CrowdStrike and NVIDIA Launch Dual-Use Cybersecurity AI

CrowdStrike SafeMind pairs offensive and defensive AI models in a closed loop designed to test attack paths and strengthen enterprise cyber defenses.

Written By
Eric Mboizi
Eric Mboizi
Sep 2, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cyber defenders could soon have an AI system capable of testing attacks and developing defenses in the same continuous loop.

CrowdStrike has introduced SafeMind, a family of purpose-built cybersecurity models and agent harnesses with offensive and defensive capabilities. The system was developed using NVIDIA Nemotron 3 open models, with NVIDIA serving as an AI design partner and CoreWeave providing cloud infrastructure for training and inference.

CrowdStrike announced SafeMind at its Fal.Con conference in Las Vegas, where NVIDIA CEO Jensen Huang joined CrowdStrike CEO George Kurtz.

“This is the beginning of a new age of cybersecurity,” Huang said. “On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever.”

His comments framed SafeMind as a response to an increasingly automated security landscape in which attackers and defenders have access to more capable AI tools.

How SafeMind works

SafeMind combines purpose-built security models with agent harnesses that can also work with other frontier and open-source models. Its training data includes Falcon sensor telemetry, CrowdStrike threat intelligence, Falcon Complete managed detection and response annotations, and knowledge from 15 years of incident-response work.

CrowdStrike built SafeMind using NVIDIA Nemotron open models and post-trained them with its cybersecurity data. According to NVIDIA, CrowdStrike’s internal evaluations found that the Blue Solano defensive model delivered higher accuracy than the leading frontier models tested at 99% lower cost.

SafeMind has two specialized models: Red Tempest emulates adversaries in controlled red-team scenarios, while Blue Solano identifies security gaps and develops defensive detections. SafeMind’s harnesses operate both models in the same closed loop. The red model tests an attack path, the blue model develops and validates a defense, and the red model then adapts and tries again.

CrowdStrike says SafeMind will operate natively in its Falcon cloud cybersecurity platform. Trusted access to standalone models and harnesses will also be offered through Project QuiltWorks, although CrowdStrike has not announced general availability or pricing.

Advertisement

The new security landscape 

On the same day as the SafeMind launch, Crowdstrike also launched its Cyber Superintelligence Lab. The company says that the lab is meant to be “the first frontier AI research organization built for cyberdefense and AI safety.”

The launch of the lab and the release of its first product on the same day signal a strong commitment toward building agentic security tools. 

Earlier last month, Anthropic expanded access to its cybersecurity model, Mythos. This availability expansion saw the model go into public-beta access, allowing enterprises to test its features. 

Unlike SafeMind, Anthropic restricts potentially harmful capabilities in Mythos by default. However, approved researchers and organizations conducting “legitimate work” can apply for access to dual-use cybersecurity capabilities.

SafeMind instead places offensive testing and defensive remediation in a controlled, continuous loop. This could help authorized security teams conduct more complete end-to-end audits, although its enterprise value will depend on access controls, deployment safeguards, false-positive rates, and performance outside CrowdStrike’s internal evaluations.

Read more: As SafeMind aims to automate the contest between attackers and defenders, CrowdStrike’s 2026 threat report details how adversaries are already using AI to accelerate attacks and bypass traditional defenses.

Eric Mboizi

Eric Mboizi is a technology news writer covering software development, emerging technologies, and the evolving digital landscape for TechRepublic and eWeek. He holds a bachelor’s degree in software engineering from Makerere University and has more than five years of experience creating technical content for developers and technology professionals. In addition to his work as a journalist, Eric is an Ethereum developer with more than four years of experience in blockchain technology. His hands-on development background gives him a practical perspective on software engineering, decentralized technologies, and the real-world implications of new technology trends.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.