ChannelLife US - Industry insider news for technology resellers
United States
CrowdStrike launches SafeMind agentic cybersecurity system

CrowdStrike launches SafeMind agentic cybersecurity system

Fri, 4th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

CrowdStrike has launched SafeMind with NVIDIA, describing it as a new agentic cybersecurity system.

CrowdStrike Chief Executive Officer and Founder George Kurtz and NVIDIA Founder and Chief Executive Officer Jensen Huang introduced the system to an audience of security professionals in Las Vegas.

Developed by the CrowdStrike Cyber Superintelligence Lab, SafeMind is designed to combine offensive and defensive artificial intelligence in a continuous loop. It uses CrowdStrike's own models and agentic harnesses alongside defensive models built on NVIDIA Nemotron.

The launch comes as cyber attacks become faster and more automated. CrowdStrike said AI-enabled attacks rose 89% over the past year, while the fastest eCrime breakout time fell to 27 seconds.

Huang put that shift plainly. "We're at an inflection point in cybersecurity," he said. "Attacks are now automated. Defence has to be, too."

At the same event, CrowdStrike also announced Falcon IQ, which applies agentic workload automation to Project QuiltWorks, and expanded its Guardian AI safety offering. Together, the additions place automation at the centre of the company's broader product strategy.

How SafeMind works

CrowdStrike said it built SafeMind's defensive model from NVIDIA Nemotron open models, then post-trained them with its own threat data and cyber expertise. The models are linked to proprietary cybersecurity harnesses designed to operate as an agentic stack within the Falcon platform.

According to the companies, that design lets the system repeatedly pit offensive and defensive AI against each other so each side adapts to the other. The goal is to harden a customer environment until attacks fail.

Kurtz described the gap he believes the system is meant to close. "The real gap that I saw was that the attackers had frontier AI, and the defenders didn't," he said. "And that changes now."

SafeMind can run as a complete system, but its underlying models can also be used separately. Security teams can also combine their own models with CrowdStrike's harnesses, giving customers another deployment option.

Huang described the architecture this way: "Your decade and a half of security data that we can train on - we can take a frontier model and make it essentially a super AGI that is incredibly good at cybersecurity."

CrowdStrike said NVIDIA Nemotron 3 Ultra orchestrates the defensive agent harness, while a fine-tuned Nemotron 3 Super runs SafeMind's rule-generation sub-agent.

Internal evaluations showed that Blue Solano, CrowdStrike's model based on Nemotron 3 Super, achieved higher accuracy than leading frontier models at 99% lower cost after post-training on CrowdStrike data, according to the company. It did not provide comparative figures in the announcement.

Testing loop

NVIDIA also described testing SafeMind models and harnesses in a simulated environment based on its own network. According to NVIDIA, the setup created a high-fidelity cyber agent environment that mirrors its infrastructure and threat conditions.

Within that environment, an offensive red-team agent is tasked with finding exploits while a defensive blue-team agent attempts to detect and stop them. Findings from that cycle are then turned into detections intended to block attacks.

The red-agent harness runs Recon, Assault and Compromise sub-agents, while the blue-agent harness monitors Falcon sensor data, generates detection candidates, validates them and promotes them. CrowdStrike said the digital twin was built jointly with NVIDIA and validated against NVIDIA's real threat landscape.

Huang said the model could extend beyond cybersecurity. "The basic framework of SafeMind - an adversarial model acting on a digital twin of the environment, with a defender model in a continuous cat-and-mouse loop, eventually learning how to secure itself - this basic framework applies to robotics, edge computing, enterprise computing and just about everything," he said.

Broader push

Falcon IQ is another part of the companies' collaboration. CrowdStrike said it uses more than 50 agents working together to automate tasks in assessment, prioritisation and remediation.

NVIDIA Nemotron models sit inside the agentic engine used by Charlotte AI AgentWorks, CrowdStrike's no-code agent development platform, where Falcon IQ operates. According to CrowdStrike, partners can use Falcon IQ to generate tailored findings, recommendations and executive outputs for customers, while Falcon users can build their own automated security workflows through AgentWorks.

Kurtz cast the launch as a break from simpler AI tools. "Together with NVIDIA, we built cybersecurity's first complete agentic system for cybersecurity, including the first frontier models and harness purpose-built for defenders," he said. "This isn't a copilot baked into someone else's intelligence. It's not a chatbot with a security skin. It is a frontier-class model built and trained by CrowdStrike on our data in partnership with NVIDIA."

Huang also argued that open models matter in a field where organisations want tighter control over how systems are trained and inspected. "There are many applications in the world where you must have the ability to fine-tune, to post-train - to create an AI that is super good at a particular domain," he said. "Nemotron was created for precisely that. Completely free. Incredibly fast. You have the ability to have an asymmetric advantage against whatever comes your way."

CrowdStrike says its platform processes trillions of daily security events across thousands of customer organisations, and Kurtz said that breadth of data remains central to its market position. "The crowd in CrowdStrike," he said, "is the asymmetry that puts the defenders in a unique position to defeat the adversary."