Skip to main content

Explainer · CrowdStrike

CrowdStrike Falcon Guardian, explained

CrowdStrike launched Falcon® Guardian on 1 September 2026 as its flagship AI Detection and Response product. Here’s what it does, what it replaces, and the part the datasheet doesn’t cover.

In brief

The short version

Falcon Guardian secures AI agents where they actually run: on the endpoint. It’s built into the CrowdStrike Falcon sensor, so there’s no new agent to install. It finds AI agents on Windows and macOS devices, traces what they do at runtime, controls which ones may run, and detects and responds when one is misused or compromised.

It’s CrowdStrike’s answer to a specific problem. In CEO George Kurtz’s words at launch: “AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion.”

Capabilities

What it does

CrowdStrike describes these capabilities at launch:

  1. 1

    Agent discovery and inventory

    Every AI agent on the device, including what skills, tools and MCP servers it can reach.

  2. 2

    Runtime visibility

    The causal chain from a prompt to the processes, files and network activity that followed.

  3. 3

    Agent access controls

    Policy over which agents run and how people use AI tools.

  4. 4

    Runtime detection and response

    Detecting compromised or misused agents and containing them.

  5. 5

    Next-Gen SIEM integration

    Guardian data arrives as first-party Falcon data.

CrowdStrike has also announced an AI Gateway and managed services, Falcon Complete for Guardian and Falcon Adversary OverWatch for Guardian, as part of the Guardian family.

Naming

What happened to Falcon AIDR?

“AIDR”, meaning AI Detection and Response, is the category. Falcon Guardian is now CrowdStrike’s product name for it. If you’ve seen earlier CrowdStrike announcements about AIDR for endpoint, Copilot Studio or cloud, Guardian is where that capability now lives. Existing customers should check the transition details with CrowdStrike or their provider.

Comparison

Guardian vs an AI gateway

AI gatewayFalcon Guardian
Where it sitsIn the network path to AI servicesIn the Falcon sensor on the device
Sees agents that aren’t currently talkingNoYes
Sees what a prompt did on the machineNoYes
Sees AI traffic routed around itNoYes, where the sensor runs
Best atCentral policy on sanctioned AI trafficDiscovery, runtime behavior, endpoint response

They aren’t rivals. Guardian can take gateway data through a collector, and most organizations with a gateway should keep it.

Operating it

What it takes to run

Guardian produces what every good detection product produces: detections, policies and decisions. Someone has to:

  • decide what counts as sanctioned AI, and keep that list current as new tools appear
  • tune the prompt detectors so legitimate work isn’t flagged all day
  • set privacy controls before any prompt content is collected
  • triage agentic detections at 2am and decide whether to isolate a developer’s laptop
  • report to the CISO and the board on what’s running and what changed

CrowdStrike offers its own services for parts of this. Service partners, including Vijilan, offer others.

One option

How Vijilan runs it

ThreatAI Watch is Vijilan’s managed AI Detection and Response service on Falcon Guardian: Deploy, Sustain and Operate, with a 24/7 SOC and a Vijilan analyst authorizing every consequential action. Available as an add-on to ThreatDefend™ or NextDefend™, or standalone for organizations that already own Falcon.

References

Sources

Page published . We update it when CrowdStrike does.