Analyst(s): Fernando Montenegro
Publication Date: September 8, 2026
What Is Covered in This Article:
- CrowdStrike’s Fal.Con 2026 announcements, from SafeMind and the Cyber Superintelligence Lab to Falcon Guardian and the Agentic SOC
- Why its bet on building specialized security models is defensible, and the promise of the digital twin
- The gap between securing agents technically and governing them at the business layer
- What the endpoint re-architecture and on-device AI mean for CrowdStrike’s core
- What to watch as AI-enabled attacks and autonomous defense mature
The Event—Major Themes & Vendor Moves: CrowdStrike held Fal.Con 2026 from September 1 to 3 at Mandalay Bay in Las Vegas, with a Day Zero Summit on August 31. The company reported more than 10,000 attendees from 4,000 organizations across 71 countries, and over 150 sponsors on the expo floor.
The message across the three days was consistent. CrowdStrike leaned hard into AI, setting out to “secure the AI revolution,” but it did so as a security company extending its remit rather than as a reinvention, keeping “we stop breaches” front and center throughout.
The Frontier-AI Push
A key announcement was the Cyber Superintelligence Lab, led by Bartley Richardson, formerly of NVIDIA, and aimed at frontier AI research for cyber defense rather than general intelligence, trained on telemetry from the Falcon platform. Alongside it, CrowdStrike introduced SafeMind, an agentic system built with NVIDIA, and two purpose-built models: Red Tempest for offensive security and Blue Solano for defense, the latter of which is built on NVIDIA’s Nemotron.
CrowdStrike said the models are trained on its own breach data and framed the pairing as continuous, machine-speed red-and-blue teaming. It is holding them back from broad release on guardrail grounds, gating access through a trusted-access program it called Project QuiltWorks, while SafeMind capabilities ship natively inside Falcon. The cost and detection figures it cited for the models were drawn from its own evaluations.
Securing AI and Agents
The week’s headline announcement was Falcon Guardian, CrowdStrike’s offering for discovering and securing AI and AI agents, and the reveal that the company built its keynotes around. Guardian is generally available and builds on the Pangea acquisition by extending the platform’s telemetry model to agents via what CrowdStrike calls an Agent Graph. Its stated capabilities include agent discovery, prompt visibility and control, posture management, and malicious prompt detection, with roadmap items for skills, model, and MCP server access controls, as well as automated red teaming.
CrowdStrike also introduced an AI Gateway, delivered as SaaS first, with general availability targeted for the fourth quarter, and said Falcon Complete support for AI Detection and Response would follow.
Identity for the Agent Era
CrowdStrike put identity at the center of agent security, drawing on its acquisitions of SGNL and Seraphic. It presented Seraphic as an enterprise browser, Shield for SaaS security posture management, and SGNL-based zero-standing-privileges and just-in-time access. It also previewed an agentic identity provider for managing agent access, describing it as forthcoming rather than shipping, and framed the work as augmenting existing identity providers rather than replacing them.
The Agentic SOC and Platform
CrowdStrike detailed the next stage of its Agentic SOC, built on its next-generation SIEM, with agents that automate detection, triage, and investigation while keeping human oversight, alongside federated search and behavioral detection. It cited a SIEM run rate it has reported at more than $695 million, along with in-session figures for data processed and triage accuracy in beta, with broader availability targeted for October.
A separate executive session on exposure management and cloud framed continuous, AI-driven visibility across attack surfaces, and named exposure management as a priority displacement play against incumbents, including Tenable, Qualys, and others.
The Endpoint, Re-Architected
Alex Ionescu, the company’s Chief Technology Innovation Officer, laid out a redesign of the endpoint sensor that depends less on kernel-level code and aligns to Microsoft’s Windows Endpoint Security Platform and the MVI 3.0 program, the framework Microsoft began building after the July 2024 outage.
CrowdStrike also described on-device AI inference, including a small language model running locally through the endpoint’s NPU. The on-device model is shipping in sensor version 8.10, while the broader modularity work was presented as directional and in private preview.
Ecosystem, Partners, and Services
NVIDIA was named the 2026 Global Partner of the Year, and the SafeMind models were presented as jointly built. Jensen Huang joined George Kurtz on stage for a segment marked by friendly banter and a clear alignment on where AI and cybersecurity are heading, and Kurtz also brought Intel chief executive Lip-Bu Tan on stage, underscoring the strength of that relationship and CrowdStrike’s work with Intel on hardware-level protections.
CrowdStrike also announced deeper integration with OpenAI, whose models are being folded into the platform alongside joint cyber evaluations, and said the Falcon platform is now available on the Anthropic Claude Marketplace.
The company outlined sovereign-cloud expansion across Germany, Saudi Arabia, India, the United Kingdom, and the United Arab Emirates. Regarding services, it reported a rise in incident-response case volume and said Falcon Complete support for AIDR would reach general availability by the end of October.
CrowdStrike Bets on Its Own Models to Secure the AI Revolution
Analyst Take: CrowdStrike came into Fal.Con with the wind at its back. Frontier models are now doing autonomous offensive work, open-weight models are catching up cheaply, and everyone is under pressure to adopt AI faster than they can secure it. Its answer was to go all in on securing the AI revolution, backed by its own models, a research lab, a wave of new products, and NVIDIA, without letting go of “we stop breaches.” The threat is real enough that the ambition is fair. What we keep coming back to is whether these many fronts cohere, and whether a discipline built at the endpoint stretches to a problem that is now about autonomy, authorization, and intent.
