CrowdStrike Unveils AI-Powered Cybersecurity Arsenal with Falcon Guardian and SafeMind

6 min
CrowdStrike launched a Cyber Superintelligence Lab focused on AI safety and cyberdefence.
It also unveiled SafeMind, pairing 'offensive' and 'defensive' models in a closed loop.
Falcon Guardian aims to secure AI agents at runtime, not just set rules.
The firm is expanding with Google Cloud to protect enterprise AI apps.
The wider shift is clear: vendors now guard 'the behaviour of AI itself'.
CrowdStrike is pushing harder into AI security, and this week it rolled out a cluster of announcements that show just how seriously it takes that fight. The company has unveiled its new Cyber Superintelligence Lab, a research unit focused on cyberdefence and AI safety, while also introducing SafeMind, a new family of security models, plus Falcon Guardian, an AI Detection and Response product built to monitor and enforce security where AI agents actually run. On top of that, it is widening its work with Google Cloud to support companies building and operating enterprise AI.
At the centre of the move is the Cyber Superintelligence Lab, led by Dr Bartley Richardson, CrowdStrike’s chief AI and autonomous systems officer. The lab pulls together AI researchers, offensive security teams and incident responders under one roof, all with a shared job: building the next wave of defence tools for what the company calls the “agentic era”. In plain terms, that means AI systems that can make decisions and take actions with less human input. It sounds a bit sci-fi, but in cybersecurity it is already becoming everyday business.
The lab is built on the data and security telemetry flowing through the CrowdStrike Falcon platform. According to the company, Falcon ingests signals from endpoints, identity systems, cloud workloads, data stores and its next-generation SIEM architecture, generating trillions of events each day. Add to that 15 years of threat intelligence and incident response work, and CrowdStrike is making the case that its real edge is not just scale, but context. I reckon that matters more than flashy AI slogans, because in security, volume without verified outcomes can be a bit of a faff.
George Kurtz, CrowdStrike’s founder and chief executive, said in a statement that “security is how AI scales”, adding that the new lab concentrates PhDs, AI researchers and threat hunters “who stop real attacks every day on the Falcon platform”. Dr Richardson, for his part, said the main test for AI in security is simple: whether it can stop breaches. He argued that defending against AI-powered attackers will require intelligence that learns continuously and works at machine speed.
That said, CrowdStrike did not stop at research branding. It also introduced SafeMind, which it describes as a purpose-built agentic system for defenders. Rather than acting as a single frontier AI model, SafeMind brings together an offensive model that looks for attack paths, a defensive model that works to shut them down, and the harnesses that keep both operating in one closed loop. The idea is to make each side sharper over time by pitting them against one another continuously.
SafeMind is being trained on Falcon sensor telemetry, CrowdStrike’s threat intelligence, MDR event annotations and incident response fieldwork collected over fifteen years. The models are being built using NVIDIA Nemotron open models in collaboration with NVIDIA, while CoreWeave’s AI Cloud is being used for training and inference. Jensen Huang, NVIDIA’s founder and chief executive, said cybersecurity will become one of the most compute-intensive uses of AI, and argued that SafeMind combines open models with trusted cyber data, evaluation frameworks and safeguards to create a machine-speed defence stack. CoreWeave chief executive Michael Intrator also said the real test for AI is what it can do “in production, at scale, when the stakes are highest”.
Dr Richardson said SafeMind marks “the start of a new chapter for cyberdefense”, arguing that the combination of models and harnesses allows defenders to act at machine speed. CrowdStrike also said trusted access to standalone models and harnesses will be available through its Project QuiltWorks programme. On the flip side, plenty of AI security claims still need real-world proof, and that is usually where the rubber meets the road. Still, tying model training to live cyber telemetry and responder-labelled outcomes is, at least on paper, spot on.
Then there is Falcon Guardian, another fresh product from CrowdStrike, aimed at AI Detection and Response. It is designed to provide visibility and runtime enforcement from the endpoint, where AI agents execute, and then across the wider enterprise. The pitch here is that governance and posture management are not enough once an AI agent is already in motion. If an agent is accessing sensitive data, triggering workflows or behaving in ways that look just like a legitimate user, runtime security becomes the key control point.
CrowdStrike says Guardian covers the full AI estate, including data, models, prompts, agents, identities, infrastructure and interactions. Protection stretches from the endpoint out to cloud, SaaS and browser environments. Kurtz said AI has not changed the nature of attacks so much as the speed of them, and argued that Falcon Guardian turns policy into actual protection before damage is done. And believe it or not, that endpoint-first argument feels familiar; many startup founders across MENA who speak with the Arageek crowd often say the hard bit is not setting rules, it is making them stick once tools are live in the wild.
The company is also broadening its partnership with Google Cloud. CrowdStrike said Falcon Guardian is being expanded through Google Agent Gateway, which should bring AI runtime protection to enterprise AI applications built on Google Cloud. The integration is meant to help organisations detect and block risks such as prompt injection, sensitive data leakage and malicious AI activity, while improving visibility across AI agents and apps.
Alongside that, CrowdStrike is extending the Falcon platform to Gemini Enterprise through Falcon MCP, Charlotte AI and Falcon Shield. The goal is to bring CrowdStrike’s intelligence into workflows powered by Gemini models, support AI-native security operations and strengthen AI governance through Google Cloud’s Agent Registry. CrowdStrike is also building the Falcon platform on regional Google Cloud infrastructure, which could help customers that want to align with hyperscaler preferences or meet operational requirements in specific locations.
Daniel Bernard, CrowdStrike’s chief business officer, said companies should not have to choose between moving faster on AI and reducing risk. Brian Goldstein, vice president for Strategic AI and ISV at Google Cloud, said enterprise AI is becoming a new operating layer for businesses, making security a foundational requirement for every application and agent. That framing feels definately right for large organisations now moving from AI experiments into actual production systems.
For startup watchers, especially those in MENA keeping one eye on global infrastructure trends, the bigger story may be less about one product launch and more about where the market is heading. Security vendors are no longer just protecting servers, laptops and cloud accounts. They are racing to secure the behaviour of AI itself, from models and prompts to the agents acting on behalf of users. I’ve seen founders get chuffed to bits about new AI capability, only to pause when the talk turns to control, visibility and liability… well, I mean, that pause is becoming impossible to ignore. CrowdStrike clearly wants to be the platform sitting in the middle of that shift.
🚀 Got exciting news to share?
If you're a startup founder, VC, or PR agency with big updates—funding rounds, product launches 📢, or company milestones 🎉 — AraGeek English wants to hear from you!
✉️ Send Us Your Story 👇
Ai Everything








