CrowdStrike FalCon 2026: AI Is Changing the Speed of Cybersecurity

CrowdStrike FalCon 2026 showed how autonomous AI is forcing cybersecurity to move faster.

Written By
Ken Underhill
Ken Underhill
Sep 3, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

After spending time at CrowdStrike FalCon 2026, I came away thinking the biggest change facing cybersecurity is not simply that attackers and defenders have better AI tools.

It is that AI is starting to act on its own.

Across keynotes, panels, and private roundtable discussions, I heard executives repeatedly come back to the same challenge from different directions: How do you secure an environment when autonomous agents can discover vulnerabilities, make decisions, and take actions faster than people can?

Attacks are moving at the speed of inference

CrowdStrike founder and CEO George Kurtz described attacks as happening at the “speed of inference.” 

Instead of waiting for a human operator to decide what happens next, autonomous agents can potentially identify an opportunity and immediately act on it.

Kurtz pointed to the recent Hugging Face incident as an example of what that future could look like. 

Greg Brockman, co-founder and president of OpenAI, went further and described it as the first public example of a real autonomous agent attack rather than a theoretical scenario.

OpenAI had anticipated that agents could eventually demonstrate these capabilities, Brockman said, but seeing them operate against live systems changed the conversation. 

His point was that powerful models still need deterministic security controls around them. The model itself cannot be the security boundary.

Adam Meyers, CrowdStrike’s SVP of Counter Adversary Operations, showed just how quickly that boundary is being tested.

CrowdStrike measured average attacker breakout time at 29 minutes last year, with the fastest observed case taking just 27 seconds. Meyers also described an attack where more than 1,100 LLM-driven commands were executed within minutes.

Vulnerability volume is accelerating too. Meyers said CrowdStrike discovered approximately 2,400 CVEs in June 2026, while roughly 7,400 were identified industrywide that month. 

His conclusion was that the traditional 30-day patching cycle is becoming obsolete.

Advertisement

That stood out to me because many enterprise security processes are still built around human-speed attacks.

Trust now extends beyond humans

Mike Sentonas, president of CrowdStrike, framed the problem differently. Enterprises are no longer deciding only which people should be trusted. They also have to decide which AI agents can act on their behalf.

That makes runtime visibility critical. Security teams need to understand what an agent is doing, what it can access, and what actions it is taking.

During a private roundtable, Sentonas told me that large enterprise customers are increasingly bringing their boards into AI security discussions. The question they are asking is how they can use AI faster without introducing unacceptable risk.

NVIDIA founder and CEO Jensen Huang took that idea further with what he called “agentic zero trust.” Agents should continually have to prove they are allowed to access systems and take actions.

I also found Huang’s tone interesting because it was noticeably less alarmist. 

He expects security operations to become significantly more autonomous over the next five years, but argued that the security industry should help reassure people rather than feed predictions about an AI catastrophe. 

Humans, in his view, will remain involved in the decisions that matter most.

The SOC will change, but people still matter

Austin Murphy, VP of Falcon Complete, gave one of the clearest pictures of what that human-AI relationship could look like.

CrowdStrike deals with more than 100,000 alerts each week. Its security agents were built around the standard operating procedures already used by MDR analysts, essentially teaching agents how experienced defenders respond to different incidents.

Murphy described humans as both “in the loop,” directly participating in decisions, and “on the loop,” overseeing autonomous activity. CrowdStrike also samples agent decisions to determine whether they match how a principal-level analyst would respond.

AI could also change how quickly junior analysts become productive. 

An analyst might use an LLM to generate a YARA rule without personally knowing how to write one, for example. But Murphy stressed that foundational security knowledge still matters.

Advertisement

Amazon CISO CJ Moses made a similar point. AWS honeypots encounter more than 750 million threat interactions every day, making automation essential at that scale.

Moses suggested security teams focus less on how many vulnerabilities they find and more on “mean time to defense”: how quickly they can actually protect the organization once a weakness or threat becomes known.

His comment that “AI is not magic but the people that operate it are” also reflected another theme I heard throughout FalCon: the importance of the security community. 

Kurtz and several other speakers repeatedly came back to the idea that the “Crowd” in CrowdStrike represents defenders working together and sharing what they learn. 

As attacks become faster and more autonomous, that collaboration could become even more important. 

AI will expose the security foundation you already have

Cristian Rodriguez, CrowdStrike’s field CTO of the Americas, gave me one of my favorite analogies of the conference.

He described organizations as having either a “clean room” or a “messy room.”

Companies that already have strong identity visibility and controls, AI visibility, vulnerability management, and policies are starting from a clean room. Organizations with existing gaps could see AI magnify the mess very quickly.

That may be my biggest takeaway from FalCon.

AI does not necessarily require security leaders to rebuild their programs from scratch. But it does change how quickly weaknesses can be found and exploited, who or what needs to be trusted, and how quickly defenders need to respond.

The organizations best prepared for autonomous AI may ultimately be the ones that get the fundamentals right before AI starts testing them at machine speed.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.