A stark divergence emerged within the tech sector on Monday as AI safety warnings triggered a massive rotation out of semiconductor stocks and into cybersecurity software, with the gap between the two groups reaching historic proportions.
CrowdStrike (NASDAQ: CRWD) surged 13.8% to close at an all-time high, while Palo Alto Networks (NASDAQ: PANW) jumped 13% in its best single-day performance since April 2025, and Fortinet (NASDAQ: FTNT) advanced 9%. All three ranked among the S&P 500's top gainers for the session. The catalyst came from Anthropic CEO Dario Amodei, who published a warning that AI development is proceeding too rapidly and risks spiraling out of control. His comments weighed heavily on chip makers but unexpectedly served as a powerful tailwind for cybersecurity stocks.
This session marked an unprecedented performance gap between software and semiconductor stocks. According to Dow Jones Market Data, the iShares Expanded Tech-Software Sector ETF outperformed the iShares Semiconductor ETF by 10.67 percentage points in a single day — the largest such margin ever recorded. Analysts say the market signal is unmistakable: as doubts mount over the AI narrative, capital is rapidly shifting from compute hardware to security software.
AI Safety Warning Sparks Sector Rotation
In a lengthy blog post, Amodei detailed concerns about AI "recursive self-improvement" (RSI), the scenario where AI models gain the ability to train and iterate on themselves, potentially triggering uncontrollable leaps in capability. He also referenced a recent incident where an OpenAI AI agent attacked the open-source model platform Hugging Face, urging major industry players to slow down and prioritize safer AI progress. OpenAI CEO Sam Altman, along with Tesla and SpaceX CEO Elon Musk, publicly endorsed Amodei's position.
The warning directly pressured chip stocks that are highly sensitive to AI compute demand, but the market quickly pivoted to another line of reasoning: regardless of how AI development proceeds, security needs only stand to increase.
The More AI Expands, The More Security Spending Becomes Essential
Evercore ISI analyst Kirk Materne wrote in a Monday client note that whether AI agents are adopted by enterprises quickly or slowly, "these agents will still need to be protected, governed, and monitored," maintaining a "structural demand backdrop for cybersecurity and select infrastructure names" even if AI training momentum decelerates. Materne further stated that "greater scrutiny around AI safety could prompt enterprises to increase focus on identity management, data governance, observability, and security." He identified Okta, SailPoint, Palo Alto Networks, and CrowdStrike as initial beneficiaries, noting that companies are prioritizing identity security software in their spending plans. He also noted that cybersecurity vendors are accelerating partnerships with AI labs, particularly in run-time security — the real-time protection of active, operational systems.
Among all cybersecurity names, Materne believes Palo Alto Networks and CrowdStrike are "in the best position to consistently capture growing security spending," citing their differentiated ability to provide "integrated visibility and response across the entire security stack."
Jefferies analyst Joseph Gallo said in a report that while momentum is building around AI agent security, the market remains nascent. He expects "initial signals" in the second half of this year, with "meaningful contribution" potentially not materializing until 2027 or beyond. Gallo also sees identity security vendors among the first beneficiaries, citing high visibility in demand for that segment and accelerating product adoption driven by AI agent deployment.
Interestingly, D.A. Davidson managing director Gil Luria acknowledges the existence of AI security risks but diverges on the solution path. He stated in a report that the correct way for enterprises to address AI security threats is to "harden the code base" — strengthening software's ability to withstand attacks — rather than slowing AI development. Luria believes Microsoft, Amazon, and Google, with their vast customer bases, are the "ideal candidates" to lead this approach. His view complements those of Materne and Gallo: regardless of which path the industry ultimately takes, the central role of cybersecurity appears difficult to displace.