3 Sources
[1]
CrowdStrike launches Falcon Guardian to police AI agents at the endpoint
CrowdStrike launches Falcon Guardian to police AI agents at the endpoint CrowdStrike Holdings Inc. today unveiled Falcon Guardian, software that finds the artificial intelligence agents running inside a company and shuts down the ones security teams have not approved. The launch came at the company's Fal.Con 2026 conference in Las Vegas. Guardian is the expanded successor to Falcon AI Detection and Response, which went generally available in December and picked up endpoint runtime protection and shadow AI discovery at the RSAC Conference in March. Enforcement is what has been added this time. CrowdStrike's argument is that the device is where an agent reasons, plans and runs code, which makes it the one place with a complete view of what that agent actually did. Discovery comes first. The Falcon sensor inventories known and shadow agents across Windows and macOS machines, both running and dormant, and logs who deployed each one along with its security status. Guardian then ties agent behavior back to endpoint telemetry, building a chain that starts at a user's prompt and runs through the identity used, the tools called and the skills invoked, down to whatever the agent did to the system afterward. Administrators can name which agents are permitted to run on a managed endpoint. Anything not on the list gets blocked. Detection and response work off the same telemetry. Guardian flags attacks aimed at agents as well as agents misbehaving on their own, then reconstructs the execution chain and calculates blast radius while an incident is still in motion. "CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach," said founder and Chief Executive George Kurtz. "AI hasn't changed the attack, it has changed its speed. Governance alone can't stop an agent already in motion." Two parts of Guardian are not shipping yet. AI Gateway will sit in front of enterprise AI traffic and apply Falcon policy to every call, including Model Context Protocol connections. CrowdStrike said it is in pre-beta and goes generally available next quarter. The managed detection and response tier, Falcon Complete for Guardian, is due later this quarter. Managed threat hunting through Falcon Adversary OverWatch Cross-Domain runs today. Agent telemetry lands in Falcon Next-Gen SIEM as first-party data with retention included, ready to be correlated against identity, cloud and software-as-a-service activity. Competing AI security tools ship no security information and event management of their own, according to CrowdStrike, leaving customers to bolt on a third-party product whose cost climbs as agent volume grows. Guardian is the second major product CrowdStrike has released at this year's conference. Falcon IQ, which hands the assessment and remediation work behind the company's Project QuiltWorks coalition to a fleet of more than 50 agents, launched on the conference's opening day Monday.
[2]
CrowdStrike Unveils Falcon Guardian to Secure AI Agents Where They Execute: On the Endpoint at Runtime
The endpoint is the control point for AI agent security - CrowdStrike's structural advantage drives the innovation that defines it CrowdStrike introduced FalconĀ® Guardian, the new AI Detection and Response (AIDR) solution delivering complete visibility and runtime enforcement from the endpoint, where AI agents execute and across the enterprise. Deployed across hundreds of millions of devices, CrowdStrike has more endpoint real estate than anyone. That structural advantage now defines AI agent security. "CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach," said George Kurtz, CEO and founder of CrowdStrike. "AI hasn't changed the attack, it has changed its speed. Governance alone can't stop an agent already in motion. Falcon Guardian turns policy into protection, stopping threats where AI agents execute and before they can cause harm." The Control Point for AI Security The industry is already seeing what happens when autonomy outpaces authority. As AI agents gain system-level privilege, the endpoint is where they reason, plan, and execute - accessing sensitive data and triggering downstream workflows with behavior indistinguishable from legitimate user activity. Posture tells you what could go wrong. Governance shrinks it. Only runtime stops what is going wrong. The endpoint is the only enforcement point with complete execution visibility, and where runtime security begins. Complete AI Runtime Security Guardian delivers the full spectrum of AIDR across the AI estate: data, models, prompts, agents, identities, infrastructure, and interactions. Protection extends from the endpoint to every surface where agents operate: cloud, SaaS, and browser. Only a single-sensor, unified architecture can cover this ground. With this release, Guardian introduces: * AI Agent