Enterprises have a new entry in cost of goods sold that did not exist five years ago, and Daniel Bernard says it is tokens.
The standard answer to a hard AI problem is to rent the largest model available. The argument these two make is that a model big enough to reason its way through an attack is too expensive to leave running on every machine all the time, which is the only way security works.
"You don't treat a specialized illness with a generic pill."
Bernard is CrowdStrike's chief business officer. Boitano runs Nvidia's enterprise business, and the models CrowdStrike launched that morning are built on weights his company published.
I listened to the full interview so you can skip it. 17 minutes of audio, 10 minutes of reading.
Here are the 8 takeaways that matter.
👤 Guests: Daniel Bernard, chief business officer of CrowdStrike, and Justin Boitano, who leads Nvidia's enterprise business as its vice president of enterprise AI
🎙️ Hosts: John Coogan and Jordi Hays, who present TBPN live on X and YouTube every weekday
📰 Published: 1 September 2026 on YouTube (TBPN)
🔴 YouTube | 🟣 Apple Podcasts | 🔗 Show notes | ⏱️ 17 min | ✅ Time saved: 7 min
Key Takeaways
The claimed advance is the harness around the model, not the model itself One harness is tuned for attack, another for defense, and each reasons and calls tools on its own
CrowdStrike says it never evaluated an open model other than Nvidia's
Raw intelligence is commoditizing, and the defensible asset is the incident data around it Years of human analyst decisions and frontline breach response is what the models are tuned on
Frontier models alone are too expensive to run always-on, and generic open models are too vague
Tokens have become a cost-of-goods line that enterprises are budgeting against for the first time
The defender's advantage is knowing its own code and configuration, which the attacker does not
Nvidia says it is not a cybersecurity company and does not intend to become one
1. Safemind, and the harness
The pair opened on the launch. Bernard introduced himself as CrowdStrike's chief business officer — "You can call me DB, chief business officer at CrowdStrike." Boitano followed with "Justin Boitano. I lead the enterprise business at Nvidia."
The product is Safemind, and the claim on it is a first. "Cyber security's first frontier models and harnesses custom for cyber." The slogan attached to it: "Made by Cyber for Cyber."
It is built on Nvidia's open weights. "We built this on Nemotron." The pitch as delivered: "It's bending the curve of Frontier AI and the advantage of defenders."
The interesting part, on their account, is not the model. "I think the big news too is that the frontier is in the harness." Then: "It's not really about just the model. It's the entire system."
Two harnesses, tuned in opposite directions. CrowdStrike tuned one harness for attack and one for defense: "And the harness is the thing that's going to sit there and reason and call tools and work through solving the problem, whether it's finding vulnerabilities or finding and writing detections."
Nvidia is running the same approach on itself. "Jensen talked a lot about how we're deploying it internally. We're building the digital twin of our environments." That twin is used to run attack and defense simulations against Nvidia's own estate
Benchmarks were the design target, not a marketing afterthought. The stated goal: "Like, the goal here that we both set out to achieve is this thing needs to be better, faster, and more cost effective than the other open source and frontier models of the day." The scope is deliberately narrow — "We're not here to change the world of science, math" — because "We're here to stop breaches."
2. Why they picked Nemotron
A host asked how they chose Nemotron when there are many open models to build on.
The answer was that there was no selection process. "Look. There's a really, really close relationship between CrowdStrike and Nvidia." On alternatives: "So that we didn't even look at anybody else"
The reasoning runs through the hardware. "And who do we get our GPUs from? The creators of them."
The second reason offered was a shared position on open weights. Nvidia's public position, they said, is that the world needs open source and needs choice, and that was described as a cultural fit as much as a technical one
The partnership was returned in public from the Nvidia side. "I think Jensen said on stage, CrowdStrike is our number one partner in cyber security."
What Nvidia says it gets in return is visibility it does not have. "They have the perception system that really understands what's going on in customer environments."
What Nvidia says it gives is the raw material rather than a finished product. "But we put out there the data sets, the open techniques and the weights, so they can be customized by CrowdStrike." The intended result is that CrowdStrike builds its own cyber domain intelligence and sells tokens to secure enterprises on top of an open foundation
3. Research, not just the GPUs
Asked whether the partnership goes further than handing over model weights, the answer was that most of the current work is research on the harness.
The lab publishes what it finds. Boitano pointed at a harness technique Nvidia released a few weeks earlier and tested on a public reasoning benchmark
The result claimed for it is the whole range. "We could take a frontier model from 30% accuracy to a 100% accuracy." He called the surprise of the past month people showing what a different harness can do against the benchmark's own standard one
The research is shared rather than licensed. He said the two firms publish it openly together to advance the industry
Nvidia's framing of the division of labor was explicit. "And ultimately, we're not a cyber company, they're the cyber company." CrowdStrike has the domain knowledge and the view into customer environments; Nvidia supplies the compute and the model research
Bernard described how every Nvidia meeting opens and closes. "How can we help you grow? It's the first question. It's the last question." He added: "It's from Jensen all the way to the person at the front desk."
The trade going the other way is distribution. "We're bringing them to over a 100,000 customers" plus everyone on the conference floor
4. What CrowdStrike brings
A host asked how much of the work is designing reinforcement-learning environments rather than collecting data.
Bernard's answer started by devaluing the model layer. "Intelligence, I believe, is really becoming somewhat commoditized." His alternative: "I think what's really real in this next chapter of AI is how you contextualize based off of specific situations."