One aside worth calling out: the company is to be commended for consistently referring to “adversaries” rather than the more popular “hackers”. It’s a subtle point, but it conveys a more nuanced understanding of the overall cybersecurity landscape.
Specialized Models Are a Defensible Bet
CrowdStrike is not alone in building its own models. Cisco, Palo Alto, and others have moved in the same way, with some open-weight and tunable, others proprietary and security-specific. What stands out in CrowdStrike’s version is how vertically integrated it is: frontier-class, built with NVIDIA on Nemotron, and trained on years of its own breach telemetry, a genuine data advantage. The shared bet is that models purpose-built for security, by a security vendor, will beat general-purpose models from the labs, and CrowdStrike’s data advantage makes its version credible.
The piece we find most promising is the digital twin, the “enterprise clone” that the company described for modeling a customer’s environment. Getting proper context into an AI system is usually the hard and expensive part of making its reasoning reliable, and a digital twin is a genuinely efficient way to build that context. If it works as described, it could be one of the more consequential ideas of the week.
The Harder Half Is the Business Layer
The technical footprint of AI is native ground for CrowdStrike. Endpoints, telemetry, identities, and now agents are what it knows, and Guardian and the Agent Graph naturally extend that reach. The harder half of securing the AI revolution sits a level up, in the business abstractions: what an agent is allowed to do on behalf of a process, and why. Authorization lives at the goal level, not the action level, and no runtime layer can reconstruct intent that was never recorded. That is less familiar ground for a company built at the endpoint, and, to its credit, the identity team acknowledged as much, conceding that the industry still lacks the language to explain agentic authorization to customers.
The ecosystem may be CrowdStrike’s way in. The 150-plus vendors on the Fal.Con floor points to a company with real experience building partnerships, and that partnering muscle is probably its strongest route into the business layer it cannot own on its own. We have argued before that authorization is the harder problem in agent governance, and CrowdStrike is closer than most to naming it honestly. Whether it turns that partner strength into real options there is what we will be watching.
Preparing for Attacks Not Quite Here
CrowdStrike deserves real credit going in. By Futurum’s spending-intent data, it is broadly deployed and still growing, and it carries a strong reputation, so when it names a threat, the market listens. That standing matters, because the whole field, CrowdStrike included, is preparing for AI-enabled attacks that have not fully arrived. The Hugging Face incident, the first agentic ransomware case, and a handful of others have given customers a glimpse of what they want to defend against: goal-directed systems that find their own path to an objective.
What no one yet knows is whether the attacks will arrive in that shape. So far, the vivid cases have been as much about models misbehaving under test as adversaries wielding them, and the sharper risk may prove to sit at the business layer we flagged earlier, an agent doing real damage through actions it was, on paper, allowed to take. CrowdStrike is as well placed as anyone to lead this preparation. The question worth holding open is whether the industry, this vendor included, is aimed at the right shape of attack.
The Endpoint Still Matters
For all the frontier-model talk, the most grounded work of the week was at the endpoint. Alex Ionescu laid out a sensor that leans less on kernel-level code and moves toward Microsoft’s Windows Endpoint Security Platform, the out-of-kernel model the industry has been heading to since 2024. Paired with it is on-device AI inference, a small language model running locally on the endpoint’s NPU, and it is already shipping. Set alongside the cloud models, this completes a sensible two-tier design: large models in the cloud for depth, and small models on the device for privacy, latency, and cost.
It is also the least speculative part of the story, which is part of why we like it. The move out of the kernel is partly an industry-wide requirement rather than a pure choice, so it is fair to read it as a necessity handled well. Even so, putting real inference on the endpoint is a concrete step that ties the AI ambition back to the ground CrowdStrike knows best, and it is shipping now rather than sitting on a roadmap.
What to Watch:
- Does autonomous defense actually show up? The real test for SafeMind and Guardian is whether they produce genuinely autonomous outcomes rather than assisted ones. Watch the next releases for evidence that the models act at machine speed in production, not just on stage.
- Can CrowdStrike reach the business layer? Securing agents technically is one thing; governing what they may do on behalf of a business process is harder. Its partner ecosystem is the most likely route, and how it builds there will matter.
- How fast does the endpoint redesign reach general availability? The out-of-kernel sensor and on-device inference are promising, but much of the modularity work is still directional. The pace of GA and how cleanly it aligns with Microsoft’s platform are worth tracking.
- Will AI attacks arrive in the form everyone is defending against? Much of the field is instrumenting the technical layer against goal-directed intrusions. If the real damage instead comes through authorized business-level actions, today’s defenses may be aimed slightly off-target.
For more information, read the full announcement from CrowdStrike here.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
So This Is How AIs Attack: Observations from the OpenAI/Hugging Face Incident
The Hard(er) Challenge in Agent Governance Is Authorization
RSAC 2026: The AI Tragedy of the Commons and the Future of Agentic Security
Featured Image: CrowdStrike
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

