CrowdStrike Bets on Its Own Models to Secure the AI Revolution

CrowdStrike Bets on Its Own Models to Secure the AI Revolution

Analyst(s): Fernando Montenegro
Publication Date: September 8, 2026

What Is Covered in This Article:

  • CrowdStrike’s Fal.Con 2026 announcements, from SafeMind and the Cyber Superintelligence Lab to Falcon Guardian and the Agentic SOC
  • Why its bet on building specialized security models is defensible, and the promise of the digital twin
  • The gap between securing agents technically and governing them at the business layer
  • What the endpoint re-architecture and on-device AI mean for CrowdStrike’s core
  • What to watch as AI-enabled attacks and autonomous defense mature

The Event—Major Themes & Vendor Moves: CrowdStrike held Fal.Con 2026 from September 1 to 3 at Mandalay Bay in Las Vegas, with a Day Zero Summit on August 31. The company reported more than 10,000 attendees from 4,000 organizations across 71 countries, and over 150 sponsors on the expo floor.

The message across the three days was consistent. CrowdStrike leaned hard into AI, setting out to “secure the AI revolution,” but it did so as a security company extending its remit rather than as a reinvention, keeping “we stop breaches” front and center throughout.

The Frontier-AI Push

A key announcement was the Cyber Superintelligence Lab, led by Bartley Richardson, formerly of NVIDIA, and aimed at frontier AI research for cyber defense rather than general intelligence, trained on telemetry from the Falcon platform. Alongside it, CrowdStrike introduced SafeMind, an agentic system built with NVIDIA, and two purpose-built models: Red Tempest for offensive security and Blue Solano for defense, the latter of which is built on NVIDIA’s Nemotron.

CrowdStrike said the models are trained on its own breach data and framed the pairing as continuous, machine-speed red-and-blue teaming. It is holding them back from broad release on guardrail grounds, gating access through a trusted-access program it called Project QuiltWorks, while SafeMind capabilities ship natively inside Falcon. The cost and detection figures it cited for the models were drawn from its own evaluations.

Securing AI and Agents

The week’s headline announcement was Falcon Guardian, CrowdStrike’s offering for discovering and securing AI and AI agents, and the reveal that the company built its keynotes around. Guardian is generally available and builds on the Pangea acquisition by extending the platform’s telemetry model to agents via what CrowdStrike calls an Agent Graph. Its stated capabilities include agent discovery, prompt visibility and control, posture management, and malicious prompt detection, with roadmap items for skills, model, and MCP server access controls, as well as automated red teaming.

CrowdStrike also introduced an AI Gateway, delivered as SaaS first, with general availability targeted for the fourth quarter, and said Falcon Complete support for AI Detection and Response would follow.

Identity for the Agent Era

CrowdStrike put identity at the center of agent security, drawing on its acquisitions of SGNL and Seraphic. It presented Seraphic as an enterprise browser, Shield for SaaS security posture management, and SGNL-based zero-standing-privileges and just-in-time access. It also previewed an agentic identity provider for managing agent access, describing it as forthcoming rather than shipping, and framed the work as augmenting existing identity providers rather than replacing them.

The Agentic SOC and Platform

CrowdStrike detailed the next stage of its Agentic SOC, built on its next-generation SIEM, with agents that automate detection, triage, and investigation while keeping human oversight, alongside federated search and behavioral detection. It cited a SIEM run rate it has reported at more than $695 million, along with in-session figures for data processed and triage accuracy in beta, with broader availability targeted for October.

A separate executive session on exposure management and cloud framed continuous, AI-driven visibility across attack surfaces, and named exposure management as a priority displacement play against incumbents, including Tenable, Qualys, and others.

The Endpoint, Re-Architected

Alex Ionescu, the company’s Chief Technology Innovation Officer, laid out a redesign of the endpoint sensor that depends less on kernel-level code and aligns to Microsoft’s Windows Endpoint Security Platform and the MVI 3.0 program, the framework Microsoft began building after the July 2024 outage.

CrowdStrike also described on-device AI inference, including a small language model running locally through the endpoint’s NPU. The on-device model is shipping in sensor version 8.10, while the broader modularity work was presented as directional and in private preview.

