top of page

Netskope AI Security Growth Hits 29%, but Proof Must Follow the Pipeline

Sep 11
12 min read

Netskope increased quarterly revenue 29% as enterprises confronted a harder question: how can employees and software agents use AI without exposing sensitive data? The Netskope AI security growth story now rests on turning that concern into lasting subscriptions. Revenue reached $220.5 million in its fiscal second quarter, while annual recurring revenue rose 27% to $899 million.

Those figures cover the quarter ending July 31, 2026. Netskope reported them on September 2 and said every reported metric exceeded its earlier guidance. Management also raised its full-year revenue outlook, strengthening the argument that demand extends beyond a brief surge of AI-related interest.

The tension lies beneath those headline results. Many customers exploring Netskope’s newer AI security products remain in proof-of-concept projects, according to management. Meanwhile, Netskope competes with larger platform vendors, including Palo Alto Networks, Cisco, Broadcom, Fortinet, and Zscaler. Its opportunity is real, but its lead is not settled.

Netskope AI Security Growth Has a Broader Engine

The quarter shows strong platform demand, but it does not isolate how much revenue came directly from AI security products.

Netskope’s quarterly filing reports revenue of $220.5 million, up from $170.8 million one year earlier. Gross profit increased from $123.2 million to $163 million. The resulting GAAP gross margin rose two percentage points to 74%.

Annual recurring revenue, or ARR, reached $899 million. ARR represents the recurring value of active subscriptions at a point in time. It can indicate future revenue momentum, although it is not a standardized accounting measure.

Netskope added $54 million in net new ARR during the quarter. That figure placed the company within reach of a major recurring-revenue threshold, but growth moderated from the 29% ARR increase reported in the preceding quarter.

The company attributed its results to demand for Netskope One, not exclusively to a single AI product. Netskope One combines more than 25 security, networking, analytics, and AI offerings through a shared platform. Its functions include protecting data, controlling cloud access, detecting threats, and connecting users to private applications.

This distinction matters because the Yahoo Finance headline presents an AI security wave as the central driver. AI appears to be expanding customer conversations and the product pipeline. However, the reported financial statements do not separate AI security revenue from Netskope’s established security service edge business.

Security service edge, or SSE, delivers security controls from the cloud for users accessing websites, software services, and private applications. Netskope already sold those capabilities before generative AI became a board-level concern.

The company’s opportunity comes from applying that existing inspection layer to new traffic. Prompts, uploaded documents, model responses, application programming interfaces, and agent actions all move between users, data, and online services. A vendor positioned in that path can apply access and data policies without deploying a separate control for every model.

Netskope’s quarter therefore reflects two connected developments. Its established platform continued gaining recurring business, while AI created new reasons for customers to expand their deployments. The second claim remains less measurable because the company has not published a separate AI revenue figure.

Management said some AI security deals had closed and many others had reached proof-of-concept testing. That is meaningful early demand, but it is not the same as broad production adoption. The next phase requires those pilots to survive security reviews, budget approval, procurement, and deployment.

Why Enterprise AI Creates a New Security Control Point

Generative AI expands the volume and variety of sensitive interactions that security teams must identify before they can govern them.

An employee can paste source code into a public chatbot, upload a contract for summarization, or connect an internal database to an AI assistant. An autonomous agent can perform similar actions repeatedly and at machine speed. Each interaction creates questions about identity, authorization, data classification, retention, and model behavior.

Traditional web filtering can determine whether a destination is allowed. AI governance demands finer context. A company might permit an approved chatbot while blocking uploads containing customer records. It might allow an agent to read a support ticket but prevent it from sending data to an unapproved model.

Netskope sees this traffic as an extension of its existing position between enterprise users and cloud services. Its products inspect activity, classify data, and apply policies while a transaction occurs. That architecture gives the company a credible route into AI security without asking customers to build a separate enforcement layer.

The company’s AI Guardrails offering aims to control how employees interact with AI applications. Its AI Gateway addresses access to models and related services. Other products target software agents, data exposure, and security operations.

Netskope also introduced its DataSec Command Center, which provides a shared view of sensitive information across endpoints, cloud services, email, networks, and AI environments. The product’s significance lies in the data map, not its dashboard. AI controls work poorly when an organization cannot identify the material being copied, retrieved, or generated.

