CLAIM #66844 · Palo Alto Networks Inc (PANW) · 2026Q1 earnings call · Feb 17, 2026 · due Jul 31, 2030
“As such, we are raising our expectations from $15 billion to $20 billion in ARR for FY '30.”
Nikesh Arora · CEO
In context
“Nikesh Arora (Chairman and CEO): Thank you, Hamza. Good afternoon, and thank you, everyone, for joining us for our earnings call today. As you can see, we had a strong start to the year in Q1. We exceeded expectations across every guided metric, demand across our core business remains robust, and customers continue to platformize with us. Year over year, RPO grew 24% and GSAR was up 29%, and total revenue was up 16%. We saw strength across our portfolio in SASE, XIM, software firewalls, and even some early traction in our AI security platform, Prisma Airs. Our top-line growth was complemented by continued improvement in profitability, achieving our second straight quarter of over 30 percent operating margin. These results are a direct outcome of our strategy to deliver better security outcomes; our platform is earning more and more trust from customers that used to be fragmented across dozens of point products. At the same time, the threat landscape continues to evolve faster than we expected because of AI. As many of you saw last week, with one of the major AI platforms, AI hackers aren't a future threat they're here now. This is the first reported case of an AI agent autonomously conducting a large-scale nation-state cyber attack. The attacker was able to manipulate an agent to take steps on its own, with minimal human intervention. This is a turning point, proof that attackers are already weaponizing AI agents at scale. Even more importantly, they're able to attack quickly and will be able to exfiltrate data faster. AI is exposing the cracks in our enterprise architectures which do not have robust security. Patches are incomplete, platforms are missing, and there is a plethora of point products across the enterprise. This gap is exactly where attackers thrive. They're testing how far they can exploit a model. They're running prompt injections, jailbreaks, and model manipulations. Now we're seeing the next phase: autonomous AI agents being leveraged into the attack chain. AI is here, and with it, AI attackers are here too. Our message to customers is clear: real-time visibility and security are essential for infrastructure. This reality necessitates a paradigm shift in the industry. We must move away from today's fragmented security landscape and towards platformization. AI requires a seamless cyber data strategy. This platform approach allows security agents to be utilized effectively by the good guys to detect attacks, protect customers, and address immediate security concerns. Fragmentation creates friction, which in turn causes latency. Latency is a critical enemy of real-time cybersecurity. This is the backdrop that informs our strategy as we go forward. Now let's get into the quarter. In Q1, platformization once again drove large deals across multiple industry verticals. This included US Federal, where we had a strong quarter and notable competitive wins. One example was a $33 million SASE deal with a US cabinet agency securing 60,000 seats. This agency displaced a major SASE incumbent as they needed a platform to provide unified visibility across both their firewall estate and remote endpoints. Another example was a $100 million deal with a large US telecom provider. This included an $85 million commitment to XIM, which is our largest EXIM deal ever. This customer chose us to consolidate their disparate point products based on the ability of our platform to deliver materially faster mean time to respond. The common theme across these large transactions is clear: customers are moving from managing vendor sprawl to demanding superior, demonstrable security outcomes through platformization. The natural place for customers to start their journey is network security, which remains our largest business. In Q1, we continue to see strength in our next-generation software form factors. SASE had a phenomenal quarter. ARR grew 34% year over year, and surpassed $1.3 billion in Q1. Because we're the fastest growing SaaS provider at scale, we now have approximately 6,800 SASE customers, including one-third of the Fortune 500, and leading technology companies like IBM and Oracle. Even though it's early days, we continue to see strong momentum with secure browsers. The arrival of AI and agentic browsers will expose security cracks on them and focus the enterprise on ensuring the widespread adoption of secure browsers. In Q1, we crossed seven and a half million browsers sold while our bookings nearly quadrupled year over year. One more product which I'm getting more and more excited about recently is a shift I'm observing in our customers deploying more and more software firewalls. And it's beginning to show in our results. Product revenues grew 23% year over year. Today, nearly half of our product revenues are driven by the software form factor. We now have over 12,500 customers and maintained our leading market position in software firewalls. As AI transformation accelerates, growth in cloud workloads to software firewalls provides essential runtime protection with new AI data centers with its recent ability to step up and predict AI. Talking about predicting AI, let's talk for a bit about Prisma Airs. As I mentioned earlier, AI is moving faster than expected. This creates a critical moment for enterprise innovation. The reality is that while 78% of organizations are embracing AI transformation, a staggering 94% still lack the necessary security guardrails, presenting a massive risk. With our acquisition of ProtectAI now fully integrated, we introduced Prisma AIS 2.0 in Q1. The industry's most comprehensive end-to-end platform to secure AI protecting everything from autonomous agents to models that power them. I predict that AI agents will become a problematic insider threat if not secured. Prisma AIRS is the essential circuit breaker layer to stop them. It denies deep model inspection, provides real-time agent defense against threats like prompt injection, and ensures continuous autonomous AI red teaming in one platform. And once our acquisition of CyberArk closes, the addition of identity security will be critical to this mission, providing the essential privileged controls to govern these new autonomous insider threats and prevent agent identity impersonation. Our commitment to AI security is driving new high-value partnerships, including a collaboration with NVIDIA to secure the AI factory with Prisma Airs on Bluefield, and tight integrations with platforms like Glean, IBM, Factory, and ServiceNow in securing the exploding number of agentic AI workflows. Early customer traction is strong, reflecting the general market need. The number of AIS deals in Q1 more than doubled compared to last quarter. We believe we are the furthest ahead in AI security with marquee customers signing up with Palo Alto Networks, Inc. as they move from traditional to AI workloads. We believe we are going to continue to be in the pole position. In the same way I surprised the world with this pace, I want to talk about something else that will become relevant from a technology shift and security perspective. Quantum computing has seen significant innovations over the last year. We're getting more and more optimistic about the arrival of quantum and expect it to be commercialized by 2029. As is widely known, quantum computing has the ability to break current encryption across technology stacks. Enterprises have less than five years to prepare for quantum readiness. There is a fear that some nation-states will have quantum compute capability sooner than 2029. Last month, our partner IBM announced they were able to run a key quantum error correction algorithm on commonly available chips. The US government and many other nations are emphasizing post-quantum cryptography to drive new cryptographic standards that are resistant to attacks from future large-scale quantum computers. To address this, we have launched and will be delivering a complete quantum-safe strategy. First, we help you discover. In August, we launched our new version of PanOS, 12.1 Orion, which provides a quantum readiness solution to give customers an automated inventory of their cryptographic risk. Second, we help you protect. We launched our new fifth-generation firewalls which are optimized for quantum security. Third, we help you accelerate our platform. The unique Cypher translation capability can make legacy systems quantum safe immediately, even if the application itself cannot be upgraded. Beyond this, we have just announced that we're deepening our partnership with IBM to deliver the QuantumSafe Readiness and Remediation service, a complete end-to-end solution for post-quantum cryptography migration. Now moving to Cortex, which is a pillar of our security operations center strategy. ExIME continued its incredible trajectory in Q1. We now have approximately 470 customers with the average customer paying over $1 million in ARR. This includes large referenceable customers in every major industry. The success is no coincidence. Xi'M was built for large-scale data processing—organizing it, normalizing it, and making sense of it in real time. Today, we're processing 15 petabytes of telemetry on a daily basis. The result is demonstrable security outcomes. Over 60% of our deployed ExIM customers have reduced their median time to respond from days or weeks down to minutes. I am also thrilled to announce the launch of Agentyx this quarter. Agentyx brings powerful AI agents directly to the core of enterprise security challenges. In the future, the only effective countermeasure against Hacker AI will be our own AI agents, purpose-built for advanced security detection and remediation. For years, the industry has struggled with two defining issues: overwhelming alert fatigue and a massive global talent shortage. Agentyx is our definitive answer. This is a leap beyond mere automation; this is true autonomy. The ability to use predefined agents or build custom agents to secure enterprises is a step change in how security will work in the future. We are fundamentally transforming security operations and optimization by deploying autonomous AI agents that deliver enhanced speed, superior efficiency, and greater control for security