As organizations race to adopt new AI tools, deploy AI agents, and build AI-powered software, they create new attack surfaces that traditional security controls were never designed to protect.
A key example is the prompt and agentic interaction layer, which faces novel threats like indirect prompt injection and agentic tool chain attacks. The rapid acceleration of shadow AI exacerbates the challenge as employees adopt AI tools without oversight and engineering teams deploy models and agents without adequate visibility and runtime protection. The result is an AI visibility and governance gap that grows with every AI tool deployment and adoption.
CrowdStrike is closing that gap. Today we’re announcing a series of innovations across the CrowdStrike Falcon® platform that extend AI detection and response (AIDR) capabilities across new surface areas and expand our platform capabilities to secure AI workforce adoption and development across endpoints, SaaS environments, and cloud environments.
These new capabilities will enable organizations to confidently and securely accelerate AI development and adoption.
Defending Endpoints: The Ultimate AI Battleground
The endpoint has always been a primary target for adversaries, but the rise of personal AI agents like OpenClaw puts them at the frontline of a new attack technique called living off the AI land (LOTAIL). LOTAIL exploits a dangerous combination of factors that converge on the endpoint: increasing agent autonomy, high system permissions, and minimal governance. Code and computer-use agents, agentic browsers, and personal AI tools are being deployed, particularly on developer machines, and they can execute terminal commands, browse the web, interact with files, and take autonomous actions that can look indistinguishable from legitimate user behavior traffic. That makes them extraordinarily difficult to detect with traditional tools, and extraordinarily dangerous when compromised.
Today we’re announcing two significant new capabilities to extend endpoint AI security capabilities for agents and shadow AI.
AI Detection and Response for Desktop AI Applications
We’re excited to announce that CrowdStrike Falcon AIDR's runtime threat detection capabilities for securing workforce AI adoption will extend beyond the browser, where most employee AI interactions occur, to cover desktop AI applications including ChatGPT, Gemini, Claude, DeepSeek, Microsoft Copilot, O365 Copilot, GitHub Copilot, and Cursor.