That problem reaches beyond cybersecurity specialists. Developers must know whether an assistant can read repositories or deployment secrets. Legal teams need evidence about data handling. Procurement teams must compare overlapping controls. Knowledge workers need clear boundaries that do not block every useful AI interaction.

A well-maintained AI knowledge base also depends on access controls and reliable source boundaries. Search and summarization become riskier when permissions, ownership, or data lineage remain unclear.

Netskope’s position becomes more valuable as enterprises move from chatbots toward agents. A chatbot generally waits for a person to submit a prompt. An agent can choose tools and execute multistep tasks with less supervision. That autonomy increases the number of transactions and makes continuous policy enforcement more important.

Management also argues that performance matters alongside inspection. AI applications can involve multiple prompts, large context transfers, and frequent model calls. A security layer that introduces noticeable delay can frustrate users or encourage teams to bypass approved systems.

Netskope says its NewEdge AI Fast Path optimizes network routes to popular AI services. According to the company’s financial release, internal testing showed latency reductions of up to 90% for selected AI destinations. That is a company-reported maximum, not an independent benchmark across customer environments.

The strategic pitch combines governance with performance. Netskope wants customers to route AI activity through its network because that path can inspect data and shorten communication routes. If the product only restricts behavior, users may resist it. If it also improves response times, adoption becomes easier to defend.

The Main Contest Is Platform Consolidation

Netskope must convince customers that its integrated architecture offers better control than security bundles from much larger vendors.

Netskope does not enter the AI security market alone. Its own annual report identifies Broadcom, Cisco, Fortinet, Palo Alto Networks, and Zscaler among its primary competitors. Several sell adjacent network, endpoint, cloud, identity, and security operations products.

This creates the article’s central contest: Netskope One versus the broad security bundle. Netskope argues that a shared engine, console, network, and code base can replace fragmented tools. Larger rivals can answer that customers already use their platforms and can add AI controls through existing contracts.

The buyer’s decision rarely turns on one feature. Enterprises consider the number of products they can retire, integration effort, regional infrastructure, policy consistency, incident response, and commercial leverage. A technically strong AI control can lose if adopting it adds another console and another source of operational complexity.

Palo Alto Networks illustrates the scale of that pressure. The company reported that its next-generation security ARR reached $9.10 billion for the fiscal year ending July 31, 2026. That measure grew 63%, according to its fiscal results. Its revenue base and cash generation give it substantial capacity to bundle products, fund research, and pursue acquisitions.

Direct comparisons require caution because the companies define product categories differently. Palo Alto Networks’ next-generation security ARR includes a broad collection of businesses. Netskope’s $899 million ARR represents its own subscription base. The figures still reveal the difference in operating scale.

Zscaler presents a closer architectural rivalry because both companies developed cloud-delivered security around user and application traffic. Cisco and Fortinet bring existing network relationships. Broadcom can compete through its security portfolio and large-enterprise footprint.

Netskope’s answer is specialization combined with consolidation. It says its platform can understand cloud applications, data context, user behavior, and network conditions within the same policy decision. That promise is most compelling when a customer wants to replace several point products.

AI makes the platform argument more urgent. A software agent can move across cloud applications, models, private databases, and internet services during one workflow. Separate controls might observe only fragments of that activity. A unified policy layer can, in theory, preserve context across the sequence.

However, larger platforms can pursue the same architectural goal. They can integrate endpoint telemetry, identity information, firewalls, and cloud security into their AI controls. Their installed bases give them access to data and distribution that a smaller vendor must win through product performance.

Netskope’s 29% revenue growth proves that it is winning business within this competitive field. It does not prove that its platform has become the default control plane for enterprise AI. The company must keep adding customers while expanding contracts among existing ones.

That expansion is central to the model. Netskope reported $709 million in fiscal 2026 revenue, up 32%. Its annual filing said existing-customer expansion produced about 71% of that year’s revenue increase, while new customers contributed about 29%.

Existing relationships can accelerate AI security adoption because Netskope already handles relevant traffic and policies. Yet dependence on expansion also creates a test. Customers must see enough added value to allocate more budget rather than treating AI controls as included features.

