If you follow AI cybersecurity, you'll find something odd about Zscaler: strong earnings - revenue up 25%, ARR up 25%, operating profit margin at an all-time high - yet the stock was hammered.
This is not just an earnings fluctuation; Wall Street is judging a bigger issue: in the AI era, is cybersecurity a real necessity or another overhyped software story?
If you only look at the stock price, you'd think Zscaler is in trouble.
But if you look deeper, you'll find that what's really in trouble may not be Zscaler, but the entire enterprise security rulebook being rewritten by AI.
In the past, companies defended against hackers - against humans.
Now, companies must defend against AI that can automatically write code, find vulnerabilities, fake identities, and even autonomously log into systems and execute tasks.
More frightening, in the future companies will have not only employee accounts but also AI Agent accounts. They will access customer data, call internal systems, read databases, send emails, and even trigger business processes.
So the question is:
Who decides what these AI Agents can and cannot see?
Who stops them from exceeding privileges?
Who prevents employees from leaking confidential data into external models?
And when AI helps hackers scan for vulnerabilities at machine speed, who guards the last door for enterprises?
This is why this Zscaler video is worth watching.
After watching, you'll understand at least three things.
First, why Zscaler's strong earnings led to a stock drop, and what the market really worries about.
Second, why Zero Trust, AI Red Teaming, and Agentic SecOps might become the toughest new themes in AI software stocks.
Third, whether Zscaler is a slowing software stock or a core AI security player misjudged by short-term sentiment.
If you still think AI security is just a small branch of cybersecurity, you might be missing the most dangerous and profitable dark lane in the next AI software wave.
Because the stronger AI becomes, the less enterprises dare to go unprotected.
Whoever secures the entry point for AI into enterprise systems could become the real tollbooth of the next phase. Before we start the video, please like and subscribe to the channel, and let's dive into today's focus.
First, the earnings themselves.
Zscaler's Q3 earnings look great on the surface.
Revenue grew 25% YoY.
ARR grew 25% YoY.
Non-GAAP operating margin reached 23%, an all-time high.
What does this show?
Zscaler is not a software company that just burns cash on stories. It has entered a more mature phase: revenue still growing, margins improving, customer demand intact, and the Zero Trust theme still valid.
But the problem is that the US stock market is never a gentle teacher.
It won't reward you just for scoring 90.
If the market expected you to score 95, or even 98 next time, then delivering 90 today can still get you punished.
That's the cruelty of high-growth stocks.
The mistake isn't necessarily about now, but about failing to excite for the future.
Zscaler's sell-off is not due to a business collapse, but market doubts about the future.
Q4 guidance wasn't impressive enough, sales team adjustments worried investors about execution, and the overall software stock market is in a sensitive phase. As soon as future growth shows any uncertainty, capital runs first.
That's the current software stock market.
You can't just be good; you must be better.
You can't just grow; you must prove growth can continue.
You can't just say AI brings opportunities; you must prove AI turns into orders, revenue, profit, and free cash flow.
So Zscaler's decline is essentially the market asking one question: When will your AI security story turn into real money?
But viewed differently, this divergence is interesting.
If a company's earnings were already bad and the stock fell, there's little to discuss.
But if operating data is still decent and long-term logic is strengthening, yet the stock is hammered due to short-term expectations, then market divergence may exist.
Real investment opportunities often hide in divergence.
Next, we need to see if Zscaler's long-term logic has changed.
The answer is not only unchanged, but possibly more important.
Why? Because the AI era is reshaping cybersecurity.
In the past, enterprise security was like defending a castle.
Inside the company was the city; outside was the enemy. Firewalls were like walls, VPNs like gates. As long as you guarded the perimeter, you felt safe.
But now the world has changed.
Cloud apps, SaaS systems, remote work, API interfaces, third-party plugins, external model calls - they have riddled the old walls with holes.
Company data is no longer only in corporate servers; employees no longer only in offices; apps no longer run only on internal networks.
The perimeter is gone.
After AI Agents emerged, the problem became more complex.
An AI Agent is not an ordinary tool.
It can automatically log into systems, access customer data, generate reports, modify code, send emails, create tickets, and even trigger business processes.
Sounds great, right?
But from a security perspective, it's scary.
Because an AI Agent that can autonomously perform tasks is essentially a never-sleeping digital employee.
It needs permissions.
It needs data access.
It needs to call applications.
It needs to connect different systems.
If permission management is insufficient, data boundaries unclear, models misled by prompt attacks, or AI Agents exploited by hackers, they can turn from efficiency tools into internal security vulnerabilities.
That's why Zero Trust becomes a necessity again in the AI era.
