CrowdStrike Adds Platform to Secure AI Agents Running on Endpoints

CrowdStrike today at its Fal.Con 2026 conference launched the Falcon Guardian platform that leverages a sensor to provide a live inventory of every active and dormant artificial intelligence (AI) agent running on a Windows or macOS endpoint. At the same time, CrowdStrike is launching Falcon Complete for Guardian, a managed service based on Guardian that..

Security Boulevard
安全新闻终端安全人工智能安全远程代码执行

CrowdStrike today at its Fal.Con 2026 conference launched the Falcon Guardian platform that leverages a sensor to provide a live inventory of every active and dormant artificial intelligence (AI) agent running on a Windows or macOS endpoint.

At the same time, CrowdStrike is launching Falcon Complete for Guardian, a managed service based on Guardian that combines AI agent and professional human cybersecurity expertise, and a Falcon Adversary OverWatch for Guardian service that provides cross-domain threat hunting by tracking adversary tradecraft and AI agent activity.

AJ Shipley, chief product officer for CrowdStrike, said Falcon endpoint security software already runs on hundreds of millions of devices. Falcon Guardian leverages that structural advantage to secure AI agents where they execute in a way that also provides complete visibility into interactions with AI models and other AI agents, he added.

Specifically, the Falcon sensor discovers known and shadow AI agents and then uses the telemetry data collected to establish a causal chain of behavioral relationships, said Shipley.

Access controls are then applied to enforce policies and block unauthorized agents from executing a task, while an AI gateway provides a control plane through which policies can be applied to every agentic action and workflow.

A runtime detection and response capability then makes it possible to detect attacks on agents and malicious agent behavior, reconstruct the full execution chain, and determine blast radius in real time.

Finally, CrowdStrike has integrated Falcon Guardian with its Next-Gen SIEM Integration, which also ensures the data collected is first-party data to streamline analytics workflows.

It’s not clear to what degree cybersecurity teams are moving to secure AI agents. In many instances, organizations have deployed AI agents in the name of increasing productivity without considering all the cybersecurity implications. However, in the wake of multiple incidents involving rogue AI agents, there is now a greater appreciation for the potential havoc that might be wrought.

Hopefully, cybersecurity teams will be able to secure many of the AI agents that have been deployed before there are multiple incidents. The challenge is that the inherent risks are significantly higher because AI agents are executing tasks. A stolen credential could be used to commandeer that workflow or, worse yet, AI agents created by malicious actors could be inserted into a workflow.

Like it or not, thousands of AI agents will soon be strewn across the enterprise. Cybersecurity teams will need to decide to what degree they can secure AI agents operating at machine speed themselves versus relying on a managed service provider (MSP) that has more resources and expertise. The issue, of course, is that adversaries are not going to wait for that decision to be made before launching attacks against what are now a set of rich targets that at this point are largely undefended.