenge is, right now, the frontier models know this problem.
and they're aggressively moving to incorporate memory and context into their models because they understand that's the mode.
And the challenge is you have to pay for it twice.
If you say, no, I don't want to use your memory and context, the model may not be usable if you use an orchestration layer.
The orchestration layer today is not as well-funded as these models.
The risk is you end up in architecture where the model has a lot of context, and you cannot be model agnostic.
You actually be model captive to get maximum efficacy and value for what you want to get done.
So you have a choice.
You have to go all in on the model or you can't go all in on the model.
You can't do with one what you can do with the other.
And if you want to do it with the other, you have to redesign an entire application that is deeply embedded with the capabilities of the second one.
So in the world of bifurcation and horses for courses, I think open source is a good thing because it allows you to play the cost curve.
You don't need the smartest model to do the smartest thing.
Open source is good.
Whether it comes from a certain country or not, the question becomes, what back doors are you worried about that these open sources models have?
What are you worried about that?
And that's true for any nation state, right?
If there's a nation state sponsored open source model, what are the back doors?
Can I get in?
Does the model wake up one morning and it's got a sleeper agent in and starts sending all the data somewhere else?
Those are questions.
Those can be secured.
That's why you come to Palo Alto, to help you secure the models.
Always got to secure your back doors.
I don't know.
What kind of night did he have?
This is not a hangry night.
This is a different kind of night that I'm dealing with.
It's Monday morning.
Just terrible.
Back to work.
What is the best time for me to show up here?
I'm in your time zone.
I'm well rested.
I'm not jet lagged.
The only three things you seem to have gone on to where your mind is going in the wrong direction.
I've got two questions, then we'll do a quick fight.
One is, with the incredible success you've had, you've made a lot of money.
It's just a question I have is like, what does no one know about having money that they should know?
Like one thing for me is I've become much more impatient.
We have very different, you're from all success.
I've become way more impatient.
No one told me I'd become impatient.
I'm used to a good quality of everything.
And now when it's not that, I'm very pissed.
I don't like that in myself.
But no one told me it would happen.
What are you going to do to fix it?
Therapy.
This is a common Western solution.
Yes.
As somebody else tell you, you come back saying, I must feel better now because I told somebody that I was going to this.
My father told me I should put myself first more often.
And you came back to being impatient because that's how you put yourself first.
More important.
Believe in yourself, right?
Is that what you're supposed to do?
Optimize for yourself.
Put myself first.
Be confident in yourself.
And it was your dad's fault.
Oh, my God.
Is that what your therapist told you?
Yeah, yeah, yeah.
This must be British.
Yeah.
But no one told me that.
I kind of wish they had done.
What does no one tell you about having money?
that they should do?
I think it's not about money as much as it's about success.
Remember, we all follow Maslow's hierarchy.
I came to the United States with two suitcases, $200, and I was willing to do anything, anything at all, within reason as the right side of the law, to make sure that I made a life for myself because there was no way to go back.
I was going to use a different word, but I'm not going to use it because you go crazy again.
So there's no going back, right?
It was a one-way ticket, which I did not have.
I had no recourse.
So I was willing to do whatever it took.
I took notes, became a security guard.
I tried to pump gas for a weekend.
You became a security guard?
Yeah, when I came to the United States, I was a security guard.
I took notes to the disabled.
I flipped burgers at Burger King.
I had $200.
I had to find a way of paying my tuition.
Was one quite transformative to your mindset?
Did you hate them?
Did you love them?
It had to be done.
It's karma.
When you come from Eastern philosophy, it's karma, right?
It's destiny.
This is what you need to do to break your destiny.
So you do that.
So you don't worry about what you have to do.
Now, at that point in time, there was no...
You always knew you were going to be successful.
I don't know.
Who knows?
Nobody knows they're going to be successful.
You just come in and tell your best and hope for the best and see what happens.
So that's very Eastern philosophy, right?
You believe in karma, destiny.
How do you manage billions of people in the world?
You make sure they believe in destiny.
