Inside CrowdStrike’s Move To Secure Enterprise Agentic AI
Enterprise software is rapidly moving toward autonomous agents. Gartner expects task-specific agents to appear in 40% of enterprise applications by the end of 2026, up from less than 5% in 2025. Agents can use credentials, invoke tools, and alter business systems, yet many companies still lack a reliable way to inventory or govern them.
That gap creates a different security problem than the one enterprises faced with conventional applications. Coding agents, workflow agents, and autonomous copilots can operate with real credentials, invoke tools, modify systems, and access sensitive data. The question is increasingly about which agents are operating, what authority they have, and whether their actions can be observed and stopped.
Attackers have already adapted. According to CrowdStrike ’s 2026 Global Threat Report, AI-enabled attacks rose 89% year over year, and the average breakout time, the window between initial access and lateral movement, fell to 29 minutes. The company’s 2026 Threat Hunting Report found adversaries exploiting vulnerabilities within hours. Security operations built around human analysts working tickets in sequence struggle to keep pace.
That tension was center stage at CrowdStrike’s recent Fal.Con 2026 customer event, where nearly every major announcement focused on securing the AI agents enterprises deploy and on applying AI to defend at machine speed. Taken together, the releases are CrowdStrike’s clearest statement yet of how it intends to compete as security spending follows AI adoption.
CrowdStrike president Mike Sentonas stated it plainly: “The enterprise isn’t simply using AI anymore; AI is part of the enterprise. Once AI becomes part of the enterprise, it becomes part of what we have to defend. But it’s also now changing how we defend.”
CrowdStrike’s Four-Part AI Security Strategy
CrowdStrike’s AI announcements comprise a four-layer strategy. Falcon Guardian protects agents at runtime, Agentic IdP gives each agent its own identity, the new SafeMind models provide security-specific AI, and an expanded agentic SOC acts on what the platform detects.
Each layer builds on the previous one. Together, they cover the full lifecycle of an AI agent on a single platform, from discovery and identification through authorization and ongoing monitoring.
Runtime Protection with Falcon Guardian
Falcon Guardian is the centerpiece of the announcements and of CrowdStrike’s new AI detection and response product. It uses the existing Falcon sensor on Windows and macOS to perform four functions:
- Discover both known and shadow AI agents
- Trace each agent’s actions from the user’s prompt through tool calls to downstream system activity
- Block unauthorized agents
- Contain malicious agent behavior at runtime
CrowdStrike considers its endpoint footprint its main advantage. Agents run on endpoints, and CrowdStrike says its sensor is already deployed on hundreds of millions of devices.
CrowdStrike also expanded its partnership with OpenAI, and Falcon Guardian will provide runtime controls for Codex agents. Two additional components are still to come. One is an AI gateway for model traffic, including MCP. The other is managed Guardian services delivered through Falcon Complete.
Agent Identity with Agentic IdP
AI agents often use a person’s credentials or run under service accounts. That makes it hard to tell which agent took an action and who authorized it. Traditional identity providers make the problem worse by forcing organizations to represent agents as API keys, service accounts, or workload identities. All of these are static constructs designed for other purposes.
Mike Sentonas told me that every AI agent must access something. “They call APIs, they use credentials, they touch sensitive data, they take action across your environment. Every agent has an identity, and in most cases, it’s an overprivileged identity. And in too many cases, it inherits the human permissions, and you are all deploying them faster than you can govern them—that’s just how they work.”
To address this, CrowdStrike’s Agentic IdP gives each agent its own identity and limits its access to the task it is performing. It registers every agent Guardian discovers and issues a cryptographically verifiable identity. It grants access via short-lived, narrowly scoped tokens and ties every agent action to the human or workload the agent represents. Agentic IdP builds on the Continuous Identity capabilities CrowdStrike gained when it acquired SGNL earlier this year.
Security-Specific Models with SafeMind
The third layer comprises the AI models themselves. CrowdStrike launched a Cyber Superintelligence Lab, led by chief AI and autonomous systems officer Bartley Richardson, and introduced the lab’s first output, SafeMind.
CrowdStrike built SafeMind with NVIDIA using the Nemotron open models. It is trained on Falcon telemetry, threat intelligence, and fifteen years of incident response data. SafeMind pairs two models that work together in a closed loop, coordinated by a shared set of harnesses.
Notably, Nvidia CEO Jensen Huang participated in a fireside chat with CrowdStrike CEO George Kurtz at the Fal.Con 26 keynote. This was Huang’s only appearance at a cybersecurity event this year.