The core logic of Zero Trust is simple: Don't default trust anyone, any device, any application, any connection.
Every access must be verified.
Every data flow must be inspected.
Every user, device, application, and AI Agent must operate under least privilege.
Sounds cumbersome, but that's exactly what large enterprises are willing to pay for.
Because what enterprises fear most is not hassle, but loss of control.
In the past, hackers looked for doors; now AI can help them scan every window in the building.
In the past, companies worried about employee account theft; now they also worry about AI Agents being induced to exceed privileges.
In the past, data leaks might be employee mistakes; now leaks can come from an automated agent exfiltrating information in milliseconds.
So if your company still relies on old VPNs and traditional firewall thinking, it's like using a wooden door to block tanks in the AI era.
That's where Zscaler's value lies.
It's not just selling a security product; it's integrating enterprise access control, application connectivity, data protection, Zero Trust architecture, and AI security capabilities.
That's why its collaborations with OpenAI and Anthropic are most noteworthy.
Zscaler's partnership with OpenAI is not just about "we also use AI."
It emphasizes using advanced model capabilities for secure development processes, vulnerability detection, AI Red Teaming, and Agentic SecOps.
In plain English, it means using AI to help security teams discover code vulnerabilities faster, identify risks faster, test system weaknesses faster, and respond to security incidents faster.
This is important.
Because the future security industry may enter a new phase.
Not human vs human.
But human + AI vs human + AI.
Previously, cybersecurity was like two chess players.
Now it may become both sides playing with supercomputers.
Attackers can use AI to find vulnerabilities, write malicious code, forge emails, simulate identities, and quickly test attack paths.
If defenders rely on manual slow inspection, patching, and response, they will increasingly struggle.
So security companies must also use AI.
Zscaler's involvement in Anthropic's Project Glasswing has similar significance.
If models like Claude can find software vulnerabilities faster and understand code risks quicker, that's good for defenders.
But conversely, it also means vulnerability discovery will accelerate.
Security issues in the software world may be amplified by AI.
Previously, a vulnerability might take security researchers days or weeks to uncover.
In the future, AI could dramatically speed up vulnerability discovery.
For enterprises, this is both opportunity and fear.
Opportunity: they can fix problems faster.
Fear: attackers can also exploit problems faster.
So long-term demand for AI security is not pushed by marketing, but naturally driven by technological change.
The stronger AI becomes, the stronger attacks become.
The stronger attacks become, the less defense budgets can be cut.
That's the toughest point in Zscaler's long-term logic.
So where exactly is Zscaler's opportunity?
I think it can be broken into four layers.
First layer: replacing traditional VPNs and firewalls.
This is Zscaler's original core logic.
As enterprises become more cloudified, employees more distributed, and applications more numerous, traditional perimeter security becomes increasingly strained. Zero Trust architecture continues to replace old architecture; this path is not over.
Second layer: protecting enterprise use of generative AI.
Now employees may use ChatGPT, Claude, Copilot, and various internal AI tools.
What do enterprises fear most?
Employees putting customer lists into them.
Financial data going in.
Source code going in.
Trade secrets being sucked out by external models.
So enterprises need to know who is using AI, which AI, what data is transmitted, and whether there is leakage risk.
That's the demand for AI access security and data protection.
Third layer: protecting AI Agents.
This is a bigger story for the future.
When AI Agents not only chat but start accessing systems, calling APIs, reading data, and executing processes, enterprises must set their identities, permissions, boundaries, and audit trails.
Whoever helps enterprises control AI Agent behavior may get new security budgets.
Fourth layer: AI Red Teaming and automated security operations.
Enterprises must not only defend against external attacks but also proactively test their own AI systems for vulnerabilities.
Can the model be attacked via prompt injection?
Can AI Agents exceed privileges?
Can internal data be misused?
Are there hidden flaws in application code?
Can security teams use AI to fix problems faster?
If Zscaler can combine these capabilities, it won't just be a traditional cybersecurity company, but possibly the enterprise AI security gateway.
That's where its imagination lies.
In the future, enterprises won't ask "Should we use AI?"
That question is settled.
What they'll really ask is "How can we use AI safely?"
Whoever can answer that may get the next round of budgets.
But having said that, we must also clarify the risks.
Zscaler is not without risks, and the market drop is not entirely unreasonable.
First risk: short-term guidance.
High-valuation software stocks fear downward growth revisions most. Once the market feels future revenue growth may decline, the stock gets hit.
Second risk: sales team adjustments.
Cybersecurity software growth heavily relies on sales execution, large customer expansion, cross-selling, and renewals. Any disruption in the sales organization makes markets very sensitive.
Third risk: intense competition.
