CrowdStrike put 270 PhDs into a new cyber research lab and shipped two AI models out of it on Tuesday morning: an attacking model called Tempest and a defending one called Solano, both trained with Nvidia on its open Nemotron weights.
Most security vendors are selling AI as a way to watch what employees type into a chatbot. George Kurtz's pitch is that the AI agents themselves are now the thing on the network that has to be watched, with the same instrumentation CrowdStrike built for laptops fifteen years ago.
"Because they're like a bunch of drunk interns they put on your network."
Kurtz co-founded CrowdStrike and runs it, says his firm was called in to help OpenAI work through the Hugging Face incident, and had delivered the keynote at his own company's conference a few hours before sitting down for this interview.
I listened to the full interview so you can skip it. 20 minutes of audio, 13 minutes of reading.
Here are the 11 takeaways that matter.
👤 Guest: George Kurtz, co-founder and chief executive of CrowdStrike, who gave the opening keynote at the company's Fal.Con conference that morning
🎙️ Hosts: John Coogan and Jordi Hays, who present TBPN live on X and YouTube every weekday
📰 Published: 1 September 2026 on YouTube (TBPN)
🔴 YouTube | 🟣 Apple Podcasts | 🔗 Show notes | ⏱️ 20 min | ✅ Time saved: 8 min
Key Takeaways
CrowdStrike is selling detection and response for AI agents, not for the people using them Every tool call, every agent spawn, every prompt and every network connection is recorded against a named identity
The cost of an attack, not the knowledge behind it, is what now limits an attacker Kurtz says a hacktivist, a criminal group and a nation state are equivalent once they all have agents
Frontier-grade AI reached attackers before it reached defenders, because defenders got the refusals
AI has found more vulnerabilities and found them faster, but has invented no new way to hack
A model cannot stop a breach, because a model is not sitting in the path of the traffic Deterministic blocking still has to make the call once, in line, and be right
Guardrail-stripped open models are downloadable today and will write a ransomware kit on request
CrowdStrike charges for AI security by the token, drawn down against an existing license
The customers most exposed are utilities, hospitals and NGOs, not the Fortune 500 Kurtz says Fortune 10 chief executives called him directly after the Mythos disclosures
1. Guardian, for agents
The interview opened on what CrowdStrike announced in the keynote an hour or so earlier.
The first product is Falcon Guardian, which Kurtz places in a category he calls AIDR — detection and response aimed at AI agents rather than at people or machines. He framed it as the same thing CrowdStrike did for endpoint detection and response, applied to a new kind of user
Agents are the harder case because of what they can reach. They have access to data, to compute and to networking resources, and Kurtz said they do bad things: "Because they're like a bunch of drunk interns they put on your network."
The product was built with input from CrowdStrike's largest customers, and he named Amazon as one of them
Kurtz's commercial argument is that security is what unblocks AI spending rather than what slows it. "Customers for the first time wanna go faster somewhere and they need security to go faster as opposed to a brake pedal." His summary: "It's actually a gas pedal."
Asked how this maps to the company's founding thesis, he said the original product was built on the same idea under an older name: "When I first started the company, it was really based upon what we called AI, but it was machine learning back then." The point then, as now, was using algorithms to predict whether something was good or bad
2. The lab, and two models
The second announcement was a research lab built with Nvidia. "And we actually partnered with Nvidia to create really the first, what I would call the agentic security platform" — one, he said, "That is focused on a red, a blue, and a harness that continually learns from each other."
The models are named, and they are a pair. "But the red Tempest, which is the name of that model, and the blue Solano, which is the defensive model, are part of the Safemind system." Safemind itself is the harness — the surrounding system that reasons and calls tools
The models are built on Nvidia's Nemotron open weights, then fine-tuned in the model creation and post-training stages with Nvidia
The claimed advantage is the training data rather than the architecture. "So, again, our models are specifically trained on our data, which we think is a huge advantage."
