CrowdStrike launches Falcon Guardian, AIR Security raises $50M for AI agent security
CrowdStrike launched Falcon Guardian to police AI agents; AIR Security raised $50M for an agent firewall.
Falcon Guardian is the expanded successor to Falcon AI Detection and Response, which went generally available in December and added endpoint runtime protection and shadow AI discovery at the RSAC Conference in March. This time, CrowdStrike added enforcement. The company argues the endpoint is where an agent reasons, plans and runs code, making it the only place with a complete view of what the agent actually did. The sensor inventories known and shadow agents across Windows and macOS machines, including running and dormant ones, and logs who deployed each one along with its security status. Guardian ties agent behavior to endpoint telemetry, building a chain from a user’s prompt through the identity used, tools called and skills invoked, down to the agent’s subsequent actions on the system. Administrators can name allowed agents, and anything not on the list gets blocked.
Detection and response work off the same telemetry. Guardian flags attacks aimed at agents as well as agents misbehaving on their own, then reconstructs the execution chain and calculates blast radius while an incident is still in motion. “CrowdStrike pioneered EDR by making the endpoint the control point for stopping attacks. AI demands the same approach,” founder and Chief Executive George Kurtz said. “AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion.”
Two parts of Guardian are not shipping yet. AI Gateway will sit in front of enterprise AI traffic and apply Falcon policy to every call, including Model Context Protocol connections; CrowdStrike said it is in pre-beta and goes generally available next quarter. The managed detection and response tier, Falcon Complete for Guardian, is due later this quarter, while managed threat hunting through Falcon Adversary OverWatch Cross-Domain runs today. Agent telemetry lands in Falcon Next-Gen SIEM as first-party data with retention included.
CrowdStrike used the event to frame AI detection and response as a category rather than a single product, according to President Michael Sentonas, who noted the company’s Cyber Superintelligence Lab built on purpose-built models trained on its own threat data. The “2026 Global Threat Report” found the average eCrime breakout time has fallen to 29 minutes, with the fastest intrusion clocked at 27 seconds. Sentonas said boards are worried and asking whether security teams are doing enough. Field chief technology officer Cristian Rodriguez said early adopters that moved first are now returning for visibility and governance, with AI sprawl a real problem. Box Inc. Chief Information Security Officer Heather Ceylan said the attack surface is the same but agents move at machine speed, so detections need to be faster and visibility real-time.
AIR Security, founded earlier this year by CEO Yair Saban and CTO Niv Hoffman, both veterans of Israeli military intelligence unit 8200, sits in the path between agents and the third-party skills, plugins and Model Context Protocol servers they reach for. The platform maps agents across endpoints, cloud accounts and SaaS applications, then re-checks the components those agents depend on. It blocks untrusted tools and injected instructions at runtime and runs a marketplace of pre-cleared add-ons. Company research found more than 17,800 public AI add-ons with 6.7 million installations drew instructions from outside sources nobody had verified, and AI skills impersonating Anthropic and OpenAI could run arbitrary code. About 27% of add-ons and skills found online get filtered out. More than 20 companies use the platform, roughly a quarter of them large enterprises, with strongest demand in financial services and pharmaceuticals.
The $50 million came in two rounds, both closed within the company’s first six months. Sequoia Capital led the first at $10 million and Greenoaks Capital Partners led the $40 million that followed. Swish Ventures and Netz Capital also invested, along with angel backers including Wiz co-founder Yinon Costica and Anne Neuberger, former White House deputy national security adviser. “Every enterprise has a firewall protecting its network,” Saban said. “Now they need one protecting their AI agents.” The company is based in New York and will spend the new money on hiring researchers and building sales in the U.S. and Europe.