Key Points
- CrowdStrike SafeMind pairs offensive and defensive AI models in a single security system
- Company claims 29 per cent higher detection and 99 per cent cost savings versus generic models
- Built using NVIDIA Nemotron with training on 15 years of incident response data
CrowdStrike has launched SafeMind, a family of artificial intelligence models designed specifically for cybersecurity that pairs offensive and defensive systems to detect and remediate threats without human intervention.
The Austin-based cybersecurity firm announced the launch on 1 September at its Fal.Con 2026 conference in Las Vegas. SafeMind will operate within the existing CrowdStrike Falcon platform, the company’s flagship security product used by enterprises globally including several large Indian organisations.
Unlike general-purpose AI models that can identify security risks, SafeMind operates as what the company calls an agentic system, meaning software that can take autonomous action rather than simply flagging problems for human review. The system consists of two distinct models working in tandem: one trained to find vulnerabilities as an attacker would, and another trained to close those gaps using defensive measures.
Dual-model approach
The offensive model, named Red Tempest, emulates the behaviour of AI-powered adversaries to identify attack paths within an organisation’s systems. The defensive model, Blue Solano, responds by deploying countermeasures drawn from real-world security practices.
“The future of cybersecurity won’t be defined by AI that simply identifies threats, it will be defined by AI that defeats them,” said George Kurtz, chief executive officer and founder of CrowdStrike. “SafeMind brings offensive and defensive models together in a system trained on CrowdStrike’s unique cyber data.”
The models were trained using data from CrowdStrike’s Falcon sensor network, which the company describes as the world’s largest dataset focused exclusively on cybersecurity. Training data also included threat intelligence gathered by the company, annotations from its managed detection and response service, and records from 15 years of incident response work where human security teams stopped active breaches.
CrowdStrike built SafeMind using NVIDIA‘s Nemotron open models, with NVIDIA serving as the company’s AI design partner. CoreWeave, a cloud computing firm specialising in AI workloads, provided infrastructure for both training the models and running them in production.
Claimed performance
The company released benchmark comparisons against what it described as leading frontier models and open-source alternatives. According to CrowdStrike’s internal evaluations, SafeMind demonstrated a 29 per cent higher detection rate, remediated threats six times faster end-to-end, and achieved 99 per cent cost savings on detection and remediation tasks.
These figures have not been independently verified. The company did not disclose which specific models SafeMind was tested against or the methodology used for comparison.
“Cybersecurity in the age of AI will be a continuous contest between adversaries using AI to scale attacks and defenders using AI to expand detection and response,” said Jensen Huang, founder and chief executive officer of NVIDIA. “SafeMind combines NVIDIA Nemotron open models with CrowdStrike’s deep cybersecurity expertise.”
The system includes what CrowdStrike calls harnesses, software components that orchestrate both models in a continuous loop where the offensive model probes for weaknesses and the defensive model responds. This creates what the company describes as a co-evolving system that improves through constant internal testing.
“With the models and harnesses together in a co-evolving agentic system, defenders can now act at machine speed,” said Bartley Richardson, chief AI and autonomous systems officer at CrowdStrike. “This is the foundation for the next decade of AI security.”
By the numbers
Key figures from this story- 29%
- higher detection rate claimed versus frontier models
- 6x
- faster end-to-end threat remediation
- 99%
- cost savings on detection and remediation tasks
The harnesses are also designed to work with third-party AI models, allowing organisations to use frontier models from other providers or open-source alternatives within the same security framework. This approach gives enterprises flexibility in model selection while maintaining the automated response capabilities.
SafeMind will be available natively within the Falcon platform. Standalone access to the models and harnesses will be offered through CrowdStrike’s Project QuiltWorks programme, though the company did not announce pricing or availability timelines for the Indian market.
Michael Intrator, co-founder and chief executive officer of CoreWeave, said the partnership represented a test of AI capabilities in high-stakes production environments. “Few environments put that to the test more than cybersecurity,” Intrator said.
Your Questions, Answered
What is CrowdStrike SafeMind?
SafeMind is a family of AI models designed specifically for cybersecurity. It pairs an offensive model that identifies attack paths with a defensive model that deploys countermeasures, operating autonomously within CrowdStrike's Falcon platform.
How does SafeMind differ from other security AI tools?
Unlike general AI models that flag risks for human review, SafeMind operates as an agentic system that can autonomously take defensive action. Its two models continuously test each other, with the offensive model probing for weaknesses while the defensive model responds.
What data was used to train SafeMind?
The models were trained on CrowdStrike's Falcon sensor telemetry, threat intelligence, managed detection service annotations, and 15 years of incident response records from human security teams stopping active breaches.
What performance improvements does CrowdStrike claim for SafeMind?
CrowdStrike claims SafeMind achieves 29 per cent higher detection rates, six times faster end-to-end remediation, and 99 per cent cost savings compared to leading frontier models. These benchmarks have not been independently verified.