Discovery and Inventory: The Falcon sensor discovers known and shadow AI agents across Windows and macOS, providing a live inventory of every running and dormant agent across the enterprise, who deployed it, and its security status. * Agent Runtime Visibility: Connects AI agent behavior directly to Falcon endpoint telemetry, establishing a causal chain from user prompt, identity, tool call, and skill use to every downstream system action, revealing the full agent execution graph. * Agent Access Controls: Defines which AI agents are permitted to run on managed endpoints, blocking unauthorized agents and translating governance policy into enforceable runtime controls. * Runtime Detection and Response: Detects attacks on agents and malicious agent behavior, reconstructs the full execution chain, and determines blast radius in real time, containing AI threats before they spread. * AI Gateway: Will provide a centralized control point for enterprise AI traffic across supported AI models and services, applying Falcon security context to enforce consistent visibility and policy across every AI communication, including MCP. * Falcon Complete for Guardian: Will deliver 24/7 expert-led detection, investigation, and response for AI agents. CrowdStrike's elite analysts assess intent, distinguish legitimate AI behavior from malicious activity, and stop threats before impact. * Falcon Adversary OverWatch for Guardian: Extends managed cross-domain threat hunting informed by frontline adversary tradecraft to AI agent activity, keeping organizations ahead of emerging AI threats. * Native Next-Gen SIEM Integration: Ingests AI agent data into FalconĀ® Next-Gen SIEM as first-party data, ready for correlation across identity, cloud, and SaaS, with retention built in. Competing AI tools have no SIEM, forcing a costly third-party bolt-on that gets more expensive as agent volume grows. AI's Cybersecurity Infrastructure Layer The Falcon platform is cybersecurity's infrastructure layer for AI adoption. Guardian is where that infrastructure meets the AI agent - securing every agent at runtime, across every surface where they operate.
[3]
Crowdstrike Unveils Falcon Guardian to Secure Ai Agents on the Endpoint At Runtime
CrowdStrike introduced Falcon Guardian, the new AI Detection and Response (AIDR) solution delivering complete visibility and runtime enforcement from the endpoint, where AI agents execute and across the enterprise. Deployed across hundreds of millions of devices, CrowdStrike has more endpoint real estate than anyone. Guardian delivers the full spectrum of AIDR across the AI estate: data, models, prompts, agents, identities, infrastructure, and interactions. Protection extends from the endpoint to every surface where agents operate: cloud, SaaS, and browser. With this release, Guardian introduces: AI Agent Discovery and Inventory: The Falcon sensor discovers known and shadow AI agents across Windows and macOS, providing a live inventory of every running and dormant agent across the enterprise, who deployed it, and its security status. Agent Runtime Visibility: Connects AI agent behavior directly to Falcon endpoint telemetry, establishing a causal chain from user prompt, identity, tool call, and skill use to every downstream system action, revealing the full agent execution graph. Agent Access Controls: Defines which AI agents are permitted to run on managed endpoints, blocking unauthorized agents and translating governance policy into enforceable runtime controls. Runtime Detection and Response: Detects attacks on agents and malicious agent behavior, reconstructs the full execution chain, and determines blast radius in real time, containing AI threats before they spread. AI Gateway: Will provide a centralized control point for enterprise AI traffic across supported AI models and services, applying Falcon security context to enforce consistent visibility and policy across every AI communication, including MCP. Falcon Complete for Guardian: Will deliver 24/7 expert-led detection, investigation, and response for AI agents. Falcon Adversary OverWatch for Guardian: Extends managed cross-domain threat hunting informed by frontline adversary tradecraft to AI agent activity, keeping organizations ahead of emerging AI threats. Native Next-Gen SIEM Integration: Ingests AI agent data into Falcon Next-Gen SIEM as first-party data, ready for correlation across identity, cloud, and SaaS, with retention built in.
Share
Copy Link
CrowdStrike introduced Falcon Guardian at Fal.Con 2026 in Las Vegas, a new AI Detection and Response solution that discovers, monitors and blocks unauthorized AI agents running on enterprise endpoints. The platform extends beyond governance to deliver runtime enforcement where AI agents execute, addressing the growing challenge of shadow AI and autonomous agent security across hundreds of millions of devices.