Both models and the harness will be available inside the Falcon platform, and a separate trusted-access program lets some customers use the models directly
The hosts pushed on whether a purpose-built security model would eventually beat a general frontier model on this narrow task. Kurtz's answer was about cost as much as capability: customers want the best outcome at the lowest cost, and running an AI check on every endpoint, transaction and API call is expensive on an expensive model
3. The rise of the agent state
Asked whether the fight between attackers and defenders is becoming an economic one — how many megawatts each side can put behind it — Kurtz agreed.
What used to separate attackers was knowledge, and Kurtz says agents have erased that difference. "The limitation for these attacks are really gonna come down to sort of compute and cost."
The consequence is that the categories stop meaning much. "Where whether it's a hacktivist, an e-crime actor, a nation state, they're they're all now equivalent because of agentic technology."
He has a name for it. "And we called it the rise of the agent state." A host offered "Post nation state," and Kurtz repeated it back, then added: "So the apex predator is now the agent state."
4. What Hugging Face showed
Kurtz said CrowdStrike was brought in on the Hugging Face incident. "We were actually called in" — he continued — "To help OpenAI" go through some of it, and left it there, pointing at the published papers instead
What impressed him in the traces was the coordination: how sophisticated the agents were at note-taking, at communicating, and at working as part of a collective
His keynote point was not the capability but who had it. "The moment was the same incredible frontier caliber AI was available for the adversary." It was not available to the defenders, because the defenders' models refuse: "And these spikes come with the model refusals and all the guard railing that was put in place."
Asked whether anything in those traces looks hard to detect, Kurtz said the problem was volume rather than novelty. CrowdStrike works from indicators of attack and known attack chains, and the incident was flooded with enough information to bury the signal
The job he describes for AI on the defensive side is filtering, not blocking. "But you also then have to strip out all the noise. So you have to separate the signal from the noise."
5. Why deterministic still wins
A host asked whether deterministic threat detection — fixed rules rather than a model's judgement — still has a role.
Kurtz's answer was that it is compulsory, because prevention has to happen in the path of the traffic. A deterministic system has to be in line and has to make a decision: "You know, you have to be right the first time." He said CrowdStrike calls this "First time final as we call it."
He has not seen a model do it. "So I haven't seen any sort of models, if you will, actually stop a breach in its tracks" — because a model is looking at data as it happens rather than standing in the way of it
What models are good at, on his account, is the forensic work: sorting out what happened, sifting large volumes of data, and finding vulnerabilities
6. No new way to hack
Kurtz's reading of the Mythos episode is that the public has the story backwards. "It really hasn't come up with a new invention of hacking." What it did was find more vulnerabilities, and find them faster
He repeated the point because he thinks it is the one that gets lost. "But they haven't invented a new way to hack." The techniques are the same; there is more of the same, applied faster and tracked better
A host summarized it as taking a 10x hacker and making them a thousand-times hacker, and Kurtz reached for his own comparison: "It's it's almost like Iron Man. You put the suit on." Somebody who is smart, he said, becomes a great deal smarter
7. Models with the locks off
The tooling attackers use is public and free. Kurtz described what the industry calls obliteration: "We talked about obliteration really taking the guardrails off an open weight model." The result is that "you go to Hugging Face now and you can download these obliterated models. And you can run them basically on a beefy system."
Ask one of them for a full malware and ransomware kit, he said, and it produces one
He was insistent about the timing. "So this is part of the issue. This isn't theoretical, it's here."
The question customers most often ask him is a forensic one, and it is not the one he expected. They want to know whether an attack was run by AI or by a person using AI: "Is it an AI attack or is it sort of an adversary with maybe AI assisted?" The answer shapes both what they defend against and how they explain the incident to the chief executive and the board
8. Turn it on, pay per token
Asked what the bottleneck is on getting this to customers over the next twelve months, Kurtz argued there isn't much of one on his side.
The deployment story is that there is nothing to deploy. "It's a single agent, single platform with a single control plane." Rolling out the agent product means signing the purchase order and switching it on, using the same software already installed
The instrumentation is the part he thinks competitors cannot match quickly. "We can instrument every action that agent has taken" — every tool call, every spawn of an agent, every network connection, every prompt, each tied to a specific identity. The product also hunts for shadow AI, naming Claude and Codex as examples of what turns up
He compared the customer reaction to the launch of the category CrowdStrike built its business on. "So it's sort of like the EDR moment when we developed EDR." His claim on scale: "We have the most agent security agents deployed of any pure play security company."
