Loading...

CrowdStrike unveils Falcon Guardian to secure AI agents

CrowdStrike has introduced Falcon Guardian, a new AI Detection and Response (AIDR) solution designed to give enterprises complete visibility and runtime enforcement over AI agents, starting at the endpoint where they execute and extending across the broader enterprise environment.

With deployments spanning hundreds of millions of devices, CrowdStrike said its extensive endpoint footprint now forms the structural backbone for securing AI agents at scale.

George Kurtz, CEO and Founder of CrowdStrike, said the company built its reputation by making the endpoint the control point for stopping attacks, and that AI now demands the same discipline. He added that while AI has not changed the nature of attacks, it has dramatically increased their speed, and that governance alone cannot stop an agent already in motion — a gap Falcon Guardian is built to close by converting policy into real-time protection.

The company positioned the endpoint as the critical control point for AI security, noting that as AI agents gain system-level privileges, they increasingly reason, plan, and execute actions that closely resemble legitimate user behavior, often accessing sensitive data and triggering downstream workflows in the process. According to CrowdStrike, visibility into posture only reveals what could go wrong, governance can reduce that risk, but only runtime protection can stop an active threat, making the endpoint the natural starting point for enforcement.

Falcon Guardian delivers AI detection and response across the full AI estate, covering data, models, prompts, agents, identities, infrastructure, and interactions, with protection extending from the endpoint into cloud, SaaS, and browser environments through a single, unified sensor architecture.

The release introduces a range of new capabilities, including discovery and inventory of both known and shadow AI agents across Windows and macOS systems, and runtime visibility that links agent behavior to endpoint telemetry to map the complete execution chain from user prompt to downstream system action. The platform also introduces access controls that let organizations define which AI agents can run on managed endpoints, along with runtime detection and response capabilities that reconstruct attack chains and contain threats before they spread.

Additional features include an AI Gateway that will serve as a centralized control point for enterprise AI traffic across supported models and services, as well as Falcon Complete for Guardian and Falcon Adversary OverWatch for Guardian, which will extend CrowdStrike’s managed detection, response, and threat-hunting services to AI agent activity. The solution also integrates natively with Falcon Next-Gen SIEM, allowing AI agent data to be ingested as first-party data for correlation with identity, cloud, and SaaS telemetry, an approach CrowdStrike says avoids the costly third-party integrations required by competing tools that lack native SIEM support.

The company describes the Falcon platform as cybersecurity’s infrastructure layer for AI adoption, with Guardian serving as the point where that infrastructure secures every AI agent at runtime, across every surface where they operate.

Send news announcements/press releases to:
editor@thefoundermedia.com

About The Author