09/22 2026
380
In this year's AI market rally, a counterintuitive divergence has emerged.
US cybersecurity stocks have surged. As of August 31, the US Cybersecurity ETF CIBR has risen 40.36% year-to-date, far outpacing the Nasdaq and producing numerous stocks with doubled returns.
On the other side, Chinese cybersecurity stocks present a starkly different picture.
Even though Zhipu has secured cybersecurity-related orders exceeding 1 billion yuan, the entire sector remains in disarray. As of September 18, the CSI Information Security Theme Index has fallen 12.49% year-to-date.
One side is up 40%, the other down 12%—a gap of over 50 percentage points in less than a year.
This is intriguing.
Facing the same AI wave, why have US cybersecurity stocks become AI darlings while Chinese stocks have plummeted?
The core reason is that cybersecurity in the US and China has increasingly become two entirely different businesses:
US cybersecurity has evolved into infrastructure growing alongside AI usage, earning from AI expansion. In contrast, Chinese cybersecurity remains primarily a cost center, trapped within traditional government and enterprise IT compliance budgets.
This is the fundamental reason for the growing divergence between Sino-US cybersecurity stocks this year.
/ 01 / Two Entirely Different Markets
Sino-US cybersecurity stocks are transforming into two distinct businesses.
US cybersecurity is shifting from traditional software spending to an "AI tax" in the AI era. Meanwhile, Chinese cybersecurity revenue remains locked within traditional government and enterprise IT compliance budgets.
This difference first manifests in industry scale.
Gartner projects global information security spending to reach USD 244 billion by 2026, up 11.6% year-on-year.
The fastest-growing segment is precisely new demand driven by AI. Gartner separately tracks a market called Securing AI, encompassing AI application security, AI usage control, AI governance platforms, and AI Gateways.
By 2026, this market is expected to reach USD 2.835 billion, up 83% year-on-year; by 2027, it will further grow to USD 4.783 billion, an additional 68.7% increase.
In other words, after AI's rise, US enterprises haven't shifted security budgets from existing pools but created new security budgets instead.
From model licensing to data security, each new AI application potentially adds a new layer of security demand. The more AI deployments, the higher security spending becomes.
More critically, this revenue is already appearing in financial reports. Fortinet reported USD 2.05 billion in Q2 revenue, up 26% year-on-year; billings reached USD 2.37 billion, up 33%; GAAP operating margin hit 34%.
Palo Alto Networks is even more striking. In Q4 FY2026, its AI security product Prisma AIRS, launched just four quarters earlier, surpassed USD 100 million in ARR, becoming the company's fastest-growing new product ever.
In summary, US cybersecurity firms face a market growing at double digits annually, with AI creating incremental demand. In contrast, Chinese cybersecurity firms confront a market shrinking for three consecutive years.
Shuoshi Consulting data shows the 2025 domestic digital security market at RMB 88.743 billion, down 1.5% year-on-year.
More critically, this marks the third consecutive annual decline. In 2022, China's digital security market reached RMB 98.12 billion; it fell 0.76% in 2023, 7.4% in 2024, and another 1.5% in 2025.
Over three years, the market has shrunk by nearly RMB 10 billion.
Qianxin's H1 report actually states this bluntly. Affected by macro conditions and government finances, clients universally cut budgets, with project delays persisting. Meanwhile, fierce industry price competition leads clients to prioritize maintaining existing systems over new projects when budgets are tight.
In H1, Qianxin reported RMB 1.497 billion in revenue, down 14.09% year-on-year, with a net loss attributable to shareholders of RMB 411 million.
Some Chinese cybersecurity firms do benefit from AI, but the money doesn't necessarily flow to "security" first.
The most typical example is Sangfor. In H1, the company reported RMB 3.998 billion in revenue, up 32.85% year-on-year, with net profit attributable to shareholders of RMB 231 million, turning profitable.
But the fastest-growing business wasn't security. Cloud computing and AI infrastructure revenue reached RMB 2.212 billion, up 58.6%; cybersecurity revenue was RMB 1.587 billion, up 10.57%.
