Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

CrowdStrike puts AI agents under runtime security with Falcon Guardian

CrowdStrike has launched a new AI detection and response platform designed to discover, monitor, and control AI agents at runtime across endpoints, cloud, SaaS, and browsers.

Wed, 02 Sep 2026
CrowdStrike puts AI agents under runtime security with Falcon Guardian

CrowdStrike has launched Falcon Guardian, a new AI detection and response platform aimed at securing AI agents as they move from experimentation into production and gain access to enterprise systems and data.

Guardian uses the Falcon sensor to provide visibility into AI agents running across Windows and macOS devices, including both authorised and “shadow” agents.

It can maintain a live inventory of agents, identify who deployed them and assess their security status.

 
 

CrowdStrike argues that the endpoint has become a critical control point for AI security because agents increasingly operate with system-level privileges and can access sensitive information or trigger downstream workflows with behaviour that may resemble legitimate user activity.

“CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach,” George Kurtz, CEO and founder of CrowdStrike, said in a statement.

“AI hasn’t changed the attack; it has changed its speed. Governance alone can’t stop an agent already in motion. Falcon Guardian turns policy into protection, stopping threats where AI agents execute and before they can cause harm.”

Guardian connects agent activity with Falcon endpoint telemetry to trace the chain of events from a user prompt and identity through tool calls and skills to subsequent system actions. CrowdStrike said this allows security teams to understand agent behaviour and determine the potential blast radius of an attack in real time.

The platform also introduces runtime access controls that allow organisations to specify which AI agents can operate on managed endpoints, blocking unauthorised agents and translating governance policies into enforceable controls.

Guardian will extend protection beyond endpoints to cloud, SaaS and browser environments, covering AI data, models, prompts, agents, identities, infrastructure and interactions through its single-sensor architecture.

The company is also planning an AI Gateway to provide a central control point for enterprise AI traffic across supported models and services, including communications using the Model Context Protocol.

Managed services will form another plank of the platform, with Falcon Complete for Guardian providing 24/7 detection, investigation, and response for AI agents. Falcon Adversary OverWatch for Guardian will extend threat hunting into AI agent activity using intelligence from CrowdStrike’s frontline adversary operations.

Guardian will also integrate AI agent telemetry directly into Falcon Next-Gen SIEM, allowing it to be correlated with identity, cloud and SaaS data without relying on third-party SIEM infrastructure.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: