Science & TechnologySecurity ThreatsTech

Nvidia and CrowdStrike unveil SafeMind: how agentic cyber defence is meant to work

CrowdStrike and Nvidia have announced SafeMind, a family of cybersecurity models and agent harnesses intended to find attack paths and generate defensive changes in a continuous test-and-remediation loop. The system was unveiled at CrowdStrike’s Fal.Con 2026 conference in Las Vegas and is designed to operate natively within the Falcon platform.

The announcement reflects a broader shift from AI assistants that summarise alerts toward systems that can coordinate multi-step security work. That greater autonomy also increases the importance of isolation, approval controls and reliable evaluation.

Red Tempest and Blue Solano

SafeMind launches with two specialised models. Red Tempest is described as an offensive red-team model for advanced attack simulations, while Blue Solano is intended to generate defensive measures. CrowdStrike says both use Nvidia Nemotron open models as a foundation and are post-trained with Falcon telemetry, threat intelligence, managed-response annotations and incident-response experience.

Agent harnesses place the offensive and defensive models in a closed loop. A red-side agent identifies a possible attack path, a blue-side agent creates and tests detections or mitigations, and the result is evaluated before defensive changes are promoted. Nvidia says the companies tested this approach in a digital twin of Nvidia’s accelerated-computing environment.

Where Falcon IQ fits

Falcon IQ is a related workflow system powered by Nvidia Nemotron and CrowdStrike’s Charlotte AI AgentWorks. CrowdStrike says it uses more than 50 agents for assessment, prioritisation and remediation tasks. Partners can use it to produce attack narratives, investment priorities and remediation roadmaps inside Falcon.

This does not necessarily mean 50 independent frontier models are simultaneously making unsupervised production changes. “Agent” can describe a specialised workflow with constrained tools and instructions. The practical safety level depends on what permissions each agent has, how actions are validated and whether a human must approve a change.

Performance claims need independent testing

CrowdStrike reports that its SafeMind evaluations produced a 29% higher detection rate, six-times faster end-to-end remediation and 99% cost savings compared with selected frontier-model and open-source baselines. Nvidia separately highlights the 99% lower-cost figure for the Blue Solano model.

Those numbers come from the companies announcing the product. Public details do not yet provide everything needed to reproduce the comparison across identical workloads, model versions, tools and error costs. Prospective customers should ask for evaluation design, false-positive rates, rollback behaviour and results on their own environment.

The central operational questions

  • Can offensive agents reach only an isolated simulation or digital twin?
  • Which proposed detections and configuration changes require approval?
  • How are hallucinated vulnerabilities or unsafe remediations rejected?
  • What customer telemetry is used for training, inference and retention?
  • Can every action be audited and reversed?

Agentic defence may help teams respond faster than manual alert queues allow, but speed is valuable only when the system stays inside its authorised boundary.

Sources: Nvidia’s Fal.Con announcement; CrowdStrike SafeMind release; CrowdStrike Falcon IQ release.

George Kurtz and Jensen Huang at Fal.Con 2026. Official event photograph: Nvidia.

Related Articles

Back to top button

Adblock Detected

Please consider supporting us by disabling your ad blocker