“We are at a tipping point in cybersecurity,” NVIDIA Founder and CEO Jensen Huang told a packed audience at CrowdStrike’s Fal.Con 2026 conference in Las Vegas. As cyberattacks become increasingly automated, cybersecurity defenses must evolve at the same speed.
Huang joined CrowdStrike Founder and CEO George Kurtz to announce SafeMind, an agentic cybersecurity system developed by the CrowdStrike Cyber Superintelligence Lab.
“This is the beginning of a new era in cybersecurity,” Huang told an audience of approximately 10,000 security professionals. “On the one hand, the enemy will be better armed than ever. On the other hand, all of you will be better armed than ever.”
SafeMind combines CrowdStrike’s purpose-built cybersecurity reasoning model and customized agent harness with a defense model built on NVIDIA Nemotron. The system operates in a continuous co-evolutionary loop in which offensive and defensive agents repeatedly challenge, test and improve one another.
CrowdStrike also announced enhancements to CrowdStrike Falcon IQ, which supports Project QuiltWorks through agent-driven workload automation, as well as new CrowdStrike Guardian AI safety solutions.
“We have an asymmetric advantage because we have a large community of cybersecurity professionals who want to work together to keep the world safe,” Huang said.
CrowdStrike’s annual conference brings together security leaders from financial services, healthcare, the public sector and critical infrastructure organizations.
“The real gap I saw was that the offense had frontier AI and the defense did not have it,” Kurtz said. “And now that changes.”
SafeMind: An Agentic AI System for Cybersecurity
CrowdStrike built SafeMind’s defense model using open NVIDIA Nemotron models and post-trained it with CrowdStrike’s cybersecurity expertise, threat intelligence and operational data. The SafeMind model is paired with a specialized cybersecurity harness optimized to operate as an agentic AI stack.
The technology is delivered natively through the CrowdStrike Falcon platform as SafeMind, an agentic cybersecurity system designed to help organizations detect, investigate and stop threats. SafeMind combines offensive and defensive AI in a continuous co-evolutionary process, with each side adapting to the other until the customer environment is hardened and the attack fails.
“We have 15 years of security data that we can train on. We can take the frontier model and essentially make it a super AGI that is highly capable in cybersecurity,” Huang told Kurtz.
“Together with NVIDIA, we built cybersecurity’s first complete agent system, including the first frontier model and a defender-specific harness,” Kurtz said. “This is not a copilot with someone else’s intelligence built in. It is not a chatbot with a security layer. It is a frontier-class model built and trained on CrowdStrike data by CrowdStrike in partnership with NVIDIA.”
NVIDIA Nemotron 3 Ultra tunes the defense agent’s harness, while the fine-tuned Nemotron 3 Super model powers SafeMind’s rule-generation subagent.
After post-training Nemotron with CrowdStrike data, CrowdStrike’s internal evaluation found that the Blue Solano model, based on Nemotron 3 Super, delivered higher accuracy than leading frontier models at 99% lower cost.
SafeMind can operate as a complete cybersecurity system, while its individual models can also support security teams as they work to stay ahead of attackers. Security professionals can combine their own models with CrowdStrike’s custom harnesses, giving organizations the flexibility to select the models and capabilities best suited to their environments.
“The harness is essentially an exoskeleton for a large language model,” Huang said. “The large language model is the brain. The exoskeleton turns it into an agent. That exoskeleton does not need to have the same shape or function in every environment.”
When AI Becomes Your Cybersecurity Defense
AI-powered attacks increased by 89% over the past year, while the fastest eCrime breakthrough time reached just 27 seconds, according to CrowdStrike. Responding at human speed is no longer an effective cybersecurity strategy.
“There are many applications that require fine-tuning and post-training to create AI that is highly capable in a particular domain,” Huang said. “Nemotron was built to do just that. It is open, incredibly fast and gives you an asymmetric advantage against whatever comes your way.”
Using open Nemotron models, CrowdStrike’s security team customized the AI for its own cybersecurity environment by post-training it with proprietary threat data without sending that data to an external provider.
This level of customization and visibility is not possible with a closed frontier model. For cybersecurity teams, the ability to inspect, adapt and understand the technology protecting an environment is essential.
Red Team vs. Blue Team: Continuous AI Security Testing
NVIDIA and CrowdStrike also announced testing work for the SafeMind model and harness in a high-fidelity CyberAgent environment that simulates an NVIDIA network.
In these tests, SafeMind operates in an automated attack-and-defense loop designed for adversarial co-evolution. Red-team agents discover vulnerabilities and execute attack paths, while blue-team defender agents identify and stop those attacks. Each discovery can then become an actionable detection designed to block future attempts.
The Red Agent Harness uses reconnaissance, attack and compromise subagents to execute attack paths within the CyberAgent environment. The Blue Agent Harness monitors the environment through Falcon sensors to generate, validate and support new detection candidates.
CrowdStrike and NVIDIA created the test environment as a digital twin of NVIDIA’s proprietary accelerated computing infrastructure. The environment was validated against NVIDIA’s real-world threat landscape.
“SafeMind’s basic framework is an adversarial model acting on a digital twin of the environment, while a defender model operates in a continuous cat-and-mouse loop that ultimately learns how to protect itself,” Huang said. “This framework applies to almost everything, including robotics, edge computing and enterprise computing.”
CrowdStrike also announced Falcon IQ. NVIDIA Nemotron models help power the agent engine at the center of Charlotte AI AgentWorks, CrowdStrike’s no-code agent development platform on which Falcon IQ runs.
Falcon IQ uses more than 50 agents working together as a unified AI workforce to automate time-consuming security workflows, including assessment, prioritization and remediation.
Partners can use Falcon IQ to deliver customized findings, recommendations and executive-level reports to customers. Charlotte AI AgentWorks also enables Falcon users to build their own agentic cybersecurity workforce.
Full-Stack AI for Enterprise Cybersecurity
CrowdStrike’s customers generate trillions of security events every day across thousands of organizations.
NVIDIA’s full-stack accelerated computing platform supports collaboration across the entire cybersecurity technology stack—from chips and infrastructure to AI models and agent harnesses that act on detected threats. For Kurtz, that integration is central to the value of the partnership.
“The crowd in CrowdStrike creates an asymmetry that puts defenders in a unique position to defeat the enemy,” Kurtz said.
Source: blogs.nvidia.com