practitioners. Right out of the box, Agentyx leverages a broad integration ecosystem connecting with thousands of existing security and IT tools and third-party environments. It provides customers with an intelligent, fully governed, and completely transparent teammate across the enterprise. Ready to operate on day one, Agentyx accelerates response, elevates quality, and frees up scarce human talent to focus on higher-order strategic work. Now shifting gears, I am pleased to announce our CyberArk integration plans remain fully on track and we're proud to have received overwhelming shareholder support for the acquisition, which is now expected to close in fiscal Q3. Since our announcements in July, we've spent more time with the CyberArk team, and we are even more excited about the growth opportunity and future product roadmap. This includes our vision of democratizing identity security across the enterprise and making identity the next platform for Palo Alto Networks, Inc. Anecdotally, our customers share in our enthusiasm, and early feedback has been encouraging. As many of you saw, CyberArk's business continues to execute, achieving record net new ARR in their most recent quarter. Even as we invest ahead of the curve, our long-term financial model remains intact. The scale of our platforms and operational leverage in our business reinforces our confidence in achieving over 40 percent free cash flow margins by FY '28, inclusive of both the pending and Chronosphere acquisitions. We are executing from a position of strength, and we see a clear path to drive both innovation and financial discipline. Now let's talk about our new announcement. I'm sure all of you are wondering why Palo Alto Networks, Inc., who is in the midst of a large acquisition of CyberArk, would engage in an acquisition at the same time of Chronosphere. I think it's important to understand where we are in the AI cycle. The AI cycle is moving fast. There's never a day that goes by without significant announcements on investments in AI, data centers, and AI infrastructure. This large surge towards building AI compute is causing a lot of AI players to think about newer models for software stacks and infrastructure stacks in the future. The seventeen-year-old observability industry was not designed for the AI era. AI requires always-on comprehensive observability at gigawatt scale. The challenge so far has been that full observability is cost-prohibitive for the customer. Chronosphere is one of the fastest-growing software companies in history. Their observability solution has already been deployed and has demonstrated scale at a large frontier model where they continue to move workloads across. Leading board on the cloud consumer platforms are applying full comprehensive observability, offering over 99.9 percent availability to their customers. Chronosphere is able to deliver this capability at a third of the cost of other industry-leading solutions. Yes. A third. With $1.5 trillion of compute coming online over the next few years, there will be continued demand for next-generation observability led by Chronosphere. I'm really excited about the possibility of delivering remediation in the observability category by bringing together the capabilities of Chronosphere and our newly announced Agentyx platform. Chronosphere also recently acquired a company called Calypta, a data pipeline provider, which complements their focus on observability and ensuring the right data gets onto their observability platform. Calypta integrated with XIM will enable us to offer our XIM customers comprehensive security data pipelining capabilities in line with current industry trends. This acquisition perfectly aligns with our strategic playbook. We acquired the best technology at an inflection point in the industry; we will invest in its development and utilize our go-to-market scale to quickly deliver this game-changing innovation to our customers. Remember, this is barely 2.5% of our market cap, which is consistent with our tuck-in strategy over the last seven years of acquiring companies. To summarize, we had a strong start. Our core business is firing on all cylinders, platformization continues to take hold, and overall demand is strong. Over the last year, we have shown our ability to scale a billion-dollar plus ARR business in SASE and Cortex. Looking ahead, we think software firewalls is our hidden gem and possibly the next billion-dollar opportunity. We maintain a relentless focus on innovation by tackling new challenges in AI security and quantum. Finally, our ambitions continue to grow. This year, we'll be significantly expanding our opportunity in new markets as we close the acquisitions of CyberArk and Chronosphere in both categories of identity and observability, which we believe are in the midst of an inflection due to AI. We are less than 5% penetrated in a TAM, reaching nearly $300 billion in the next three years. As such, we are raising our expectations from $15 billion to $20 billion in ARR for FY '30. With that, I'll hand over the call to Deepak to review the quarterly results in detail.”
Verify independently
SEC filings for PANW ↗ · Claim quote is verbatim from the 2026Q1 earnings call.