Investing

Interview: Aurora Labs CEO on AI’s impact on software stocks and cybersecurity

Software stocks have had a volatile ride this year as investors have repeatedly reassessed how artificial intelligence could reshape the sector.

The cohort came under pressure in February after Anthropic unveiled Claude Cowork, an AI agent designed to handle complex workflows traditionally performed by software applications and their users.

The development raised concerns that increasingly capable AI agents could undermine the business models of software companies.

That narrative flipped as companies including Atlassian, ServiceNow and Snowflake demonstrated that they could integrate AI into their platforms while continuing to grow revenue and customers.

Software stocks rallied again in the first week of September as investors turned their attention to companies positioned to benefit from rising AI adoption.

The optimism was short-lived. OpenAI’s latest Astra model reignited concerns about the ability of AI to disrupt software, sending stocks lower and reviving questions about the sector’s long-term value.

The narrative shifted again this week after AI executives called for a slowdown in AI development, triggering a sell-off across parts of the AI trade.

The renewed focus on AI safety, however, has also brought cybersecurity and software stocks back into the spotlight as investors assess the risks created by increasingly capable AI systems.

Declan Hannon, CEO of Aurora Labs

Declan Hannon, CEO of Aurora Labs, in a conversation with Invezz explained that AI is expanding the cybersecurity threat landscape but is not necessarily making traditional software obsolete.

Instead, he argues that AI is changing where software companies derive their value.

AI is making cyber threats faster and larger

Invezz: Cybersecurity companies such as CrowdStrike and Okta have reported strong results and cited AI as a reason for their performance. Is the demand structural, or is it simply a narrative the market currently rewards?

I would say it’s structural. There is obviously a big premium attached to companies that can apply AI, provided they are using it credibly. But the underlying threat facing companies has genuinely changed.

AI doesn’t suddenly make every hacker world-class, but it reduces the time and skill required to undertake certain attacks. Identifying vulnerabilities, writing and adapting code, and iterating attacks have become much easier because agents can work around the clock, examining code for vulnerabilities.

The biggest change is speed and scale. Attackers can automate large parts of an attack that previously required multiple people working manually.

At the same time, companies are deploying their own AI agents, creating a new class of identity within an organisation that needs permissions, access controls, and monitoring.

So the attack surface is getting bigger while the tools available to attackers are becoming more powerful.

Some companies will inevitably oversell the AI angle, but the demand for protection against AI-driven threats is not manufactured.

Security spending typically follows the level of threat companies perceive, and that threat has materially expanded.

Cybersecurity valuations face a higher bar

Invezz: How do you view the valuation of cybersecurity companies? Are they priced perfectly now, or is there more room to run?

I don’t think the two are mutually exclusive. You can have a completely valid, long-term investment thesis while still having an overvalued stock.

Tesla is a good example, with the stock sometimes falling even after earnings beats because investor expectations have been pushed far beyond forecasts by speculative hype. 

If investors are pricing cybersecurity companies as though AI guarantees years of accelerated growth, the bar becomes very high. Even good results can then disappoint the market.

The underlying demand for cybersecurity is also more defensive than many other software categories.

A company can delay replacing a CRM or upgrading a productivity tool, but it can’t easily delay protecting its infrastructure, data, or user identities.

That makes cybersecurity different from many other software sectors.

But purely from a valuation perspective, once expectations get ahead of fundamentals, any slowdown can produce a significant correction.

AI agents are becoming a new cybersecurity threat

Invezz: OpenAI’s model recently hacked Hugging Face. How should enterprises protect themselves going forward?

This is probably a much more important development. When AI was first being used, the initial cyber risk was largely humans using AI as a tool.

The Hugging Face incident highlighted where we’re heading: AI is becoming the actor within the system rather than simply a tool used by a human.

That substantially changes the security model. If an agent can discover vulnerabilities, chain them together, obtain access, and decide what to do next, you’re dealing with something that can operate at machine speed and outside the paths an organisation might expect.

For enterprises, this means they can’t simply ask their cybersecurity teams how to stop AI attackers.