Ecosystem, Partners, and Services

NVIDIA was named the 2026 Global Partner of the Year, and the SafeMind models were presented as jointly built. Jensen Huang joined George Kurtz on stage for a segment marked by friendly banter and a clear alignment on where AI and cybersecurity are heading, and Kurtz also brought Intel chief executive Lip-Bu Tan on stage, underscoring the strength of that relationship and CrowdStrike’s work with Intel on hardware-level protections.

CrowdStrike also announced deeper integration with OpenAI, whose models are being folded into the platform alongside joint cyber evaluations, and said the Falcon platform is now available on the Anthropic Claude Marketplace.

The company outlined sovereign-cloud expansion across Germany, Saudi Arabia, India, the United Kingdom, and the United Arab Emirates. Regarding services, it reported a rise in incident-response case volume and said Falcon Complete support for AIDR would reach general availability by the end of October.

CrowdStrike Bets on Its Own Models to Secure the AI Revolution

Analyst Take: CrowdStrike came into Fal.Con with the wind at its back. Frontier models are now doing autonomous offensive work, open-weight models are catching up cheaply, and everyone is under pressure to adopt AI faster than they can secure it. Its answer was to go all in on securing the AI revolution, backed by its own models, a research lab, a wave of new products, and NVIDIA, without letting go of “we stop breaches.” The threat is real enough that the ambition is fair. What we keep coming back to is whether these many fronts cohere, and whether a discipline built at the endpoint stretches to a problem that is now about autonomy, authorization, and intent.

One aside worth calling out: the company is to be commended for consistently referring to “adversaries” rather than the more popular “hackers”. It’s a subtle point, but it conveys a more nuanced understanding of the overall cybersecurity landscape.

Specialized Models Are a Defensible Bet

CrowdStrike is not alone in building its own models. Cisco, Palo Alto, and others have moved in the same way, with some open-weight and tunable, others proprietary and security-specific. What stands out in CrowdStrike’s version is how vertically integrated it is: frontier-class, built with NVIDIA on Nemotron, and trained on years of its own breach telemetry, a genuine data advantage. The shared bet is that models purpose-built for security, by a security vendor, will beat general-purpose models from the labs, and CrowdStrike’s data advantage makes its version credible.

The piece we find most promising is the digital twin, the “enterprise clone” that the company described for modeling a customer’s environment. Getting proper context into an AI system is usually the hard and expensive part of making its reasoning reliable, and a digital twin is a genuinely efficient way to build that context. If it works as described, it could be one of the more consequential ideas of the week.

The Harder Half Is the Business Layer

The technical footprint of AI is native ground for CrowdStrike. Endpoints, telemetry, identities, and now agents are what it knows, and Guardian and the Agent Graph naturally extend that reach. The harder half of securing the AI revolution sits a level up, in the business abstractions: what an agent is allowed to do on behalf of a process, and why. Authorization lives at the goal level, not the action level, and no runtime layer can reconstruct intent that was never recorded. That is less familiar ground for a company built at the endpoint, and, to its credit, the identity team acknowledged as much, conceding that the industry still lacks the language to explain agentic authorization to customers.

The ecosystem may be CrowdStrike’s way in. The 150-plus vendors on the Fal.Con floor points to a company with real experience building partnerships, and that partnering muscle is probably its strongest route into the business layer it cannot own on its own. We have argued before that authorization is the harder problem in agent governance, and CrowdStrike is closer than most to naming it honestly. Whether it turns that partner strength into real options there is what we will be watching.

Preparing for Attacks Not Quite Here

CrowdStrike deserves real credit going in. By Futurum’s spending-intent data, it is broadly deployed and still growing, and it carries a strong reputation, so when it names a threat, the market listens. That standing matters, because the whole field, CrowdStrike included, is preparing for AI-enabled attacks that have not fully arrived. The Hugging Face incident, the first agentic ransomware case, and a handful of others have given customers a glimpse of what they want to defend against: goal-directed systems that find their own path to an objective.

What no one yet knows is whether the attacks will arrive in that shape. So far, the vivid cases have been as much about models misbehaving under test as adversaries wielding them, and the sharper risk may prove to sit at the business layer we flagged earlier, an agent doing real damage through actions it was, on paper, allowed to take. CrowdStrike is as well placed as anyone to lead this preparation. The question worth holding open is whether the industry, this vendor included, is aimed at the right shape of attack.