The former now accounts for 55.34% of revenue, becoming the absolute growth core for the first time.
/ 02 / US Cybersecurity Enjoys Platform Dividends While Chinese Firms Remain Project-Dependent
Beyond budget gaps, Sino-US cybersecurity business models are increasingly divergent.
US cybersecurity firms sell subscriptions. Clients sign contracts with ongoing renewals. As AI applications multiply, new security demands can be stacked onto existing clients.
With AI's emergence, US cybersecurity increasingly resembles a platform business.
On one hand, AI Gateways, AI application security, and agent identity and permission management represent entirely new demands that didn't exist before.
On the other hand, AI complicates IT environments, making clients prefer fewer vendors. Thus, leading firms like Palo Alto, CrowdStrike, and Fortinet can absorb budgets that would otherwise go to other security companies.
The most representative firm is Palo Alto. For years, it has emphasized "Platformization."
Simply put, large enterprises previously procured from dozens of security vendors—network security, cloud security, SOC, and identity security from separate providers. Palo Alto aims to consolidate these dispersed budgets into one platform.
This model is now working. In Q2 FY2026, Palo Alto had ~1,550 platform clients, up 35% year-on-year; their net revenue retention rate reached 119%. By Q4, this exceeded 120%.
This means clients on the platform typically spend more in their second year than their first.
The market is growing, and leaders can simultaneously raise per-client revenue. This explains why US cybersecurity firms' growth metrics are particularly impressive.
But China shows no such trend.
Many Chinese cybersecurity firms remain project-based, drawing funds from enterprise IT budgets with even lower priority.
For example, a local SOE might spend tens of millions on a large model platform to drive business operations—processing materials, analyzing data, building knowledge bases, or delegating tasks to agents. Such projects have clear use cases and can be approved independently.
Cybersecurity differs. It rarely directly generates business revenue. Thus, during new technology construction cycles, security demand lags behind production systems.
China is currently in this phase. Many government and enterprise clients are still building large model platforms, with budgets first flowing to models, computing power, data governance, and application development. Security is considered but usually as part of broader projects, rarely as a standalone large budget item.
In this process, traditional cybersecurity firms remain just one supplier among many, capturing only a fraction of revenue.
This explains why Zhipu can secure RMB 1 billion in orders while cybersecurity vendors struggle to achieve similar scale.
Of course, Chinese vendors are using AI to upgrade products—e.g., enhancing SOC, threat detection, and security operations with large models.
But here's the issue: adding AI doesn't guarantee clients will pay more.
A security system previously sold for RMB 1 million might now include large model analytics, but clients may view this as a normal product upgrade rather than justification for higher prices.
Vendors face increased R&D costs without proportional price hikes. For now, AI primarily adds costs for many Chinese cybersecurity firms rather than significant new revenue.
What could truly transform the industry are security products specifically protecting AI—model access control, data leak prevention, prompt attack protection, and agent permission management.
But for this demand to materialize, AI must first enter production environments.
This market remains nascent. The reason is simple: only when large models truly integrate into core business operations do these issues become painful enough. If a company's AI is only occasionally used by employees for writing materials, AI security rarely justifies a standalone budget.
This is where the US market moves faster.
Many US enterprises have already deployed Copilots, coding agents, and various AI applications in production. As AI accesses more enterprise data and internal systems, security becomes a prerequisite for model deployment.
Thus, US AI security is forming an independent market, while China hasn't fully reached this stage yet.
/ 03 / Conclusion
What truly divides Sino-US cybersecurity is the changing economic nature of security within enterprises.
US cybersecurity has transformed from a compliance cost into infrastructure growing alongside AI usage. The more enterprises use AI, the higher security spending climbs, with leading platforms continuously raising per-client revenue.
Chinese cybersecurity remains primarily a cost center. Clients purchase security for compliance and system stability, with inherently capped budgets that rarely grow with AI usage.
One earns from AI expansion; the other still from IT construction. This is the fundamental reason for their diverging valuations.
By Aqi