They also need to examine what permissions their own agents have, what systems they can reach, and what happens if those systems are manipulated.

Companies need to detect abnormal agent behaviour quickly enough to respond.

I wouldn’t take one incident and conclude that autonomous AI is now roaming around hacking companies by itself. The circumstances surrounding that incident were unusual, including reduced safeguards.

But it is a clear warning about where the technology is going.

Security architecture needs to get ahead of that threat rather than waiting for it to become commonplace.

Invezz: Software stocks sold off earlier this year on fears that AI would compress the value of human-coded software. Are these stocks getting another chance because human developers are still needed to verify AI-generated software, or could AI eventually write software without coders?

The market initially treated AI as though it was going to destroy software, but that’s not really what is happening. AI is changing where the value in software lives.

If your moat is simply that it took a large number of engineers and a long time to build your application, your proposition becomes weaker when AI can dramatically reduce the cost of building software.

But code is rarely the only source of value.

Distribution, proprietary data, integrations, customer trust, unique workflows, network effects, and relationships all matter. None of those disappear because AI makes code cheaper to produce.

We’re going to see more startups that are almost entirely AI-built, particularly where customers are driven primarily by price.

But for much of the market, the winners will be companies that continue developing their own products while making them ready for AI agents.

If a product is agent-ready, with strong APIs, structured data, appropriate permissions, and interoperability, it becomes much harder to displace.

AI is therefore a risk to some software valuations and business models, but for strong companies it could increase product usage while reducing development costs.

The question isn’t whether AI kills software. It’s which software becomes more valuable when humans and agents use it together.

Which companies could benefit from the AI transition?

Invezz: Which companies or stocks are better equipped for this transition?

Revolut has an interesting use case. It has said it doesn’t want to approach AI in the same way as other companies, instead building it in-house and being strategic and selective about its deployment.

xAI is a company that will continue to grow. We’re also going to see much more AI usage in the automotive industry. Tesla has led the way with self-driving, but there are many more potential applications.

Within CRM, companies like Hubspot who are developing their AI “Breeze” are making CRM usage simpler.

Cybersecurity is more complicated because these companies have to balance trust and security against the additional functionality AI provides.

If cybersecurity companies go too far with AI, they risk losing the trust of the clients who rely on them to protect against AI-related threats, particularly while AI systems can still hallucinate.

Beyond that, B2B and B2B2C businesses could see significant gains quickly. Gaming is another interesting area where AI could enable new types of experiences.

On the stock side, Nvidia and other GPU providers should continue to benefit as long as demand for AI remains strong.

AI could reshape liability and insurance

Invezz: OpenAI and Anthropic are now saying their own models can become threat vectors. How does this change the insurance and regulatory challenges for these companies? Should AI companies be liable for the damage caused?

We’re moving toward a situation where the perpetrator of a breach or incident may not be a human being but an AI model. That raises difficult questions around ownership and responsibility.

Liability will inevitably move up the stack as AI systems become more autonomous. If an AI model simply provides information and a person decides what to do with it, responsibility is relatively straightforward.

It becomes much more complicated when an agent takes actions independently, interacts with third-party infrastructure, and makes decisions without human approval.

I don’t think the AI lab should automatically be liable for everything. That would be unworkable and would ignore how the model was deployed, what permissions it received, and whether the customer had appropriate controls in place.

There needs to be balanced liability. However, frontier AI labs such as Anthropic and OpenAI will have to take greater responsibility for testing, containment, and disclosure, while demonstrating that appropriate safeguards are in place.

Insurance could force some of these changes before regulation does. Insurers are good at turning vague risks into practical checklists because they have money at stake.

Policies will increasingly ask how AI agents are authenticated, what they can access, which actions are logged, what human approval exists, and how quickly access can be revoked.

That should create opportunities for independent security vendors. Companies may not want the same AI provider to supply the model, security layer, and audit its own behaviour.

Independent identity monitoring and security infrastructure could therefore become more valuable as autonomous AI enters critical environments.

The post Interview: Aurora Labs CEO on AI’s impact on software stocks and cybersecurity appeared first on Invezz