ATRIUMsearch → argument graph
Audio · 2026-06-08 · 31m · 12 moments

Nikesh Arora: Mythos is Real, Analytical SaaS is Dead, and Google can be a $10T company

(0:00) Palo Alto Networks CEO Nikesh Arora joins the Besties! (0:47) Claude Mythos found years of vulnerabilities in Palo Alto's code in weeks (5:15) Are cyber defenders losing the race against AI attackers? (6:50) Analytical SaaS is dead, so what survives the AI wave? (14:06) If models become a utility, where will the money be made? (20:35) Armchair CEO: Nikesh rates Waymo, Google, and OpenAI (28:22) Palo Alto's M&A playbook and the path to $1 trillion Thanks to our partners for m ✦ AI generated

timeline · colored by role

01
Data

In six weeks, Claude Mythos found vulnerabilities in Palo Alto Networks' code that would have taken five to seven years to find using traditional methods, at a cost in the low millions.

Nikesh Arora reveals that Palo Alto Networks tested Anthropic's Claude Mythos on their codebase and found vulnerabilities in six weeks that would normally take five to seven years, at a cost of just a few million dollars.

transcript

Nikesh Arora: Mythos has shown us that all the bad code that humans have written over the last 50 years can be assessed by AI and shown. The vulnerabilities can be shown. We tested for six weeks, and in six weeks we found what would have taken us five to seven years. ... In 6 weeks, we found vulnerabilities which would have normally taken us five to seven years to find. ... If you put it on ultra mode, which is persistent thinking, so it keeps trying until it gets an answer, you can actually daisy chain vulnerabilities, i.e. finding a new attack path into your vulnerabilities. Now, we pride ourselves as a top percentile of companies that test our code because we're in cybersecurity business. If you take that and compound that across all the companies that exist in the world that write their own code or the 10 million developers write code, this thing is going to find stuff which would have taken us 10 years to find. ... No, it was in the low millions.

extends · 1

02
Data

In six weeks, Claude Mythos found vulnerabilities in Palo Alto Networks' code that would have taken five to seven years to find using traditional methods.

Nikesh Arora reveals that Palo Alto tested Claude Mythos on their own code and found what would have taken 5-7 years of manual work in just six weeks, confirming the AI's capabilities are real and not hype.

transcript

Nikesh Arora: Mythos has shown us that all the bad code that humans have written over the last 50 years can be assessed by AI and shown the vulnerabilities can be shown. We tested for six weeks, and in six weeks we found what would have taken us five to seven years.

extends · 1

03
Claim

Analytical SaaS — companies that collect and analyze data for you — is dead, because AI models can run against that data directly without needing a separate analytics layer.

Arora declares that analytical SaaS is over: if a SaaS product's value is collecting and analyzing your data for you, you no longer need it because you can run language models against that data yourself.

transcript

Nikesh Arora: SAS is different pieces, right? If you're an analytical SAS company, it's over. Somebody that says, I'm going to collect a lot of data for you and analyze it for you. I don't need you to analyze it for me. I can run models against data and analyze them myself.

supports · 4

04
Claim

Analytical SaaS is dead — companies no longer need third-party analytics applications because they can run LLMs against their own data directly.

Arora argues that analytical SaaS companies are finished because enterprises can now run LLMs directly against their data instead of paying for separate analytics modules. He cites his own company reducing a SaaS bill by 90% by replacing 17 seats with AI agents.

transcript

Nikesh Arora: SAS is, as Bill said, SAS is different pieces, right? If you're an analytical SAS company, it's over. It's over. ... Somebody that says, I'm going to collect a lot of data for you and analyze it for you. I don't need you to analyze it for me. I can run models against data and analyze them myself. ... I can just go run an LM against the data. So the entire incrementality that has been sold as incremental software modules to all of us doesn't need to be sold to us because I'd much rather have LMs run against that. ... We had an instance with a SAS product with 20 seats. Nobody was logging in and using it, but the data was there. So we created like 3 accounts, got rid of 17, connected it to Slack, connected it to Claude, and now everybody can interface it through a natural language, and we've reduced our bill by 90%.

rebuts · 1

05
Prediction

Infrastructure software is undervalued and will thrive as enterprises store 10x more data over the next three years, and systems of record will be reinvented as agents eliminate UIs.

