AI has rapidly evolved into a technology that takes action. AI agents can reason, access enterprise systems, and execute tasks autonomously at machine speed, often with the full permissions of the users they serve. As these agents proliferate across the enterprise, organizations need to understand where they operate, what they do, what they can access, and how to stop threats before they become breaches.
This shift demands a new approach to AI security. Traditional tools can discover AI assets, govern access, or inspect individual interactions, but they were not designed to connect agent activity with the downstream system actions they trigger. Securing the agentic enterprise requires visibility and control at agent runtime.
CrowdStrike is introducing CrowdStrike Falcon® Guardian, the evolution of Falcon AI Detection and Response (AIDR) and CrowdStrike’s flagship solution for the AIDR category. Falcon Guardian includes Falcon AIDR’s AI visibility, governance, data protection, and threat detection and response capabilities across endpoint, cloud, and SaaS environments, while introducing powerful new capabilities to comprehensively discover, investigate, and secure AI agents on the endpoint, where AI executes.
Falcon Guardian will include a new AI gateway capability to provide a centralized control and monitoring point for enterprise AI traffic. CrowdStrike is also extending our elite security services, expanding support for cross-domain threat hunting and managed detection and response (MDR) to Falcon Guardian.
With Falcon Guardian, CrowdStrike is extending our runtime security architecture into the agentic layer. Falcon Guardian fuses AI agent activity with CrowdStrike Falcon® platform endpoint telemetry to establish a direct causal chain from prompt to runtime behavior and impact. This gives security teams the context to understand what agents do, investigate AI threats and their blast radius, and respond before threats spread.
Secure AI Agents Where They Execute
AI agents introduce a new execution layer. They may reason at the AI layer, but when they take action, those actions execute through the operating system and interact with files, credentials, networks, applications, and other enterprise resources. This makes the endpoint a critical control point for understanding and securing autonomous AI behavior.
Built on the Falcon platform, Falcon Guardian combines continuous agent discovery with runtime visibility, investigation, and control to help organizations understand which AI agents are operating and what they do. New capabilities include:
- Discover shadow AI agents: Falcon Guardian continuously discovers known and previously unknown AI agents across supported Windows, macOS, and Linux endpoints. It identifies where they are running, who is using them, and their security status.
- Connect AI activity to runtime impact: Falcon Guardian fuses AI agent activity with Falcon endpoint telemetry to connect prompts, skill use, tool calls, MCP servers, and identity with downstream system execution for supported agents. This establishes prompt-to-runtime-behavior that shows security teams what an agent was asked to do and what happened.
- Turn AI governance into runtime control: Falcon Guardian enables organizations to define which supported AI agent types are permitted to operate on managed endpoints, helping security teams sanction approved agents and prevent unauthorized agent types from running. Existing Falcon Guardian controls continue to protect supported AI interactions against threats such as prompt injection and sensitive data exposure.
- Investigate threats to agents, determine blast radius, and stop breaches: Falcon Guardian reconstructs agent sessions and downstream execution into a unified causal investigation, allowing analysts to trace suspicious activity across affected agents and systems. Teams can quickly pivot to related activity to understand the scope of exposure and drive automatic containment by blocking malicious agent behaviors and compromised assets at runtime across agents.
Falcon Guardian’s new AI agent security capabilities build on a broader foundation of AI protection. It continues to help organizations discover shadow AI across endpoint, cloud, and SaaS environments, govern access to models and AI tools, protect sensitive data, and detect AI-specific threats. This foundation protects both workforce AI adoption and enterprise-developed AI systems.
