Skip to main content
ThreatHunt and ThreatContain revealed.See the announcements
Threat Intelligence · September 3, 2026

Fal.Con 2026: Securing the AI Revolution

CrowdStrike used the Fal.Con 2026 mainstage to argue that AI has rewritten both sides of the attack equation. Here is what was announced, and the part most teams will underestimate: the platform now wants telemetry from everything, not just the endpoint.

Vijilan Security· 4 min
Fal.Con 2026: Securing the AI Revolution

The threat model has changed

Founder and CEO George Kurtz opened with a claim that the traditional threat model no longer holds. As frontier AI capabilities spread past nation-states and into the hands of ordinary adversaries, attacks move at machine speed, which leaves very little room for human-paced response. AI is, in Kurtz's framing, a completely new attack surface that legacy security tools were never built to handle. And the AI agents enterprises are racing to adopt are themselves a surface that has to be defended.

That second point deserves more attention than it usually gets. Most organizations are still thinking about AI as something they secure with, not something they have to secure. Every agent that can call an API, sign in to a SaaS app, write code, send mail or read a document is a new identity with new reach.

Agentic defense: fighting AI with AI

The headline launch was Falcon IQ, CrowdStrike's agentic AI security platform, built with NVIDIA and powered by Charlotte AI AgentWorks. It ships with a library of prebuilt agents that automate assessment, prioritization and response, and it lets partners build custom agents on the platform.

Alongside it:

  • Falcon Guardian is now generally available.
  • New autonomous defense capabilities, SafeMind, Blue Solano and Red Tempest, extend AI-driven protection across the attack lifecycle.

Platform and ecosystem

CrowdStrike also broadened where and how Falcon runs:

  • The Falcon platform is now available on Google Cloud.
  • Falcon Next-Gen SIEM (Project QuiltWorks) now ingests real-time telemetry from across the stack, including third-party tools, positioning it as the aggregation layer for AI-era security operations.
  • Deepened alliances with NVIDIA, Intel and OpenAI, with NVIDIA founder and CEO Jensen Huang joining Kurtz on stage.

More mainstage sessions follow this week: President Michael Sentonas and Counter Adversary Operations lead Adam Meyers, with CrowdStrike's technology leaders closing out the event.

What this means if you run on Falcon

Three practical consequences, in the order they will hit you.

Your AI environment is now in scope, whether or not you planned for it. Models, prompts, agents and the pipelines feeding them are an attack surface that EDR and XDR structurally cannot evaluate: prompt injection, jailbreaks, agent behaviour drift and shadow AI do not look like malware. This is the domain Falcon AIDR covers, and it is the one most teams have no baseline for. Vijilan onboards and operates it as Managed AIDR, and we are running 60-day AI risk assessments that inventory your AI environment and hand back a prioritized picture of where the exposure actually is.

A SIEM that ingests everything is only as good as what you send it. The Next-Gen SIEM announcement is the one we would underline hardest, because it quietly moves the bottleneck. Once the platform will take telemetry from your whole stack, the limiting factor becomes pipeline engineering: getting third-party sources parsed to the CrowdStrike Parsing Standard so they are queryable and correlatable, and shaped at the edge so ingest cost stays predictable. That is the half of the platform Vijilan engineers, on Falcon Onum or Cribl Stream, depending on what you already run.

Machine speed still needs someone accountable. Automation is what removes latency. It is not what removes responsibility. Praxis AI™ is our SOC platform: it correlates, triages and contains in seconds across every connected source, and a Vijilan analyst owns the decision at every layer, detection through response. Machine speed where speed wins, human judgement where it matters, and never autonomous-only.

And on the obvious question about overlap: Falcon Complete and Adversary OverWatch stop at the endpoint. NextDefend™ Operate and ThreatHunt™ carry the same standard across identity, cloud control planes, network and SaaS. We extend that team rather than duplicate it.

If you are at Fal.Con this week, come find us. If you are not, the same conversation works remotely.

Found this useful? Send it to someone who needs it.

Talk to a security expert

See what 24/7 looks like when the SOC actually acts.

Book a 20-minute platform walkthrough: no slide deck, just the console.

Book a walkthrough →