CrowdStrike has introduced Falcon Guardian, an AI detection and response (AIDR) product for runtime security of enterprise AI agents.
Guardian covers data, models, prompts, agents, identities, infrastructure and interactions. It extends across endpoints, cloud environments, software-as-a-service (SaaS) applications and browsers.
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
CrowdStrike CEO and founder George Kurtz said: “CrowdStrike pioneered endpoint detection and response (EDR) by making the endpoint the control point for stopping attacks. AI demands the same approach.
“AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion. Falcon Guardian turns policy into protection, stopping threats where AI agents execute and before they can cause harm.”
CrowdStrike said endpoints are where AI agents reason, plan, execute and access sensitive data.
The Falcon sensor of the new AIDR solution discovers known and shadow AI agents on Windows and macOS. It creates a live inventory of running and dormant agents, identifies who deployed them and records their security status.
Agent Runtime Visibility, another feature of Falcon Guardian, links agent behaviour to endpoint telemetry. It traces user prompts, identities, tool calls and skill use to downstream system actions, creating a record of the agent execution graph.
Falcon Guardian also comes with the Agent Access Controls feature to define which AI agents can run on managed endpoints and block unauthorised agents. The capability is intended to turn governance policy into runtime controls.
The Runtime Detection and Response tool of the solution detects attacks on agents and malicious agent behaviour. The feature reconstructs execution chains, determines blast radius in real time and contains AI threats before they spread.
AI Gateway will provide a central control point for enterprise AI traffic across supported models and services. It will apply Falcon security context to AI communications, including MCP, to enforce visibility and policy.
Falcon Complete for Guardian will deliver 24/7 expert-led detection, investigation and response for AI agents. CrowdStrike plans for its analysts to assess intent, distinguish legitimate AI behaviour from malicious activity, and stop threats before impact.
Falcon Adversary OverWatch for Guardian extends managed cross-domain threat hunting to AI agent activity. The service is informed by frontline adversary tradecraft.
Guardian also feeds AI agent data into Falcon Next-Gen security information and event management (SIEM) as first-party data. The data is available for correlation across identity, cloud and SaaS, with retention included.
In a separate announcement, CrowdStrike introduced CrowdStrike SafeMind, a family of security models and harnesses from the CrowdStrike Cyber Superintelligence Lab.
The SafeMind agentic system will operate natively in the Falcon platform. Trusted access for standalone models and harnesses will form part of the Project QuiltWorks programme.
It comprises an offensive model that identifies an attack path, a defensive model that closes it, and harnesses that operate both in the same loop.
SafeMind training data includes Falcon sensor telemetry, CrowdStrike threat intelligence, Falcon Complete MDR event annotations and 15 years of incident response fieldwork.
CrowdStrike also announced new Falcon platform capabilities for Google Cloud’s enterprise AI ecosystem, intended to support organisations building, deploying and operating enterprise AI on Google Cloud.
The company is expanding Guardian through Google Agent Gateway, bringing runtime protection to enterprise AI applications built on Google Cloud. The integration is intended to identify and stop prompt injection, sensitive data leakage and malicious AI activity.
It will also provide continuous visibility across AI agents and applications.
CrowdStrike is extending the Falcon platform to Gemini Enterprise through Falcon MCP, Charlotte AI and Falcon Shield. The integrations bring CrowdStrike intelligence into workflows supported by Google Gemini’s models and enable AI-native security operations.
They also strengthen AI governance through Google Cloud’s Agent Registry, the company said.
CrowdStrike is building the Falcon platform on regional Google Cloud infrastructure to help organisations consolidate on CrowdStrike while aligning with hyperscaler preferences and operational requirements.
Last month, CrowdStrike partnered with Cerebras Systems to combine its cybersecurity capabilities with the latter’s AI inference technology. CrowdStrike will use Cerebras’s inference capabilities for its Falcon AI Detection and Response solution, while Cerebras will use the Falcon platform to secure its operations.