The Endpoint Still Matters

For all the frontier-model talk, the most grounded work of the week was at the endpoint. Alex Ionescu laid out a sensor that leans less on kernel-level code and moves toward Microsoft’s Windows Endpoint Security Platform, the out-of-kernel model the industry has been heading to since 2024. Paired with it is on-device AI inference, a small language model running locally on the endpoint’s NPU, and it is already shipping. Set alongside the cloud models, this completes a sensible two-tier design: large models in the cloud for depth, and small models on the device for privacy, latency, and cost.

It is also the least speculative part of the story, which is part of why we like it. The move out of the kernel is partly an industry-wide requirement rather than a pure choice, so it is fair to read it as a necessity handled well. Even so, putting real inference on the endpoint is a concrete step that ties the AI ambition back to the ground CrowdStrike knows best, and it is shipping now rather than sitting on a roadmap.

What to Watch:

  • Does autonomous defense actually show up? The real test for SafeMind and Guardian is whether they produce genuinely autonomous outcomes rather than assisted ones. Watch the next releases for evidence that the models act at machine speed in production, not just on stage.
  • Can CrowdStrike reach the business layer? Securing agents technically is one thing; governing what they may do on behalf of a business process is harder. Its partner ecosystem is the most likely route, and how it builds there will matter.
  • How fast does the endpoint redesign reach general availability? The out-of-kernel sensor and on-device inference are promising, but much of the modularity work is still directional. The pace of GA and how cleanly it aligns with Microsoft’s platform are worth tracking.
  • Will AI attacks arrive in the form everyone is defending against? Much of the field is instrumenting the technical layer against goal-directed intrusions. If the real damage instead comes through authorized business-level actions, today’s defenses may be aimed slightly off-target.

For more information, read the full announcement from CrowdStrike here.


Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

A Loud Floor and a Quiet Gap: Security Summer Camp 2026

So This Is How AIs Attack: Observations from the OpenAI/Hugging Face Incident

The Hard(er) Challenge in Agent Governance Is Authorization

RSAC 2026: The AI Tragedy of the Commons and the Future of Agentic Security

Featured Image: CrowdStrike

Author Information

Fernando Montenegro

Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.

Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.

Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

Related Insights
Snowflake Q2 FY 2027 CoCo and CoWork Expand AI Consumption
September 8, 2026

Snowflake Q2 FY 2027: CoCo and CoWork Expand AI Consumption

Futurum Research analyzes Snowflake’s Q2 FY 2027 earnings, focusing on AI-led consumption, CoCo adoption, CoWork growth, and raised FY 2027 guidance....
Entelgy Brasil Bets on Febraban Tech to Own LatAm's AI Banking Moment
September 8, 2026

Entelgy Brasil Bets on Febraban Tech to Own LatAm’s AI Banking Moment

Entelgy Brasil's full-team commitment to Febraban Tech 2026 signals a deliberate channel-ecosystem strategy timed to capture AI consulting growth in Latin American banking, where 86.7% of partners identify AI as...
PyTorch Foundation Deepens Chinese AI Ecosystem Ties
September 8, 2026

PyTorch Foundation Deepens Chinese AI Ecosystem Ties

The PyTorch Foundation welcomed Alibaba Cloud, Cambricon, and Ant Group as Platinum and Gold members at PyTorch Conference China 2026, strengthening its position in the world's second-largest AI market with...
OPSWAT at GISEC 2026: Can You Secure What You Can't Detect?
September 7, 2026

OPSWAT at GISEC 2026: Can You Secure What You Can’t Detect?

OPSWAT debuted its AI Content Inspector at GISEC Global 2026, introducing a new defense layer against semantic fraud and AI-generated content that bypasses traditional malware scans in enterprise environments....
HGC and Macroview Bet on AI SecOps Education to Win Enterprise Trust
September 7, 2026

HGC and Macroview Bet on AI SecOps Education to Win Enterprise Trust

HGC and Macroview Telecom co-launch an AI ASOC Workshop Series in October-November 2026, positioning themselves as trusted advisors helping enterprises modernize network and security operations amid critical SOC capacity gaps....
GPT-6 Astra Sharpens Cross-File Bug Detection at a 2.5× Price
September 5, 2026

GPT-6 Astra Sharpens Cross-File Bug Detection at a 2.5× Price

CodeRabbit's evaluation reveals GPT-6 Astra catches 20% more bugs than GPT-5.6 Sol on cross-file reviews, demonstrating superior multi-system reasoning despite premium pricing at $10/M input tokens....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.