The fourth layer extends CrowdStrike’s agentic security operations center. Charlotte AI now deploys domain-specific agents that run in parallel across endpoint, identity, SaaS, cloud, and network. These agents share a persistent context layer, so findings from one agent inform the others. Customers can set the autonomy level for each workflow, from requiring human approval to full automation. Bidirectional MCP support also enables third-party agents to plug into Falcon.
AI Driving Growth for CrowdStrike
AI is beginning to generate new revenue for CrowdStrike, in addition to demand for its established endpoint products. The clearest example is AI Detection and Response, a separately priced module that sits alongside EDR. During CrowdStrike’s most recent earnings call, management said AIDR’s annual recurring revenue nearly tripled sequentially in the latest quarter, after growing more than 250% the previous quarter. CrowdStrike believes AIDR could eventually outgrow EDR.
AI is also attracting new customers and larger deals. CrowdStrike cited three eight-figure wins, including an AIDR deployment at a major global bank, an agreement with a frontier AI lab, and a deal to protect a technology company’s AI cloud infrastructure and research labs. New-logo net new ARR reached a record, and total net new ARR rose 51% year over year to $333 million.
The bigger opportunity may be the security spending that each AI deployment entails. A production agent may need endpoint controls, its own identity, access to cloud workloads and sensitive data, and continuous monitoring. Existing Falcon modules for identity, data protection, cloud security, SIEM, and exposure management cover much of that, which helps explain why 51% of customers now use six or more modules, 35% use seven or more, and 26% use eight or more.
Adjacent businesses are also growing, with cloud-security ARR above $905 million and Next-Gen SIEM approaching $700 million. Non-human identity is an emerging opportunity as well, since every production agent requires credentials and controlled access.
Falcon Flex turns that demand into broader adoption by letting customers draw on a committed spending pool as they add Falcon products. Flex-related ARR reached $2.29 billion, up 101% year over year. Customers who moved to Flex from conventional subscriptions increased ARR by more than 40% on average.
AI is also widening Falcon’s audience. Because AIDR tracks AI applications, agent activity, and token consumption, it may appeal to CIOs overseeing AI inventories, governance, and costs, as well as to security leaders. AI-readiness assessments and incident response lifted professional-services revenue to a record $71 million, and business with global systems integrators grew nearly 50% in the quarter.
Taken together, each agent or AI workload can drive demand across several CrowdStrike businesses and add AIDR revenue. That multiplier effect helps explain why the company raised its fiscal 2027 net-new-ARR growth outlook from 22.5% to 34%. Investors should keep management’s long-term expectations separate from demonstrated results, though the latest quarter offers early evidence that AI is expanding CrowdStrike’s addressable market.
Every major security platform vendor now targets AI agent security, and the category is crowded well before it is mature.
Palo Alto Networks remains CrowdStrike’s most direct rival. It has built an AI security portfolio around Prisma AIRS, strengthened by its 2025 acquisition of Protect AI. Its move to acquire CyberArk gives it a deep privileged-access franchise to extend to machine and agent identities.
Microsoft holds a distribution advantage no pure-play vendor can match, with Entra Agent ID and Security Copilot embedded in the productivity and cloud stack, where many enterprise agents originate. Identity specialists such as Okta are building agent authentication directly into the identity layer, while SentinelOne and Zscaler pursue agent visibility from the endpoint and the network, respectively.
The competitive boundary also extends beyond cybersecurity vendors. Microsoft, Google, and AWS are embedding identity, policy, agent registries, and runtime controls into the platforms used to build and run agents, creating another potential control point between CrowdStrike and the agent.
CrowdStrike’s defensible advantages are its endpoint footprint and its data. Endpoint-level runtime enforcement gives CrowdStrike a control point that network- and identity-centric vendors must address with different architectures. Falcon’s ability to correlate endpoint telemetry with identity and cloud data provides a useful foundation for cross-domain investigations.
The endpoint, identity, and SOC markets are converging on a single question of who governs autonomous software within the enterprise. CrowdStrike is betting that the vendor controlling where agents run and how they authenticate will also be positioned to sell the analytics and response tools built on top of those controls.
Its new commercial arrangements with Anthropic and Snowflake reinforce that strategy by allowing customers to apply existing commitments to Falcon, while its expanded Google Cloud relationship extends Falcon’s reach deeper into the infrastructure and tooling used to build enterprise AI.
For CISOs, the immediate issue is governance. As agents gain the ability to investigate, decide, and act on both sides of the security equation, CISOs must determine how much authority to grant and how to audit their actions.
The vendors that make governance simple will win the next platform cycle, and CrowdStrike used Fal.Con to argue that the answer begins at the endpoint.