They believe in destiny and say, oh, this must be what was my destiny in the end.
I tried my best.
This is where I ended up.
That is better than your therapist.
It just keeps you centered.
Say, okay, I tried my best.
I gave it everything I had.
But perhaps this is what God intended for me.
You find that hard to believe.
If you were my therapist, I don't think I could afford you, though.
This is free.
You're getting free.
I'm not sure I fully embraced all of that, but that was where I started.
So if you start from that perspective, over time, you climb up Maslow's hierarchy.
It was about food and shelter, and that became about ambition, and it becomes about actualization, conceptually, in Maslow's hierarchy.
And you get to a certain amount of money, then you decide, there are some things I don't have to do anymore.
I don't have to be a security guard.
I don't have to flip burgers.
But that very quickly goes up further.
I don't have to tolerate certain things that I tolerate in my life because I don't need it in my life because I don't have to adapt to the circumstance because I can walk away.
Do you ever get worried that the willingness to walk away makes you softer?
The willingness to walk away makes you softer.
No, actually, it's the other way around.
The willingness to walk away makes sure you optimize the outcome.
When you negotiate, if you're fully vested in the outcome...
You fold at some point in time saying, well, I can't let Harry Stebbings walk away because Harry walks away, I have no deal.
But if I say, you know what, Harry, it's going to be these terms or no terms.
I'm willing to walk away.
Then it depends, the battle of wits, right?
So he says, does Harry want it more or do I want it more?
Does it make you softer?
I don't want to make it political, but isn't that Donald Trump's, like, the art of the deal, like, leverage?
I don't know.
I've not read the book, so.
It's quite a good book, actually.
Is it?
At the end of the day, I don't think being willing to walk away makes you softer.
I think being willing to walk away makes sure that you understand the pros and cons of what you're dealing with.
It makes you understand whether you should spend your time over there or not, which makes you understand whether you can get an outcome that is useful for you as well as the other person.
We have a lot of choices in life once you have the amount of wealth you have.
Final one, and then we'll do a quick fight.
I care a lot about kids, actually.
I love kids, and I want to be a really good father when I am one.
You already see you have a public company that is incredible.
You've had an insane career.
And I've had the pleasure of meeting one of your children.
She's amazing.
She is.
What advice do you have for me on lessons on how to be a great dad, but also not lose an inch on work?
I'm not willing to sacrifice much on the work side.
You know, this is the hardest problem in the world.
I think there's, what, 20, 30 billion people who have been born since the beginning of civilization.
Yet there is no AI that can train us on what we need to specifically do to create the outcome we'd like to create.
It's way too many variables, right?
All kinds of people in the world, and I'm sure their parents, some of the parents are amazing, some of the parents are not as amazing.
So I think part of it is you can do your best from your perspective.
And I think kids absorb a lot by watching you, your work ethic.
They watch your values to see how you interact with them.
Because my daughter probably has a better sense of who I am as a person than anything I can tell her because she spends time around me.
She sees me interacting in every sort of micro situation.
what makes me impatient, what makes me patient, what makes me do certain things.
At the end of the day, your child believes that you have the best intention for them.
I think that goes a long way.
I had a guest on the show and they said, watch National Geographic if you want to be a good parent.
And I said, what?
They said, look at the elephants.
The children follow.
And so if you want your child to be nice to waiters, be nice to waiters.
If you want them to work hard, work hard.
But that's true in organizations too, by the way.
Organizations take on the form of the leader.
I'm pretty sure if you close your eyes and you rattled off five or six attributes of a company and said, it's a company as a founder, and say, how do you compare the company's cultural values vis-a-vis the founder?
And you'd find a...
remarkable resonance between the two things.
Companies act, because remember, the organization is trying to please the founder because they figured out that's the way to achieve success.
If my CEO is impatient, if my CEO is exacting, if my CEO is ambitious, my CEO suffers no fools, gets stuff done, then that must be what they want to reward.
So you suddenly find if you, this again depends if you have the right values or not.