Early AI Security Demand Still Has to Become Revenue

A fast-growing pipeline is encouraging, but proof-of-concept activity can overstate near-term commercial adoption.

On the earnings call, Netskope said customer engagement with its AI security suite was strong. Some deals had closed, while many more were in proof-of-concept stages. A proof of concept lets a customer test whether a product works in its environment before committing to a wider rollout.

Management’s earnings discussion indicated that roughly one-third of the relevant opportunities had entered proof-of-concept work. The company also described enterprise procurement cycles that commonly take six to 12 months.

That timeline limits how confidently investors can connect current revenue growth to the new AI suite. Q2 results include contracts and expansions generated by the broader Netskope One platform. Many newer AI opportunities remain too early to contribute their full potential.

Pilots also create selection bias. A customer can test multiple vendors simultaneously, negotiate with an incumbent, or decide that existing controls are sufficient. Some projects remain small because the organization has not deployed agents or generative AI widely enough to justify a larger contract.

Production use raises harder requirements than a demonstration. The system must classify sensitive data accurately, support regional policies, integrate with identity systems, and avoid interrupting legitimate work. It also needs audit evidence that legal, compliance, and security teams can understand.

False positives present a practical risk. If a policy blocks ordinary prompts or safe documents, employees may seek unapproved alternatives. False negatives carry the opposite danger because confidential data might reach a model without detection. Netskope has not published enough independent performance data to settle that balance across varied customer settings.

The company also faces rapid change outside its control. Model providers alter interfaces, enterprise applications add embedded assistants, and agent protocols evolve. Security products must keep recognizing new destinations and interaction patterns without forcing customers into repeated redesigns.

Netskope’s reporting acknowledges these uncertainties. Its SEC disclosures cite limited experience with new products, the risk of software defects, uncertain customer acceptance, evolving technology, long sales cycles, and intense competition.

The company’s total addressable market estimates should receive similar caution. Management describes an existing opportunity valued at $75 billion in 2024, growing at an estimated 17% compound annual rate through 2029. It says AI security can add more than $170 billion.

Addressable-market estimates describe possible spending, not committed revenue. They often include adjacent categories and assumptions about future products. Netskope’s opportunity will depend on what customers buy separately, what vendors bundle, and how quickly experimental AI deployments reach production.

The stronger evidence is customer behavior already visible in recurring revenue. ARR rose 27%, and the company raised its full-year forecast. Those figures support durable demand for Netskope One. They do not yet quantify AI security’s independent contribution.

The distinction does not invalidate the Netskope AI security growth thesis. It defines what must happen next. Pilots must become contracts, contracts must expand, and AI products must improve retention or net new ARR rather than simply relabeling existing cloud security demand.

Better Margins Do Not Erase the Loss Question

Netskope improved its adjusted operating performance, but GAAP losses and negative quarterly cash flow remain material counterweights.

Non-GAAP gross margin increased from 75% to 77% year over year. The non-GAAP operating loss narrowed from $34 million to $19.3 million, while the corresponding margin improved from negative 20% to negative 9%.

Those measures indicate better underlying operating leverage after Netskope excludes selected expenses. They support management’s claim that revenue can grow faster than some adjusted costs.

The GAAP picture moved differently. Netskope reported a $89.8 million operating loss, compared with $46 million one year earlier. Its GAAP operating margin declined from negative 27% to negative 41%.

The main bridge between those presentations included stock-based compensation, related payroll taxes, acquired-intangible amortization, and restructuring costs. Stock-based compensation reached approximately $63 million during the quarter, up from about $7.6 million one year earlier.

Some of that increase reflects Netskope’s transition into the public market and associated equity accounting. Stock compensation is noncash during the reporting period, but it can dilute shareholders. Readers should not treat the non-GAAP improvement as interchangeable with GAAP profitability.

Cash flow provides another check. Netskope used $16.5 million in operating cash during the quarter, close to the $16.9 million used one year earlier. Free cash flow fell to negative $29.8 million from negative $19.7 million.

Quarterly cash generation can vary with customer billing, collections, capital spending, and payment timing. One negative quarter does not erase Netskope’s positive free cash flow for fiscal 2026. It still shows why profitability remains part of the AI security growth debate.

