CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

CrowdStrike’s new flagship AI detection and response solution delivers runtime protection for AI agents, introduces a new AI gateway, and extends expert-led defense.

September 01, 2026

Securing AI

AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches.

This shift demands a new approach to AI security. Traditional tools can discover AI assets, govern access, or inspect individual interactions, but they were not designed to connect agent activity with the downstream system actions they trigger. Securing the agentic enterprise requires visibility and control at agent runtime.

CrowdStrike is introducing CrowdStrike Falcon® Guardian, the evolution of Falcon AI Detection and Response (AIDR) and CrowdStrike’s flagship solution for the AIDR category. Falcon Guardian includes Falcon AIDR’s AI visibility, governance, data protection, and threat detection and response capabilities across endpoint, cloud, and SaaS environments, while introducing powerful new capabilities to comprehensively discover, investigate, and secure AI agents on the endpoint, where AI executes. 

Falcon Guardian will include a new AI gateway capability to provide a centralized control and monitoring point for enterprise AI traffic. CrowdStrike is also extending our elite security services, expanding support for cross-domain threat hunting and managed detection and response (MDR) to Falcon Guardian.

With Falcon Guardian, CrowdStrike is extending our runtime security architecture into the agentic layer. Falcon Guardian fuses AI agent activity with CrowdStrike Falcon® platform endpoint telemetry to establish a direct causal chain from prompt to runtime behavior and impact. This gives security teams the context to understand what agents do, investigate AI threats and their blast radius, and respond before threats spread. 

Secure AI Agents Where They Execute

AI agents introduce a new execution layer. They may reason at the AI layer, but when they take action, those actions execute through the operating system and interact with files, credentials, networks, applications, and other enterprise resources. This makes the endpoint a critical control point for understanding and securing autonomous AI behavior.

Built on the Falcon platform, Falcon Guardian combines continuous agent discovery with runtime visibility, investigation, and control to help organizations understand which AI agents are operating and what they do. New capabilities include:

  • Discover shadow AI agents: Falcon Guardian continuously discovers known and previously unknown AI agents across supported Windows, macOS, and Linux endpoints. It identifies where they are running, who is using them, and their security status. 
  • Connect AI activity to runtime impact: Falcon Guardian fuses AI agent activity with Falcon endpoint telemetry to connect prompts, skill use, tool calls, MCP servers, and identity with downstream system execution for supported agents. This establishes prompt-to-runtime-behavior that shows security teams what an agent was asked to do and what happened.
  • Turn AI governance into runtime control: Falcon Guardian enables organizations to define which supported AI agent types are permitted to operate on managed endpoints, helping security teams sanction approved agents and prevent unauthorized agent types from running. Existing Falcon Guardian controls continue to protect supported AI interactions against threats such as prompt injection and sensitive data exposure.
  • Investigate threats to agents, determine blast radius, and stop breaches: Falcon Guardian reconstructs agent sessions and downstream execution into a unified causal investigation, allowing analysts to trace suspicious activity across affected agents and systems. Teams can quickly pivot to related activity to understand the scope of exposure and drive automatic containment by blocking malicious agent behaviors and compromised assets at runtime across agents.

Falcon Guardian’s new AI agent security capabilities build on a broader foundation of AI protection. It continues to help organizations discover shadow AI across endpoint, cloud, and SaaS environments, govern access to models and AI tools, protect sensitive data, and detect AI-specific threats. This foundation protects both workforce AI adoption and enterprise-developed AI systems.

Extend Falcon Guardian with an AI Gateway

As AI applications and agents communicate with a growing ecosystem of models, services, and MCP infrastructure, organizations need a consistent way to monitor and govern AI traffic beyond the endpoint.

Falcon Guardian will soon include a native AI gateway capability, offering a new centralized control point for enterprise AI traffic and will provide expanded visibility, access management, and policy enforcement as applications and agents communicate with AI models and services. The gateway feature will also use context from the Falcon platform, including the user, agent, endpoint, identity, asset, and security posture, to inform policy decisions.  

This new capability is currently pre-beta and will go to GA next quarter (Q4).

Extend Expert-Led Defense to AI

As AI agents operate autonomously across enterprise environments, organizations need the expertise to identify suspicious behavior, uncover emerging adversary tradecraft, and respond when AI systems are targeted or compromised. CrowdStrike is extending managed cross-domain threat hunting and MDR services to Falcon Guardian, bringing expert-led defense to AI applications and autonomous agents.

Falcon Adversary OverWatch Hunts Threats Targeting AI Agents

CrowdStrike Falcon® Adversary OverWatch™ Cross-Domain, available today, extends 24/7 proactive threat hunting to AI applications and autonomous agents using Falcon Guardian’s runtime context. CrowdStrike’s expert hunters combine this rich behavioral context with frontline adversary intelligence to uncover manipulation, abuse, and emerging tradecraft that automated detections may miss.

This helps security teams identify and disrupt adversaries before they can expand access and escalate AI activity into a broader intrusion.

Customers must have both Falcon Adversary OverWatch Cross-Domain and Falcon Guardian.

Falcon Complete MDR for the AI Era

CrowdStrike is also announcing CrowdStrike Falcon® Complete for Falcon Guardian to extend CrowdStrike’s industry-leading MDR service to AI applications and autonomous AI agents.

Falcon Complete for Falcon Guardian will deliver continuous, expert-led detection, investigation, and response for AI agents. CrowdStrike’s elite analysts will use Falcon Guardian’s rich runtime context to assess agent intent, distinguish legitimate AI activity from malicious behavior, and stop attacks in real time. With CrowdStrike analysts monitoring AI environments 24/7, customers can realize the full operational value of Falcon Guardian with expert protection around the clock. 

This new service will be available to customers later this quarter (Q3).

Falcon Next-Gen SIEM Delivers Scalable, Cost-Effective Agent Data Capture

AI agents generate orders of magnitude more telemetry than traditional applications or human users. Routing this volume to third-party SIEMs can cause ingest costs to spiral out of control. 

Falcon Guardian natively exports agent telemetry into CrowdStrike Falcon® Next-Gen SIEM as first-party data, pre-mapped to its schema for immediate correlation, detection, and automation, and correlated with identity, cloud, and SaaS data across the Falcon platform for cross-domain investigations. Since Falcon Guardian data is treated as first-party data rather than a separate ingest-based line item, this integration can eliminate potentially millions in annual third-party SIEM costs with agent telemetry, with default retention included to support compliance-ready visibility into AI agent activity.  

CrowdStrike Defines the Next Generation of AI Security

Falcon Guardian brings discovery, governance, data protection, runtime security, investigation, and response together in CrowdStrike’s flagship solution in the AIDR market category, extending protection from AI interactions into the new agent execution layer.

CrowdStrike pioneered detection and response for the endpoint. Today, we are defining the AIDR category and applying that same focus on deep visibility, rich security context, and decisive response as we did with endpoint detection and response (EDR). With Falcon Guardian, organizations can build a stronger foundation to accelerate secure AI adoption and innovation.

Learn more about Falcon Guardian

Disclaimer

This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action