You told me a story about a guy who had different values and they had to shut the company down, but if you have the right values, people will watch your behavior and want to emulate your behavior.
I want to do a quick focus, otherwise I'll take up all of your time.
What is a belief that is held by most top investors and founders in Silicon Valley today that you think is wrong?
My concern would be at this point in time, given the base at which technology is evolving, given the uncertainty in terms of what's going to work, what's not going to work, I'm worried that it might be too much euphoria.
and a bit of FOMO going around in terms of, oh my God, if I don't invest in something that's interesting in the right founder, I'll be left out.
Because people have seen this happen.
Look at what's happening in Enthropic, right?
You've missed the first round, the second round, the third round, the fourth round, the fifth round, and you look like a guy who didn't have money.
Now, you had 20 years to invest in SpaceX.
You had three to invest in Enthropic.
That pace is fundamentally different.
I'm sure as many people are happy that SpaceX finally went public, as many people are probably sitting and saying, damn, I should have done the Enthropic round two years ago when they showed up on my doorstep.
So I think there's a lot of FOMO.
coupled with euphoria on the other side.
And I think the risk is that we think every company that's going to show up now is going to be the next Anthropic, so we better get into it.
My next one to you is, any moment, any board meeting, what was the biggest, oh shit, in a board meeting?
I got a very interesting insight from one of my board members.
You know, we're prolific buyers of companies because I'm constantly paranoid that we haven't built it.
Somebody else is going to build it, so we better go acquire it and find the team to go get it done.
And there's one particular acquisition.
It took a lot of effort to get the founders to the table, get them to agree, grind through diligence, figure out whether it's going to work or not.
It's a substantive amount of money, relatively speaking, hundreds of millions of dollars, close to almost a billion dollars.
And I called one of my board members and I said, hey, what do you think about this?
You're calling me.
You don't call me all the time about all the acquisitions you do.
So this one must be different.
I said, no, it's not different.
I'm just thinking hard about it.
It's taken a lot of effort.
He says, go for a long work.
Ignore all the effort you put in.
He said, because sometimes what happens is you confuse effort with wanting to get the outcome.
I spent a lot of time and effort trying to get it.
Then you feel like when you get it, you better take it because you put all the effort in.
And he says, you haven't spent a dollar yet.
You just put in three months of effort.
But remember, once you put the dollar, then it becomes yours.
It's your job to make it successful.
So you still have one more chance to decide if you want it or not.
I go for a very long walk and say, if this walked in the door right now and there was zero effort involved, all I had to do was write the check.
Would I take it or not?
forget the sunk cost.
Yes.
You have the same in the investing business.
You spend so long.
Yes.
Yes.
You spend a lot of time.
You're like, oh my God, I'm the one getting the term sheet and nobody else has it.
I nailed it.
I've beaten out eight VCs to it.
The question is that not how many VCs you beat to get the deal?
The question is, if this deal, can this deal stand its own merits and would you invest in if there was no competition?
What's the best advice you've ever been given?
The best advice that the early old man gave me on a flight once was, you know, life is simple.
If you wake up in the morning, you're really excited about going to do what you do for a living, you're blessed.
And if you're done after a long day and you're really excited to go home to your family, you're blessed.
Do you like that?
I do.
I do.
And I actually tweeted last night.
I hated school when I was a kid.
Sunday nights was the worst.
Yes.
And my Sunday night last night was thinking about our show and the conversation.
What a great Sunday night.
What a great Monday morning.
I wasn't sure where you were going to go with that.
No, no.
How lucky am I?
Seriously.
It's amazing.
Final one.
What are you most excited for when you look forward the next five to 10 years?
What are you most excited for?
Is it becoming a grandparent?
Maybe.
I've just seen my mother become a grandmother.
It's amazing.
She's amazing.
Is it the health benefits?
I'm so excited that AI might be able to solve multiple sclerosis, which my mother has.
That'd be incredible.
You never know what tomorrow's going to bring you.
