CrowdStrike Introduces SafeMind, an Agentic Cyber Defense System with NVIDIA
At Fal.Con 2026, CrowdStrike announced SafeMind, a group of security models and agentic tools for the Falcon platform. The project is being developed with NVIDIA, but the general availability date and independent production results are not yet known.

CrowdStrike SafeMind is a new group of security models and agentic “harnesses” that the company introduced on September 1 at the Fal.Con 2026 conference in Las Vegas. The system is intended to run natively in the Falcon platform and connect attack simulation with the creation, testing, and adjustment of security detections.
CrowdStrike is developing the system in collaboration with NVIDIA. The models are intended to build on NVIDIA Nemotron open models, while CoreWeave is expected to provide training and inference. The announcement represents a product step in AI tools for security operations teams, but the company has not yet provided a general availability date, customer access scope, or licensing and pricing terms.
CrowdStrike SafeMind Combines Offensive and Defensive Models
SafeMind includes two named models. Red Tempest is designed to simulate offensive scenarios, meaning it searches for possible attack paths. Blue Solano is a defensive model for tasks on the security team’s side. CrowdStrike describes the intended process as a closed loop: a simulated attacker examines the environment, after which a defensive agent creates, tests, and adjusts detections.
According to NVIDIA, the offensive-defensive cycle was tested in an isolated environment modeled on NVIDIA’s infrastructure. It was therefore not a customer production network. The testing process included validating generated detections through telemetry, replaying captured attacks, and independent evaluation.
This process is particularly important because an automatically created detection must respond to relevant behavior without generating an unreasonable number of false positives. However, the announcement does not provide the complete technical evaluation methodology or details about the specific scenarios used in the test environment.
Declared Results Currently Come from Company Evaluations
CrowdStrike reports a 29-percent improvement in detection rate, six-times-faster remediation, and 99% lower costs compared with selected models. However, these are results from company evaluations. The announcement does not fully disclose the compared models, methodology, or independent reproduction of these results.
CrowdStrike calls SafeMind the first agentic system for defenders. This, too, is a marketing comparison that has not been independently verified. The available materials also do not show that the system has already prevented a specific real-world attack or been deployed at scale in production environments.
What Will Matter When It Is Deployed in Falcon
For customers, it will be important to see how CrowdStrike SafeMind will be made available directly in Falcon and whether the individual models will be accessible through Project QuiltWorks. The rules for approving automated actions, output auditability, handling sensitive telemetry, and protection against misuse of the attack-simulation model will also be important.
Other points to watch include independent benchmarks and a more complete description of the technical methodology. Initial customer references or production deployment data will also be relevant. For now, what has primarily been confirmed is the system’s introduction, its partnership with NVIDIA, and testing in an isolated, modeled environment.
Sources
- CrowdStrike – Launches Frontier Models for Cybersecurity, Created with NVIDIA – Confirms the SafeMind announcement, its stated components, collaboration with NVIDIA and CoreWeave, and the company’s performance claims.
- NVIDIA Technical Blog – Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron – Describes the isolated testing environment, the detection-validation methodology, and the limits of evaluation based on a modeled environment.
- NVIDIA Blog – NVIDIA and CrowdStrike Strengthen Agentic Cybersecurity Frontier – Independently of CrowdStrike, confirms within the partner announcement the use of Nemotron and the introduction of SafeMind at Fal.Con 2026.
Verified and updated: 09/02/2026 06:59