Arora segments the SaaS market into three categories: analytical SaaS is dead, infrastructure software is undervalued because enterprises will store 10x more data, and systems of record/work will be reinvented over the next five years as agents eliminate the UI layer.

transcript

Nikesh Arora: Infrastructure software, undervalued. ... Stuff that gives you databases. You collect data into it, stuff that allows the infrastructure to work, whether it's a, you know, database software. Databricks, Snowflake, MongoDB, Oracle, Oracle, all these things you need. Core storage infrastructure, core data. 10 times the data stored in enterprise than we have today. Next 3 years, 10 times. ... I think the category in the middle is called, let's call it system of work or system, a record, people call them. Those are deeply embedded in the way businesses work. ... What's going to happen is step one, we will take away UI and let agents do the work. ... Enterprise software and consumer software UI is the worst thing we did as technologists. ... If that happens, UI goes away. If UI goes away, I can rewire my system of work. ... So I think the whole system of work, system of record gets reinvented in the next five years.

06
Prediction

Enterprise software UI is the worst thing technologists built — with agents, UI goes away and systems of work get reinvented over the next five years.

Arora argues that enterprise software UI is terrible and unnecessary: if agents work as promised, users will just tell an agent what to do and it will interact with backend systems directly, eliminating the need for UI entirely and forcing every system-of-work SaaS company to re-engineer itself.

transcript

Nikesh Arora: Enterprise software and consumer software UI is the worst thing we did as technologists. If you believe agents are going to work, and I say, I just tell an agent, look, figure out from my sales call, figure out the key points and go post it into whatever sales tracking system I have. An agent conceptually should be able to do it. If that happens, UI goes away. If UI goes away, I can rewire my system of work. I think the whole system of work, system of record gets reinvented in the next five years.

extends · 3

07
Prediction

The biggest cybersecurity threat from AI isn't nation-state attacks on critical infrastructure — it's economic chaos caused by attacks on small businesses and the long tail of unpatched systems.

Arora argues that the real danger from AI-powered cyberattacks is not sophisticated nation-state attacks on critical infrastructure, but ransomware and breaches targeting small businesses, medical offices, and other under-defended organizations that would cause widespread economic chaos.

transcript

Nikesh Arora: The sad truth is, in a year there's a few thousand breaches or attacks that happen. They happen for pretty rudimentary reasons. It's not because somebody cracked a hard to crack thing. It happens because 89% of the attacks happen because credentials get stolen. Username and password. That's it. ... I'm not worried about the national security part being protected because they're very on it. They're the right people. They spend 10% of their budgets on IT on security. I'm worried about the small offices across the country where they're using some piece of packet software and you're running a dentist office or a doctor's office. Remember when Change Healthcare got breached, every physician's office shut down. ... That's what one should worry about. It's less about the big nuts will get cracked. It's less about cracking some PG&E power generation facility. It's more economic chaos.

extends · 1

08
Prediction

The biggest cybersecurity risk from AI is not nation-state attacks on critical infrastructure but economic chaos caused by attacks on small businesses and mid-market companies running unpatched legacy software.

Arora warns that the real danger from AI-powered cyber attacks isn't sophisticated breaches of large facilities — it's the economic chaos that will result from attacking small offices, dentist offices, and healthcare clearinghouses that run outdated software and can't defend themselves.

transcript

Nikesh Arora: I'm not worried about the national security part being protected because they're very on it. They're the right people. They spend 10% of their budgets on IT on security. I'm worried about the small offices across the country where they're using some piece of packet software and you're running a dentist office or a doctor's office. Remember when Change Healthcare got breached, every physician's office shut down. It's less about cracking some PG&E power generation facility. It's more economic chaos.

provides context · 1

09
Claim

Models will become a utility layer where you buy intelligence on demand at different price points, and the profit pools are in applications, not in the models themselves.

