CrowdStrike has unveiled SafeMind, a new agentic cybersecurity system built with NVIDIA Nemotron models and designed to continuously test and strengthen enterprise defenses. Announced at Fal.Con 2026 in Las Vegas, SafeMind combines offensive and defensive AI models in a closed loop where one searches for viable attack paths and the other develops ways to stop them.
SafeMind was developed by CrowdStrike’s Cyber Superintelligence Lab in collaboration with NVIDIA and will operate natively within the CrowdStrike Falcon platform. The system launches with two specialized models: Red Tempest, an offensive red-team model designed to emulate advanced attacks, and Blue Solano, a defensive model intended to identify weaknesses and deploy protections used by real-world defenders. CrowdStrike says NVIDIA Nemotron open models provide the foundation for its defensive AI.
Rather than using a general-purpose model alone, CrowdStrike has combined its models with specialized agent harnesses that determine how the AI operates within cybersecurity workflows. NVIDIA Nemotron 3 Ultra handles defensive orchestration, while a fine-tuned Nemotron 3 Super powers a specialist responsible for generating and repairing detection rules. CrowdStrike says its models have been post-trained using Falcon telemetry, threat intelligence, managed detection and response annotations, and knowledge accumulated from 15 years of incident-response work.
The central idea is to make offensive and defensive systems improve one another. In testing, a red-team agent attempts to find and execute an attack path inside a controlled environment, while the defensive side monitors activity through Falcon sensors, creates potential detections, validates them and promotes successful defenses. The process can then repeat as the offensive side adapts, creating an automated version of the continuing contest between attackers and defenders.
NVIDIA and CrowdStrike evaluated the approach inside an isolated digital environment modeled on NVIDIA’s accelerated computing infrastructure. The offensive harness divides its work among Recon, Assault and Compromise agents, while the defensive system uses multiple stages for grounding telemetry, generating detection logic, checking artifacts and independently reviewing results. The companies say the goal is to turn newly discovered weaknesses into tested protections without requiring every step to be handled manually.
CrowdStrike also published internal performance claims for Blue Solano. Its September 1 announcement says the defensive model delivered greater accuracy than the leading proprietary frontier model it tested while operating at substantially lower cost. NVIDIA’s technical breakdown separately reports a 13% accuracy advantage at 97% lower cost for the evaluated configuration, while CrowdStrike’s broader materials cite cost savings reaching 99% in other internal comparisons. These figures come from company-run evaluations and have not been independently benchmarked.
SafeMind is not limited to CrowdStrike’s own models. The company says its agent harnesses can also work with other frontier and open-source models, allowing customers to choose different underlying AI systems while retaining CrowdStrike’s cybersecurity workflows. Standalone access to SafeMind models and harnesses is planned through CrowdStrike’s Project QuiltWorks program.
CrowdStrike additionally announced Falcon IQ, which uses agentic automation to handle security assessment, prioritization and remediation workflows. NVIDIA says Falcon IQ brings together more than 50 agents as a coordinated workforce and operates through Charlotte AI AgentWorks, CrowdStrike’s no-code platform for creating custom security agents. The companies are positioning these systems as a response to the increasing speed at which AI can be used offensively.
CrowdStrike says AI-enabled attacks increased 89% over the past year, while the fastest observed eCrime breakout time has fallen to 27 seconds. Those figures underpin the company’s argument that defensive operations increasingly need to work at machine speed rather than waiting for analysts to manually investigate every stage of an intrusion.
The collaboration expands an existing relationship between the two companies. Earlier in 2026, CrowdStrike announced wider support for NVIDIA’s agent technologies and Nemotron models within its managed detection and response services and Charlotte AI AgentWorks. SafeMind takes that partnership further by applying the models to a continuous offensive-versus-defensive system rather than primarily assisting analysts with individual investigations.
SafeMind will ultimately be judged by how effectively that automated loop performs in real enterprise environments. For now, CrowdStrike and NVIDIA are presenting it as a shift from AI that primarily summarizes or identifies security problems toward agents capable of actively testing defenses, developing countermeasures and repeatedly validating whether those protections work.
