Las Vegas: CrowdStrike has introduced Falcon Guardian, a new AI Detection and Response (AIDR) solution designed to provide complete visibility and runtime enforcement from the endpoint, where AI agents execute, and across the enterprise.
The announcement was made at Fal.Con 2026 in Las Vegas.
With Falcon Guardian, CrowdStrike is positioning the endpoint as a key control point for securing AI agents as enterprises increasingly deploy autonomous systems across their environments.
The company said its structural advantage comes from its Falcon sensor being deployed across hundreds of millions of devices, giving it extensive endpoint visibility.
“CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach,” said George Kurtz, CEO and founder of CrowdStrike.
“AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion. Falcon Guardian turns policy into protection, stopping threats where AI agents execute and before they can cause harm.”
The Endpoint as the Control Point for AI Security
Falcon Guardian is built around the premise that the endpoint is a critical enforcement point for AI agent security. As AI agents gain system-level privileges, they can reason, plan and execute actions on endpoints while accessing sensitive data and triggering downstream workflows.
According to CrowdStrike, AI agent activity can exhibit behavior that is indistinguishable from legitimate user activity. While posture management can identify what could go wrong and governance can reduce risk, runtime security is required to stop malicious activity while it is occurring.
Falcon Guardian provides runtime security at the point where AI agents execute, with the endpoint offering execution visibility that enables security teams to understand and respond to agent activity.
Falcon Guardian Delivers AI Runtime Security Across the Enterprise
CrowdStrike said Falcon Guardian delivers the full spectrum of AI Detection and Response across the AI estate, covering data, models, prompts, agents, identities, infrastructure and interactions.
The protection extends from endpoints to other surfaces where AI agents operate, including cloud, SaaS and browsers. CrowdStrike said a single-sensor, unified architecture is required to provide visibility and security coverage across these environments.
With the launch, Falcon Guardian introduces several capabilities aimed at discovering, monitoring, controlling and responding to AI agent activity.
- AI Agent Discovery and Inventory
The Falcon sensor can discover known and shadow AI agents across Windows and macOS. With Falcon Guardian, organizations receive a live inventory of running and dormant AI agents across the enterprise, including information on who deployed them and their security status.
- Agent Runtime Visibility
Falcon Guardian connects AI agent behavior directly to Falcon endpoint telemetry. This establishes a causal chain linking the user prompt, identity, tool call and skill use to downstream system actions.
The capability is designed to reveal the complete agent execution graph, giving security teams visibility into how AI agents interact with systems and services.
- Agent Access Controls
With Falcon Guardian, organizations can define which AI agents are authorized to run on managed endpoints. Unauthorized agents can be blocked, allowing governance policies to be translated into enforceable runtime controls.
- Runtime Detection and Response
Falcon Guardian also provides runtime detection and response capabilities for AI agents. The solution is designed to detect attacks targeting agents as well as malicious agent behavior.
It reconstructs the full execution chain and determines the potential blast radius in real time, enabling AI-related threats to be contained before they spread.
- AI Gateway
CrowdStrike said its AI Gateway will provide a centralized control point for enterprise AI traffic across supported AI models and services.
The AI Gateway will apply Falcon security context to provide consistent visibility and policy enforcement across AI communications, including Model Context Protocol (MCP).
- Falcon Complete for Guardian
Falcon Complete for Guardian will provide 24/7 expert-led detection, investigation and response for AI agents.
CrowdStrike said its analysts will assess intent, distinguish legitimate AI behavior from malicious activity and stop threats before they cause an impact.
- Falcon Adversary OverWatch for Guardian
Falcon Adversary OverWatch for Guardian extends managed cross-domain threat hunting to AI agent activity.
The capability will use frontline adversary tradecraft to help organizations identify emerging threats targeting AI agents and stay ahead of evolving attack techniques.
Native Next-Gen SIEM Integration
Falcon Guardian also integrates natively with Falcon Next-Gen SIEM, allowing AI agent data to be ingested as first-party data.
This data can be correlated across identity, cloud and SaaS environments, with retention built into the platform. CrowdStrike said competing AI tools lack SIEM capabilities and require third-party integrations, which can add costs as AI agent volumes increase.
Falcon Guardian as an AI Cybersecurity Infrastructure Layer
CrowdStrike described its Falcon platform as a cybersecurity infrastructure layer for enterprise AI adoption.
Falcon Guardian brings that infrastructure directly to AI agents, with the objective of securing agents at runtime across the different surfaces where they operate.
The company said the endpoint is central to this approach because it is where AI agents execute and where security teams can obtain visibility into their runtime behavior.
With Falcon Guardian, CrowdStrike aims to extend its endpoint security architecture into the growing AI agent environment, combining AI agent discovery, runtime visibility, access controls, detection and response, threat hunting and SIEM integration within its Falcon platform.







