American cybersecurity firm CrowdStrike has launched its new system, SafeMind, developed in collaboration with Nvidia. This system integrates offensive and defensive AI models in a closed-loop, where one model seeks attack vectors while the other formulates and tests detection rules.

The announcement took place on September 1 at the Fal.Con 2026 conference in Las Vegas. SafeMind will operate natively within the CrowdStrike Falcon platform.

Initially, the system features two specialized models:

  • Red Tempest simulates attacker behavior and identifies potential compromise paths;
  • Blue Solano analyzes data, generates detection rules, and assesses their effectiveness.

These models function alongside agent wrappers—software frameworks that provide AI with context, tools, and rules for executing multi-step tasks.

Nvidia's description likens the system to an ongoing confrontation between red and blue teams. Red Tempest conducts attacks in a controlled environment, Falcon records telemetry, and the defensive wrapper identifies gaps and formulates new detection rules. The attack is then repeated with the updated defenses in place.

Source: Nvidia.

SafeMind's defensive framework is based on Nvidia's open-weight models, Nemotron, which have been further trained using CrowdStrike's cyber datasets.

Nemotron 3 Ultra orchestrates the defensive agents, reconstructing attack sequences, planning actions, and triggering necessary tools. The fine-tuned Nemotron 3 Super serves as a specialized model for crafting and refining detection rules.

To configure this model, CrowdStrike employed additional training on cybersecurity materials, including supervised fine-tuning and reinforcement learning. This training set comprised 9,349 examples of rule generation and correction across 59 types of programmatically generated errors.

CrowdStrike noted that the data for SafeMind also includes Falcon telemetry, proprietary threat intelligence, annotations from the Falcon Complete MDR service, and materials accumulated over 15 years of incident response. According to Nvidia, using open-weight models allows organizations to further train them on internal data without sharing that information with external AI providers.

The cloud infrastructure CoreWeave also plays a role in the training and inference processes of SafeMind.

Testing Results

In internal assessments, CrowdStrike found that SafeMind achieved a 29% higher threat detection rate, six times faster issue resolution, and a 99% reduction in costs associated with detection and remediation compared to selected advanced models and open-source solutions.

Nvidia separately detailed a more comprehensive test of the defensive framework in a controlled environment modeled on its own computing infrastructure.

In a backtest, an average of 16.5% of the rules created by Nemotron 3 Ultra with standard agent wrappers detected a recorded attack. After integrating a specialized wrapper, retrained with Nemotron 3 Super, contextual information, tools, and automated validation, this figure rose to 41.9%.

Nvidia emphasized that the improvement pertains to the entire optimized framework, not just the replacement of a single AI model.

Source: Nvidia.

In live-fire tests, five out of eleven detection rules created by the open framework triggered at least once during eight new attacks, yielding a 45% success rate. In contrast, the comparable advanced system achieved a success rate of 10 out of 35, or 29%.

After further assessment, three detections from the open framework received the highest gold rating, collectively covering all eight attacks. The comparable system had no such rules. The authors cautioned that the trial only covered one family of scenarios and small sets of detections.

AI Laboratory

CrowdStrike also announced the establishment of the Cyber Superintelligence Lab, which brings together the company's experts in artificial intelligence, offensive security, and incident response. Bartley Richardson, who was appointed CrowdStrike's Chief AI and Autonomous Systems Officer in June, heads the lab.

Nvidia is partnering with the lab to develop AI and plans to invest $100 million over the next five years.

Additionally, CrowdStrike introduced Falcon IQ, designed to automate tasks related to risk assessment, prioritization, and remediation, utilizing over 50 agents. The company also expanded Falcon Guardian to enhance protection for AI agents while they operate on endpoints.

In August, it was noted that OpenAI and 127 other organizations, including CrowdStrike, signed an open letter urging for urgent enhancements to cybersecurity, citing concerns that AI-driven attacks will become more frequent and sophisticated in the coming months.