The company ended July with approximately $1.1 billion in cash, cash equivalents, and marketable securities. That balance gives it room to invest in product development, its NewEdge infrastructure, and sales capacity. It also means the immediate issue is operating discipline rather than near-term liquidity.

Management now expects full-year fiscal 2027 revenue between $888 million and $892 million. It forecasts a non-GAAP operating margin near negative 9%, a non-GAAP gross margin near 77%, and a free cash flow margin near 2%.

For the third quarter, Netskope guided to revenue between $227 million and $229 million. That range implies continued sequential growth, but it also establishes a higher base that future results must exceed.

The financial tradeoff is straightforward. Netskope can continue investing aggressively to capture an expanding AI security market, or it can prioritize faster margin improvement. Doing both requires durable subscription growth and careful control of infrastructure, development, and sales expenses.

Competition makes restraint harder. Palo Alto Networks, Cisco, Broadcom, Fortinet, and Zscaler continue funding overlapping products. Netskope cannot assume that early customer interest will remain available if it slows development.

Yet growth without economic improvement has limits. Enterprise security contracts involve support, global infrastructure, compliance work, and continual threat research. Strong gross margins must eventually translate into operating cash after those expenses.

The next few quarters should therefore be judged on paired results. Revenue and ARR must stay healthy, while free cash flow and GAAP operating trends show whether scale is improving the business.

Three Signals Will Decide Whether the AI Wave Lasts

The next test is not another product announcement. It is measurable conversion, recurring growth, and progress toward sustained cash generation.

The first signal is proof-of-concept conversion. Netskope has described a large and rapidly advancing AI security pipeline, with some deals closed and many undergoing customer tests. The company should eventually disclose whether those evaluations become production deployments.

A rising number of completed deals would strengthen the case that AI security represents a new purchasing category. Stalled pilots would suggest that customer concern is high but willingness to allocate separate budgets remains limited.

Contract scope matters as much as the count. A small AI add-on for an existing customer carries less strategic weight than a platform expansion spanning data protection, AI gateways, agent controls, and network services.

The second signal is ARR performance. Netskope ended Q2 at $899 million after adding $54 million in net new ARR. Future reports should show whether the AI pipeline helps maintain recurring growth as the comparison base becomes larger.

Investors should watch both total ARR growth and management’s explanations for net new ARR. Continued strength from customer expansion would support the platform-consolidation argument. A sharp slowdown would indicate that competitive bundles or longer procurement cycles are constraining adoption.

Customer concentration and retention also deserve attention if Netskope provides more detail. AI security becomes strategically meaningful when customers keep and expand the controls after their initial contract periods.

The third signal is cash conversion. Netskope expects a positive full-year free cash flow margin despite reporting negative free cash flow during Q2. Meeting that guidance would show that management can fund expansion while moving toward a more sustainable operating model.

Missing the cash target would not automatically disprove the product thesis. It would weaken the financial case, especially if sales and research spending keep rising faster than revenue.

These signals should be evaluated together. Strong pilot conversion without ARR acceleration might mean contracts remain small. ARR growth without better cash generation might indicate expensive customer acquisition or infrastructure demands. Improved cash flow alongside weak product conversion could reflect cost control rather than AI momentum.

Competitive responses form the surrounding context. Larger vendors can bundle AI controls, acquire specialist capabilities, or use existing network and endpoint contracts to reduce Netskope’s opening. Customers may also consolidate around fewer platforms as security budgets face scrutiny.

Netskope’s second-quarter results establish a credible starting point. Revenue increased 29%, recurring revenue reached $899 million, margins improved on an adjusted basis, and management raised its annual outlook. The company also has a logical technical position between users, agents, data, and AI services.

What remains unproven is the headline’s strongest implication: that AI security itself has become a material, measurable growth engine. The company currently reports early traction, pilot activity, and platform-wide demand rather than a separate AI revenue line.

Enterprise buyers should use the next quarter to compare policy depth, deployment effort, performance, and data visibility across vendors. Investors should focus on pilot conversion, net new ARR, and free cash flow rather than product counts alone.

The Netskope AI security growth story will become more convincing when those measures move together. Until then, the quarter demonstrates demand for the broader platform and a promising AI pipeline, not a completed market victory.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page