The one way I've been able to do everything I do is not to get too hung up on what's going to happen to me in a year from now or five years from now, because it's too far.
I think you wake up in the morning, you have an amazing day, and everything's working around you.
Your kids are happy.
Your family's happy.
You enjoy what you do.
You have good friends.
And I was at a different place the other day, earlier this weekend.
They asked me, like, you're not a 996 CEO.
What do you do?
And I said, look, I try to make sure that I can find something to enjoy every day.
Because...
I have enough things to worry about.
I can really get myself in the wrong headspace by worrying about a lot of things.
I run cybersecurity for crying out loud.
I live off the fact that somebody's going to hack somebody at some point in time.
My phone rings saying, can you help us?
It's like, why didn't you spend the money before?
But can I help you?
So I can help you.
So I think it's a state of mind thing.
Can you get your state of mind to be optimistic, positive, and one of gratitude and happiness every day?
If you can, it's going to be great.
But guess what?
If health benefits come, I can start being Benjamin Button, be amazing.
If my kids are continuing to be happy and successful, be amazing.
My mother lives for 150 years and she's happy to be amazing.
There are so many amazing things that can happen and perhaps may not happen.
So let's just focus on tomorrow.
Nikesh, I so appreciate.
you being willing to come back for a second.
I mean, after the first, when I suggested it, I was like, there's no chance you're doing this.
Good thing.
I have to go back a little to the first one now.
But thank you so much.
You've been incredible.
Thanks for having me.
But before we leave you today...
You have the idea, but often with AI tools, you hit a wall.
Well, Base 44 is where that friction disappears, turning how you talk into how you build.
Full stack web and mobile apps, sites, autonomous super agents, all built in minutes, not weekends spent on damn configuration.
Base 44 ships it all out of the box.
The backend, the database, the authentication, and the hosting.
It handles the heavy lifting, so you can just stay in the flow.
It doesn't just replace the busy work, it multiplies you.
It makes you so- much more capable and effective version of yourself.
In this market, being fast is the baseline, but to win, you gotta be first.
And Base 44 is that edge.
It's the move that lets you skip the troubleshooting and get straight to the breakthrough.
Launch your next big thing at Base44.com.
That's Base44.com.
After Base44 helps you launch, Corgi helps you cover what comes next.
My word, what an arresting first line.
Get your ass covered with Corgi insurance, and I'll tell you why.
If you're running a business right now, you already know this pain all too well.
Getting insurance, it's really slow, it's confusing, and my word, it's full of paperwork.
Well, that's exactly why Corgi is here to change the game.
Corgi is the first and only insurance carrier designed specifically for tech companies, allowing you to get covered in minutes instead of- of days, Corgi provides essential coverages for all growth stages such as DNO, E&O liability, cyber, commercial, general liability, and more.
Get your ass covered.
I love the way we say ass with Corgi Insurance alongside thousands of other startups at corgi.com forward slash 20VC today.
That's corgi.com forward slash 20VC.
You won't regret it.
While Corgi handles the coverage, Turing handles the talent.
Frontier Labs keep facing the same limitation.
Models perform well on benchmarks, but they fall short once they enter real coding tasks, real tools, and real workflows.
That disconnect between synthetic evaluation and actual system behavior is now a core blocker for organic models.
That's why NVIDIA, Anthropix, Salesforce, Gemini, and other leading lab partners partner with Turing.
Turing is the research accelerator focused on post-training reliability.
They build realistic RL environments, next-generation data quality systems built.
from real-world operational traces and coding datasets that stress models under conditions where failures matter, state changes, workflow branching, brittle tool calls, and the coding errors that break RL agents but never appear in benchmark reports.
In reality, a model may demonstrate correct reasoning in your evaluation setup, yet still select the wrong parameter or mishandle a code update in a realistic interface.
Turing makes that failure visible and gives teams the signal they need to fix it.
For labs, Turing provides the structure required to understand why these failures occur.
To find out how, visit turing.com forward slash 20VC.
That's T-U-R-I-N-G dot com forward slash 20VC.
