Analysis
CrowdStrike's George Kurtz told CNBC that AI is exposing security gaps legacy tooling was never designed to cover, in [an interview published Aug. 27](https://www.cnbc.com/2026/08/27/crowdstrike-ceo-ai-exposes-dangerous-cyber-gaps.html). Coming from the CEO of the largest pure-play endpoint security vendor it is obviously a sales argument. It is also, this week, a well-corroborated one.
Three separate items landed alongside it. OpenAI and Anthropic jointly warned that time is running out for companies to prepare for AI-enabled cyber threats. Axios documented Iranian operatives using AI to impersonate Americans across Meta's platforms in an influence operation. And a researcher demonstrated that Claude Code could be hijacked simply by asking it to summarize a malicious website -- an attack Pulse covered this week.
The structural argument is about tempo. Traditional detection assumes a human attacker working at human speed, leaving time between initial access and impact for an analyst to triage an alert. An attacker running automated reconnaissance, exploit generation and lateral movement compresses that window toward zero. Signature-based tools and alert queues worked against a threat that waited.
“Security remains one of the clearest enterprise budget expansions available in 2026, which is why every platform vendor is making a version of this pitch.”
The competitive frame is a market repricing itself around that claim. Palo Alto Networks has assembled a platform through acquisition, Microsoft Defender bundles into E5 and competes on price rather than product, SentinelOne and Wiz attack from endpoint and cloud posture respectively, and Visa just open-sourced an agentic remediation harness that does automated fix generation for free. That last one is the interesting pressure -- when a payments network gives away the remediation layer, the vendors selling it need a different story.
The counterweight CrowdStrike's own history supplies: the July 2024 update that took down 8.5 million Windows machines globally was not an AI-enabled attack, it was a content configuration error at the security vendor. Concentration in security tooling is itself a systemic risk, and the argument for consolidating more capability into fewer agents with deeper privileges runs directly into it.
Security remains one of the clearest enterprise budget expansions available in 2026, which is why every platform vendor is making a version of this pitch. The differentiator will be whoever can show remediation outcomes rather than detection volume.