CrowdStrike launches SafeMind security AI models with Nvidia, opens Cyber Superintelligence Lab
CrowdStrike unveiled SafeMind, a family of security-specific AI models built with Nvidia, and opened a Cyber Superintelligence Lab at Fal.Con, claiming faster threat detection and remediation.
SafeMind launches with two models. Red Tempest is the offensive model, built to emulate AI-driven adversaries and run advanced attack scenarios against an environment. Blue Solano plays defense, applying containment measures that CrowdStrike responders use on live incidents. The harnesses run both in a closed loop that pits one model against the other so each improves, and they also drive frontier and open-source models from other providers. SafeMind will operate natively in the CrowdStrike Falcon platform, with standalone access handled through the Project QuiltWorks program established in April.
CrowdStrike built the models on Nvidia's open Nemotron family and trained them on its own material, including Falcon sensor telemetry, threat intelligence, event annotations from Falcon Complete analysts, and 15 years of incident response fieldwork. CoreWeave Inc. supplied cloud capacity for training and inference. CrowdStrike said SafeMind posted a 29% higher detection rate, remediated six times faster end to end, and cut detection and remediation costs by 99% when measured against leading frontier models and open-source baselines. The company did not name the comparison models or describe the methodology behind the figures.
"The future of cybersecurity won’t be defined by AI that simply identifies threats, it will be defined by AI that defeats them," said George Kurtz, founder and chief executive of CrowdStrike. He said SafeMind brings offensive and defensive models together in a system trained on CrowdStrike’s unique cyber data, finding weaknesses and strengthening protection.
Nvidia is the AI design partner on the work. Nvidia chief executive Jensen Huang said cyber defense would rank "among the most compute-intensive applications of AI," describing the coming years as a contest between attackers scaling up with AI and defenders using it to widen detection and response. CoreWeave chief executive Michael Intrator said few environments test what AI "can do in production, at scale" as hard as security.
The models come out of the Cyber Superintelligence Lab, which puts CrowdStrike’s AI researchers, offensive operators and incident responders under a single charter, led by Bartley Richardson, chief AI and autonomous systems officer. Richardson called the models "the start of a new chapter for cyberdefense," noting that CrowdStrike owns the entire stack, from sensor to harness to model. The lab runs on telemetry collected from Falcon sensors deployed in customer environments, reporting from endpoints, identity systems, cloud workloads, data stores and Falcon Next-Gen SIEM at trillions of events a day.
CrowdStrike also extended its Falcon platform across Google Cloud’s enterprise AI ecosystem with four additions. Falcon Guardian, the AI detection and response product launched at the show, now runs through Google Agent Gateway, watching for prompt injection, data leakage and malicious activity in AI applications at runtime. Falcon MCP feeds threat intelligence into Gemini Enterprise workflows, Charlotte AI brings natural-language investigation and response into the same environment, and Falcon Shield covers Google Cloud’s Agent Registry.
SiliconANGLE Media co-founder and chief analyst Dave Vellante said that while the world’s most powerful general-purpose models from OpenAI and Anthropic were not built for defenders, attackers can effectively use them to identify attack vectors. He cited the Mythos moment and Hugging Face hack as examples of novel threats that general-purpose frontier models were not designed to defend, and said CrowdStrike’s partnership with Nvidia is creating a purpose-built frontier model specifically for defenders.