The asset he named is the record of what human analysts actually did. CrowdStrike has managed detection and response data from its Falcon Complete analysts, covering the actions they took across customer environments over years, plus the work of frontline incident responders who stopped breaches
That record is what gets curated and fed into the harness, producing what he called an iterative learning loop
He expects the family to grow rather than the single model to improve. "Like, where this all goes, in my opinion, is you'll see more models and more harnesses from us in the Safemind family that solve different security use case problems."
His differentiator against the rest of the market is who built it. "You know, CrowdStrike is cybersecurity built by and for cybersecurity practitioners."
5. The new COGS line
The hosts asked how buyers are being taught to think about the cost of always-on AI security.
The harness is supposed to make the routing decision, not the customer. Bernard said it should be able to use the best of the frontier models and the best of the open ones, reason through a problem, and work out which model each part of it needs
The default is the cheap model and the exception is the expensive one. "So the Safemind models are probably the default" — with frontier reserved for genuinely novel problems. That, he said, gives the best cost across code, binaries and configurations
In production the vulnerability is often not in the code. "But in a production environment, it's really about also the configurations in your running environment."
Customers have already rejected the all-frontier approach on price. "We've heard it loud and clear from customers that just going one direction with Frontier Labs is just too cost prohibitive." Generic open source does not solve it either: it is "a compass that's spinning in a circle."
The budget problem is structural and new. "We have this new line item in COGS that's called tokens." And: "Five years ago, it didn't exist." Nothing else came out of the budget to make room — cloud spend and software spend both went up
The forecast is more spending and more scrutiny at once. "And I think every enterprise is planning to spend more on AI next year, but at the same time trying to be a lot more efficient."
6. Battleships and drones
Asked about the economics of the fight rather than the benchmarks, Bernard reached for a pricing framework.
He put it in price and quantity terms. "Well, the way I think about it is prices I mean, value creation is always measured economically in a p and a q." His diagnosis: "is the q is going out of control."
The reason is surface area. "There's more attack surface than ever before." More surface means more opportunity, and "And they don't have to be right every time." Then: "They just need to be right once."
Asked whether 2026 will look like the attackers' best year, he took the other side. "Going on a limb here." His claim: "Safemind changes the curve."
He conceded the position it starts from. "But I think sort of until like this time, it's sort of disproportionately advantaged to adversaries." Then: "And I think it's time to change the tide."
The cost comparison Boitano drew was military. Running attack paths through frontier models is expensive — "Think of it like a battleship, right?" — and the answer is: "And then what you want to do is you want to help defenders have the equivalent of drones, like super low cost models that they can run everywhere."
The defender's structural advantage is knowledge of its own estate. "And their advantage is also, they know the code, they know the configs that they run, the people coming in from the outside don't." That is what makes cheap internal reconnaissance worth running continuously
7. Not a generic pill
A host suggested CrowdStrike can push cyber capability to the frontier without the pressure a consumer lab faces from hundreds of millions of users.
Bernard reframed the pressure rather than accepting the contrast. "Well, we have the pressure of lots and lots of big numbers of attack surfaces. Those are endpoints, identities, cloud workloads." Every one of them needs protecting and none can be allowed to fall over
His summary of the demand picture was unusually direct. "So like, the threat's real, the need is there, the budget's there, but the market's asking for something better and something different."
The case for a specialist model was a medical one. "You don't treat a specialized illness with a generic pill." Then: "You need to have the right dose, the right therapy."
8. Seven processors a rack
Nvidia stated the boundary of its own business. "We're an accelerated computing company. We're not a cyber security company." Partnerships of this shape exist so that a specialist solves the specialist problem
Boitano suggested the frontier labs face the same choice. He said they are probably asking themselves where they want to own the advantage and where they want to partner, and that specialized cyber intelligence is a place to partner
Asked about diversity in the chip fleet, he answered on breadth of workload. "So we have to accelerate everything." Different models need different capabilities, whether the work is prefill, inference or decode
The unit he described is the rack, not the chip. "And then ultimately, as Jensen always talks about, we're building rack scale infrastructure with seven processors." The metric he named is "the best token efficiency per watt"
Bonus Insights
Bernard said internal nicknames are "super popular" at CrowdStrike, and that "There's only one DB."
CrowdStrike is itself a large enterprise facing the same threats as its customers, which Bernard offered as the reason its own security decisions are worth anything to a buyer
A host raised a chip deal reported the day before, involving a large GPU cluster for a partner, as an example of how quickly the compute market is moving. Boitano's only comment was that they are busy
Their bottom line is that the defensible product in AI security is not the model but the pairing of a cheap, specialized model with a harness tuned on years of real incident data, priced so that it can be left running everywhere at once.
Products, Companies & Tools Mentioned
CrowdStrike (Launched Safemind, its family of cyber-specific models and harnesses, and says its Falcon Complete detection-and-response data is what makes them worth using)
Nvidia (Supplied the open Nemotron weights, data sets and techniques, publishes the harness research, and says CrowdStrike is its number one partner in cybersecurity)
Lambda (Named by a host as the counterparty on a large GPU cluster deal announced the previous day)
Books & Resources Mentioned
ARC-AGI (The public reasoning benchmark Boitano cites, where he says Nvidia's harness research took a frontier model from 30% to 100% accuracy)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

