Cyber defenders could soon have an AI system capable of testing attacks and developing defenses in the same continuous loop.
CrowdStrike has introduced SafeMind, a family of purpose-built cybersecurity models and agent harnesses with offensive and defensive capabilities. The system was developed using NVIDIA Nemotron 3 open models, with NVIDIA serving as an AI design partner and CoreWeave providing cloud infrastructure for training and inference.
CrowdStrike announced SafeMind at its Fal.Con conference in Las Vegas, where NVIDIA CEO Jensen Huang joined CrowdStrike CEO George Kurtz.
“This is the beginning of a new age of cybersecurity,” Huang said. “On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever.”
His comments framed SafeMind as a response to an increasingly automated security landscape in which attackers and defenders have access to more capable AI tools.
How SafeMind works
SafeMind combines purpose-built security models with agent harnesses that can also work with other frontier and open-source models. Its training data includes Falcon sensor telemetry, CrowdStrike threat intelligence, Falcon Complete managed detection and response annotations, and knowledge from 15 years of incident-response work.
CrowdStrike built SafeMind using NVIDIA Nemotron open models and post-trained them with its cybersecurity data. According to NVIDIA, CrowdStrike’s internal evaluations found that the Blue Solano defensive model delivered higher accuracy than the leading frontier models tested at 99% lower cost.
SafeMind has two specialized models: Red Tempest emulates adversaries in controlled red-team scenarios, while Blue Solano identifies security gaps and develops defensive detections. SafeMind’s harnesses operate both models in the same closed loop. The red model tests an attack path, the blue model develops and validates a defense, and the red model then adapts and tries again.
CrowdStrike says SafeMind will operate natively in its Falcon cloud cybersecurity platform. Trusted access to standalone models and harnesses will also be offered through Project QuiltWorks, although CrowdStrike has not announced general availability or pricing.
The new security landscape
On the same day as the SafeMind launch, Crowdstrike also launched its Cyber Superintelligence Lab. The company says that the lab is meant to be “the first frontier AI research organization built for cyberdefense and AI safety.”
The launch of the lab and the release of its first product on the same day signal a strong commitment toward building agentic security tools.
Earlier last month, Anthropic expanded access to its cybersecurity model, Mythos. This availability expansion saw the model go into public-beta access, allowing enterprises to test its features.
Unlike SafeMind, Anthropic restricts potentially harmful capabilities in Mythos by default. However, approved researchers and organizations conducting “legitimate work” can apply for access to dual-use cybersecurity capabilities.
SafeMind instead places offensive testing and defensive remediation in a controlled, continuous loop. This could help authorized security teams conduct more complete end-to-end audits, although its enterprise value will depend on access controls, deployment safeguards, false-positive rates, and performance outside CrowdStrike’s internal evaluations.
Read more: As SafeMind aims to automate the contest between attackers and defenders, CrowdStrike’s 2026 threat report details how adversaries are already using AI to accelerate attacks and bypass traditional defenses.