CrowdStrike unveiled Falcon Guardian at its Fal.Con 2026 conference in Las Vegas, launching a comprehensive AI Detection and Response solution designed to secure AI agents where they execute: on the endpoint at runtime
1
. The platform represents an expansion of Falcon AI Detection and Response, which became generally available in December and added endpoint runtime protection and shadow AI discovery capabilities at the RSAC Conference in March1
. This latest release introduces enforcement capabilities that transform governance policies into active protection mechanisms.Deployed across hundreds of millions of devices, CrowdStrike has positioned endpoint security as the critical control point for managing AI agents
2
. According to founder and CEO George Kurtz, "CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach. AI hasn't changed the attack, it has changed its speed. Governance alone can't stop an agent already in motion"1
. The endpoint serves as the location where AI agents reason, plan and execute code, making it the only enforcement point with complete execution visibility1
.Falcon Guardian delivers comprehensive AI agent discovery and inventory functionality across Windows and macOS machines
3
. The Falcon sensor identifies both known and shadow AI agents, whether running or dormant, creating a live inventory of every agent across the enterprise2
. The system logs who deployed each agent along with its security status, addressing the challenge of unauthorized AI tools spreading across corporate networks without IT oversight.The platform connects AI agent behavior directly to Falcon endpoint telemetry, establishing a complete causal chain from user prompt through identity, tool calls and skill invocations to every downstream system action
2
. This runtime visibility reveals the full agent execution graph, allowing security teams to understand exactly what an agent did to the system1
. Administrators can define which AI agents are permitted to run on managed endpoints, with anything not on the approved list getting blocked automatically1
.Guardian's detection and response capabilities flag both attacks aimed at AI agents and agents misbehaving on their own
1
. The system reconstructs the full execution chain and calculates blast radius in real time while an incident is still in motion, containing AI-driven threats before they spread2
. This approach addresses the speed challenge posed by autonomous agents that can trigger downstream workflows with behavior indistinguishable from legitimate user activity.Related Stories
Two components of Falcon Guardian are scheduled for later release. The AI gateway will sit in front of enterprise AI traffic and apply Falcon policy to every call, including Model Context Protocol connections
1
. Currently in pre-beta, the gateway will provide a centralized control point for AI traffic across supported models and services, going generally available next quarter2
. Falcon Complete for Guardian, delivering 24/7 expert-led detection, investigation and response for AI agents, is due later this quarter2
.Managed threat hunting through Falcon Adversary OverWatch Cross-Domain is available today, extending cross-domain threat hunting informed by frontline adversary tradecraft to AI agent activity
1
. Agent telemetry lands in Falcon Next-Gen SIEM as first-party data with retention included, ready for correlation across identity, cloud and SaaS activity1
. CrowdStrike notes that competing AI security tools ship no SIEM of their own, forcing customers to add a third-party product whose cost climbs as agent volume grows1
.Guardian represents the second major product CrowdStrike released at Fal.Con 2026, following Falcon IQ which launched on the conference's opening day Monday
1
. The company positions the Falcon platform as cybersecurity's infrastructure layer for AI adoption, with Guardian serving as the intersection where that infrastructure meets the AI agent2
. Protection extends from the endpoint to every surface where agents operate: cloud, SaaS and browser, covering the full spectrum of AI Detection and Response across data, models, prompts, agents, identities, infrastructure and interactions2
.Summarized by
Navi
[2]
17 Mar 2026ā¢Technology

31 Aug 2026ā¢Technology

01 Sept 2026ā¢Technology

1
Policy and Regulation

2
Technology

3
Technology
