Skip to main content
Threat Intelligence · September 3, 2026

Fal.Con 2026: Securing the AI Revolution

CrowdStrike used the Fal.Con 2026 mainstage to argue that AI has rewritten both sides of the attack equation. Here is what was announced, and the part most teams will underestimate: the platform now wants telemetry from everything, not just the endpoint.

Vijilan Security· 4 min
Fal.Con 2026: Securing the AI Revolution

The threat model has changed

Founder and CEO George Kurtz opened with a claim that the traditional threat model no longer holds. As frontier AI capabilities spread past nation-states and into the hands of ordinary adversaries, attacks move at machine speed, which leaves very little room for human-paced response. AI is, in Kurtz's framing, a completely new attack surface that legacy security tools were never built to handle. And the AI agents enterprises are racing to adopt are themselves a surface that has to be defended.

That second point deserves more attention than it usually gets. Most organizations are still thinking about AI as something they secure with, not something they have to secure. Every agent that can call an API, sign in to a SaaS app, write code, send mail or read a document is a new identity with new reach.

Agentic defense: fighting AI with AI

The headline launch was Falcon IQ, CrowdStrike's agentic AI security platform, built with NVIDIA and powered by Charlotte AI AgentWorks. It ships with a library of prebuilt agents that automate assessment, prioritization and response, and it lets partners build custom agents on the platform.

Alongside it:

  • Falcon Guardian is now generally available.
  • SafeMind is an agentic security system built with NVIDIA, and Blue Solano and Red Tempest are its two models rather than three separate products. Red Tempest is the offensive model, built to emulate AI adversaries and find the exploit path. Blue Solano is the defensive model, built to close it. Harnesses run the pair in a closed loop, and can drive third-party frontier and open-source models too.

Platform and ecosystem

CrowdStrike also broadened where and how Falcon runs:

  • The Falcon platform is now available on Google Cloud.
  • Falcon Next-Gen SIEM now ingests real-time telemetry from across the stack, including third-party tools, positioning it as the aggregation layer for AI-era security operations.
  • Project QuiltWorks is a separate thing: the program through which trusted customers get standalone access to the SafeMind models and harnesses, so they can run them alongside external models while keeping cost under control.
  • Deepened alliances with NVIDIA, Intel and OpenAI, with NVIDIA founder and CEO Jensen Huang joining Kurtz on stage.

More mainstage sessions follow this week: President Michael Sentonas and Counter Adversary Operations lead Adam Meyers, with CrowdStrike's technology leaders closing out the event.

What this means if you run on Falcon

Three practical consequences, in the order they will hit you.

Your AI environment is now in scope, whether or not you planned for it. Models, prompts, agents and the pipelines feeding them are an attack surface that EDR and XDR structurally cannot evaluate: prompt injection, jailbreaks, agent behaviour drift and shadow AI do not look like malware. This is the domain Falcon AIDR covers, and it is the one most teams have no baseline for. Vijilan onboards and operates it as Managed AIDR, and we are running 60-day AI risk assessments that inventory your AI environment and hand back a prioritized picture of where the exposure actually is.

A SIEM that ingests everything is only as good as what you send it. The Next-Gen SIEM announcement is the one we would underline hardest, because it quietly moves the bottleneck. Once the platform will take telemetry from your whole stack, the limiting factor becomes pipeline engineering: getting third-party sources parsed to the CrowdStrike Parsing Standard so they are queryable and correlatable, and shaped at the edge so ingest cost stays predictable. That is the half of the platform Vijilan engineers, on Falcon Onum or Cribl Stream, depending on what you already run.

Machine speed still needs someone accountable. Automation is what removes latency. It is not what removes responsibility. Praxis AI™ is our SOC platform: it correlates, triages and contains in seconds across every connected source, and a Vijilan analyst owns the decision at every layer, detection through response. Machine speed where speed wins, human judgement where it matters, and never autonomous-only.

And on the obvious question about overlap: Falcon Complete and Adversary OverWatch are CrowdStrike's own managed services, and their analysts correlate across endpoint, identity, cloud, SaaS and third-party telemetry on the Falcon platform. Most Falcon customers buy neither, and for them NextDefend™ Operate and ThreatHunt™ are the 24/7 coverage and the proactive hunting nobody else is doing. Where a customer does run Complete or OverWatch, we work alongside that team on what sits outside their engagement scope. We extend it rather than duplicate it.

If you are at Fal.Con this week, come find us. If you are not, the same conversation works remotely.


Correction, 20 September 2026. This piece was written live from the Fal.Con mainstage and published the same day, before CrowdStrike's written materials were available. Two things in the original were wrong and have been fixed above.

SafeMind was listed alongside Blue Solano and Red Tempest as though the three were peer products. They are not: SafeMind is the system, Red Tempest and Blue Solano are its offensive and defensive models, and harnesses run them as a closed loop.

Project QuiltWorks was described as another name for Falcon Next-Gen SIEM. It is not related to it. QuiltWorks is the program for standalone access to the SafeMind models and harnesses.

We have left the rest of the article as published rather than quietly rewriting it. Source: CrowdStrike, "CrowdStrike Launches Frontier Models for Cybersecurity, Created with NVIDIA."

One figure we have deliberately not repeated: the launch materials claim a 29% higher detection rate, 6x faster remediation and 99% lower cost against frontier and open-source baselines. No methodology, test scope or timeframe is published alongside those numbers, so we are not passing them on as fact.

Found this useful? Send it to someone who needs it.

Threat notes, once a week

What our SOC actually saw this week: new attack patterns, the detections we shipped against them, and what it means if you run an MSP. Written by the analysts, not by marketing.

One email a week. One click to stop, and we do not sell your address to anyone.

Talk to a security expert

See what 24/7 looks like when the SOC actually acts.

Book a 20-minute platform walkthrough: no slide deck, just the console.

Book a walkthrough →