Zscaler is not fighting alone.
Palo Alto Networks, CrowdStrike, Okta, Cloudflare, Microsoft, Wiz - all vie for enterprise security budgets.
Every company talks about AI security; every company wants to be a platform.
Customer money is limited; whoever can truly prove effectiveness gets more budget.
Fourth risk: the AI security story still needs revenue validation.
AI Red Teaming, Agentic SecOps, AI Access Security - these terms sound advanced, but the market ultimately looks at whether customers pay, contracts grow, renewals improve, and revenue contributes.
If it's just hot concepts with no real conversion in earnings, valuation expansion is hard to sustain.
Fifth risk: valuation and interest rate environment.
Software stocks fear changes in rates and risk appetite.
No matter how good the company, if valuation is too expensive and market environment shifts, it will be compressed.
So Zscaler now does not lack a story; rather, the story is so big that the market starts asking when it becomes money.
That's my core judgment.
Zscaler is not a stock you can blindly rush into.
But it is definitely a core candidate worth putting on the AI security watchlist.
How does it compare with other AI security stocks?
Let's break it down simply.
Zscaler's keywords: Zero Trust, SASE, cloud access, data security, AI access control.
CrowdStrike's keywords: endpoint security, threat detection, cloud security, AI security operations.
Okta's keywords: identity management, AI Agent identity, access permissions.
Palo Alto Networks' keywords: platform security, firewall, cloud security, security operations.
Cloudflare's keywords: network edge, application security, Zero Trust, developer and edge network.
So not all security stocks should be lumped together.
AI security will benefit the whole sector, but each company captures different budgets.
If enterprises worry about AI Agent overreach, Okta's logic is more direct.
If they worry about endpoint threats and attack detection, CrowdStrike is more direct.
If they worry about cloud access, data flow, VPN replacement and Zero Trust, Zscaler is more direct.
If they want a comprehensive platform security, Palo Alto has an edge.
That's why cybersecurity stocks will continue to diverge.
Not all security stocks are the same.
What really matters is where each sits in enterprise AI security.
What should ordinary investors watch going forward?
I think Zscaler has several key metrics.
First, can ARR growth stabilize at a high level?
This indicates whether long-term contracts and subscription demand remain strong.
Second, can the number of large customers and million-dollar customers continue to grow?
The most valuable security software customers are large enterprises, especially multinationals and big institutions.
Third, can non-GAAP operating margin and free cash flow continue to improve?
This shows the company is not just burning cash for growth but moving toward a more mature business model.
Fourth, can new products like AI Security, AI Red Teaming, Agentic SecOps begin to contribute clear revenue?
This determines whether the AI story stays in press releases.
Fifth, can sales execution issues be fixed?
If sales team adjustment effects persist, short-term stock may still be under pressure.
Sixth, can next fiscal year's guidance regain market confidence?
Growth stocks ultimately compete on the future, not the past.
Real opportunity lies not in how much the stock dropped or how good the earnings headline looks.
Real opportunity lies in: if the market hammers it due to short-term guidance but mid-to-long-term AI security demand continues to rise, then this divergence may become an investment opportunity.
Let's go back to the original question.
Is Zscaler a risk signal or an opportunity window?
My answer: both.
In the short term, it indeed exposed issues with growth expectations, sales execution, and high market demands.
In the long term, it stands at the intersection of Zero Trust and AI security, a very important position.
In the AI era, security is not a supporting role but a pass.
If enterprises want to use AI, they must solve access control, data protection, identity management, model security, vulnerability detection, and Zero Trust architecture.
If these problems are not solved, enterprises won't dare to put AI into core systems.
So AI security is not optional; it's one of the infrastructures for AI adoption.
That's the biggest takeaway from Zscaler's earnings.
The market may penalize its guidance in the short term, but the long-term AI security theme hasn't disappeared.
You could even say: the more AI proliferates, the more this line is worth watching.
If AI Agents enter enterprises at scale in the future, the real beneficiaries won't be just model companies or GPU companies.
Security companies are likely to become the toughest link in the next round of AI budgets.
To summarize:
The key of Zscaler's earnings is not strong numbers or stock decline, but that it pushes to the forefront the most easily underestimated line in AI software stocks.
Zscaler's opportunity: Zero Trust is upgrading from a cloud security architecture to the enterprise access control foundation in the AI era.
Zscaler's risk: short-term guidance, sales execution, competitive pressure, valuation volatility all need market reassessment.
So it's not a blind-buy target, but a core AI security observation target worth continuous tracking.
If you feel this content helped you see Zscaler and the AI security line clearly, remember to like, bookmark, and subscribe.
See you next time.