Couldn’t make Fal.Con? Get in on Fal.Con Digital.  Learn more
CrowdStrike Falcon® Guardian

Secure AI agents at runtime

Discover, govern, and secure AI agents with runtime visibility and control. Protect AI wherever it executes, from the endpoint to cloud and SaaS environments.

New from Fal.Con 2026

AI agents don't just answer. They execute.


Computer-use agents can access identities, data, files, browsers, shells, and system settings. Acting  with user permissions at machine speed, they can create an enormous agentic blast radius.

Agents live in the shadows

Security teams can’t see which agents are running, who is using them, or what risks they introduce.
Agent actions are invisible

Security teams can’t connect prompts to the actions agents execute to identify agentic misalignment.
Agents face novel runtime attacks

Prompt injection and poisoned tools can hijack agents and cause breaches at machine speed.

Secure the entire AI estate with Falcon Guardian


Falcon Guardian brings AI Detection and Response (AIDR) to the point of execution, connecting AI activity with endpoint telemetry to understand and secure autonomous AI behavior at runtime.

Guardian AIDR infographic
×

99%

Detection efficacy of prompt attacks5


100milliseconds

Latency or less for detections5


Adopt and innovate faster

Pre-built, seamless guardrails accelerate secure AI use and development compared to DIY solutions

See and secure every AI action


Unify AI visibility, governance, runtime protection, and response.

 

New

Discover shadow AI agents


Gain visibility into workforce AI use and endpoint agents. Uncover shadow AI to understand what’s in use, who is using it, view token consumption, and see where unmanaged risk exists.

screenshot of Guardian activity dashboard
×
Identity protection screenshot
×
New

See what AI agents actually do


Connect agent activity with endpoint telemetry to trace how user prompts lead to downstream processes and system actions.

New

Govern AI usage and agent access


Turn AI governance policy into enforceable controls. Govern how users interact with AI tools and define which AI agents are permitted to run.

screenshot
×
screenshot
×

Protect prompts and sensitive data


Apply Falcon Guardian security policies as users, applications, and agents interact with AI services. Detect and stop malicious interactions and protect sensitive data in transit without disrupting legitimate AI workflows.

New

Detect and stop threats at runtime


Detect compromised AI agents, reconstruct what happened, and determine the full blast radius across affected agents and systems. Deploy containment actions to stop threats before they spread.

screenshot
×
Identity protection screenshot
New

Coming soon: AI gateway for Falcon Guardian


Centralize visibility and control over enterprise AI traffic. Falcon Guardian’s AI gateway capability will manage how applications and agents access AI models and services, using Falcon context across users, agents, endpoints, identities, assets, and security posture to inform policy enforcement.

See Falcon Guardian in action

Interactive Challenge

AI Unlocked: Agents of Chaos

The enemy is already inside. Infiltrate the Agents of Chaos, stop the insider threat, and compete for a chance to win up to $100,000.*

 

Latest innovations from

Fal.Con 2026 Logo
Falcon Guardian launches end-to-end security for endpoint agents and announces new AI gateway capability
Introducing threat hunting and managed detection and response for Falcon Guardian
New Game: Agents of Chaos. Infiltrate a shadow organization, stop the threat, and play for a chance to win up to $100,000.*

Featured Resources

AIDR: Defining the Next Era of Cybersecurity

Falcon Guardian Data Sheet

Taxonomy of Prompt Injection Methods

Secure AI where it executes

Gain the visibility, governance, and runtime protection to secure AI adoption with Falcon Guardian.

Falcon Guardian FAQs

CrowdStrike Falcon® Guardian is our flagship AI detection and response (AIDR) solution. It helps organizations discover and govern AI use, secure autonomous AI agents at runtime, protect sensitive data, and detect and respond to AI threats.

AI Detection and Response (AIDR) is a cybersecurity solution category for discovering, governing, and securing AI systems and activity. AIDR solutions extend protection from AI interactions to runtime execution, helping organizations detect and stop AI threats as they occur.

AI agents can use tools, access data, and take actions with user permissions at machine speed. Runtime security provides visibility and control as those actions execute, helping detect and stop threats before they lead to a breach.

Falcon Guardian correlates AI agent activity with endpoint telemetry to connect user prompts to downstream system actions. This runtime context helps security teams understand agent behavior, investigate threats and their blast radius, and stop attacks before they become breaches.

Shadow AI is AI use or deployment that operates outside an organization’s visibility or control Falcon Guardian discovers AI use and agents on endpoints, and across cloud and SaaS environments,helping security teams understand activity, enforce policy, and reduce unmanaged AI risk.

Yes. Falcon Guardian protects workforce use of AI including runtime security for AI agents used on the endpoint. It also helps organizations secure homegrown AI agents, factories, and workloads from runtime threats like prompt injection attacks.

Falcon Guardian identifies sensitive data in AI interactions and applies runtime controls to redact, encrypt, or block it before exposure. This helps organizations enforce data protection policies while keeping legitimate AI workflows moving.

Falcon Guardian inspects AI interactions at runtime to detect direct and indirect prompt injection attacks spanning 200+ techniques. It can block malicious interactions before they manipulate AI agents, expose sensitive data, or trigger unsafe actions.

Traditional endpoint security detects and stops threats based on host-level activity. Falcon Guardian adds AI and agent-specific context, connecting prompts and agent activity to downstream endpoint actions so teams can understand, investigate, and stop threats as AI executes. Traditional endpoint security only sees one aspect of this AI behavior, the host-level activity.

1CrowdStrike Taxonomy of Prompt Injection
2IBM Security & Ponemon Institute: Cost of a Data Breach Report 2025.
3The CrowdStrike Falcon® Adversary OverWatch™ threat hunting team
4KPMG Global AI Pulse, Q1 2026
5Performance metrics are based on results from internal benchmark testing.
*NO PURCHASE NECESSARY TO PARTICIPATE OR WIN. Challenge begins 8/31/26 at 5:00 p.m. PT and ends 9/29/26 at 11:59 p.m. PT. Must be at least age of majority in jurisdiction of residence to participate. Void in select jurisdictions & where prohibited. See full Official Rule, which govern the challenge, for complete details.