Arora argues that models will become a utility where you buy different intelligence levels at different prices, and that the real profit pools are in the application layer — companies that build agentic enterprise software on top of models. He says most enterprises have no idea how to use models directly and will buy from application companies.

transcript

Nikesh Arora: I think I still believe models are going to become a utility layer. You'll be able to buy intelligence on the fly. Or you can say, I don't need 180 IQ person to go do this task. Give me 120 IQ, and I need a 250 IQ to do this task. I'll pay $10 for this, and for this, I'll pay one cent. ... If you look at already what's happening in the market, right? The profit pools are in applications, not in models. Sarah talked about Codex running away. She didn't say OpenAI is running away. She says Codex is running away. ... The profit pools are in applications that companies can use. The profit pools are not in model usage by companies because most companies have no idea how to use the models. ... See, if I'm a company, I don't want to write every piece of software myself. I want my HR system software, which is agentic enabled and AI enabled to be delivered by some application company. ... I think we're still waiting for that layer of companies to be invented or created where applications will sit.

extends · 2supports · 1

10
Prediction

Models will become a utility layer where you buy intelligence on the fly at different IQ levels and price points, and the profit pools will be in applications, not in the models themselves.

Arora argues that models will commoditize into a utility — you'll pay different amounts for different IQ levels — and the real money will be in application companies that arbitrage between models to solve specific business problems.

transcript

Nikesh Arora: I think I still believe models are going to become a utility layer. You'll be able to buy intelligence on the fly. Or you can say, I don't need 180 IQ person to go do this task. Give me 120 IQ, and I need a 250 IQ to do this task. I'll pay $10 for this, and for this, I'll pay one cent. So I think models will get differentiated from a utilitarian perspective. If you look at already what's happening in the market, right? The profit pools are in applications, not in models.

extends · 1rebuts · 2supports · 1

11
Mechanism

The biggest challenge with frontier models in enterprise is not capability but false positive rates — a 10-30% false positive rate makes them useless for defense, insurance claims, or any high-stakes business application without additional harnesses and training.

Arora highlights that the overlooked problem with frontier models is their false positive rate — Claude Mythos had a 30% false positive rate on vulnerability detection, which makes it great for attack but terrible for defense. He argues the real challenge is taking a model with 10-20% false positives down to 0.01% for enterprise use, comparing it to self-driving cars.

transcript

Nikesh Arora: Here's the part nobody talks about, is the false positive rates on the models. What is the false positive rate on 4.8 and 5.5? No idea. You guys don't talk about it. You should. The false positive rate on Mythos was 30%. ... So the problem is, it's great for attack. It's horrible for defense. Because it finds 30 times, 30% of the time it finds something, I found a problem, and you say, let's plug the hole. Wait, there wasn't a hole there in the 1st place. ... So now the same problem applies in enterprise. If you use a model without the right harnesses, the right training, you could be running into 10, 20% false positive rates. Let's use the model to pay, I don't know, insurance claims. 10%, 20% false positive. I just lost money. The sycophantic nature of these is ridiculous. So the problem is not who wants the newest model. The problem is how do you take that model with 20% or 10% false positive and make it 0.01% false positive? In my business, I want 0%. ... Mercedes is going to use Opus 4.8 and you can just sit in the car and it's going to drive you. I'm not putting my kids in that car with a 10% false positive rate.

12
Prediction

Google will be the first $10 trillion company in our lifetime because it has all the necessary assets and the largest sales force to bring AI models to enterprise customers.

Arora predicts Google will be the first $10 trillion company, arguing it is underrated and has all the assets needed to succeed in AI — including a massive sales force that model-only companies lack to convince enterprise customers to adopt their technology.

transcript

Nikesh Arora: I think Google's underrated. I think it's going to be the first $10 million company in our lifetime. I think they have all the assets that are needed to make this successful. I think people underestimate. You can be a model company, you still need to have a sales force that convinces customers to go out there and embrace these models and buy them. And if you think about it, three hyperscalers have the biggest number of salespeople out there.

provides context · 1supports · 1

Highlight slides
Related episodes