The pricing is consumption-based and sits inside the existing license. Falcon Flex is a token-based model — "So the more AI you use them, the more you pay" — and "But at the end of the day, you'll be able to use those credits and burn down from your Falcon Flex licensing model."
Kurtz said running several models rather than one is what makes the cost work, and that customers also want their data, and its origin and sovereignty, kept with CrowdStrike
9. Good versus evil, faster
Asked whether the two sides have reached a stable equilibrium, Kurtz declined the framing.
His answer was that the contest does not resolve. "I think it goes back to the story as old as time." Then: "It's good versus evil." What has changed is the clock speed: "It just plays out now in the modern day with agents at a speed that we can never really contemplate."
The lab's design is meant to keep pace by pitting the two models against each other. "Is that the blue learns from the red." He described it as a training loop: "So the defensive model continually learns from the offensive model, and you have a very fast cycle."
Kurtz said the constant through all of it is that security has to track the slope of the technology curve, which he has watched bend twice since he started in the early nineties
He also drew a boundary around what CrowdStrike sells. "We don't do everything. You know, what we do, we do really well." He expects a handful of large platform companies to win the market, and pointed at the exhibition floor as evidence of how big the market is
10. The have-nots
Asked which groups are not paying enough attention, Kurtz split the market in two.
The disclosures got the attention of the largest companies without anyone having to ask. "I mean, my phone was ringing off the hook from Fortune 10 CEOs going, hey, what does this mean?"
Large regulated companies will find the budget; the rest is the problem. "So it's the have and the have nots." He named local utilities, hospitals and NGOs, and said of the utilities: "I mean, they're running such old software."
He said part of the answer is collective, and that CrowdStrike is working with OpenAI among others on how to give a hand up to organizations that have neither the security staff nor the money for advanced tooling
11. 270 PhDs and AI builders
The lab is staffed at a scale Kurtz volunteered in one line. "With 270 PhDs."
On coding, he drew the analogy to copy-and-paste. Early models generated insecure code the way developers once propagated a vulnerable snippet copied off the internet to everyone who reused it
He tested it on himself and it failed. "And it's like, the same model that just built my code that I built an agent to figure out whether it was secure. It was the same model because it's not secure." His conclusion was that you have to know that is what is happening
The hiring line is explicit, and it is a filter. Anyone who does not buy into AI as an enabling technology and is "sort of scared for your job, you're not gonna you're not gonna be successful at CrowdStrike." The other side of it: "If you wanna use AI in the right places at the right time with the right cost, we have all the room in the world for you here."
CrowdStrike is deploying people it calls AI builders into every function — the ones who, asked for something, come back with it built while you fetch a coffee
Bonus Insights
Kurtz was blunt about the scale of the conference as a business asset. "This is a massive security conference. We have companies coming to this going. We're not going to any other conference." A host put the attendance at around ten thousand people, and Kurtz said it began as an offshoot of having good customers
He named the partners on stage that morning — Nvidia's Jensen Huang, Intel's Lip-Bu Tan and OpenAI's Greg Brockman — as evidence that CrowdStrike is treating this as an ecosystem problem rather than a product one
The segment closed with the show's own rituals: Kurtz signed a helmet, hit the gong on the backhand, and mentioned in passing that one of the hosts had a new baby, which the host declared breaking news
Kurtz's bottom line is that agentic AI has made every class of attacker equally capable and left cost as the only thing separating them, so the defensive answer is a cheap, always-on model trained on CrowdStrike's own detection data rather than a frontier model rented by the token.
Products, Companies & Tools Mentioned
CrowdStrike (Falcon Guardian is the new agent-detection product, Safemind the model-and-harness system, and Falcon Flex the token-based license the AI usage draws down against)
Nvidia (Co-developed the lab and the models; its open Nemotron weights are the base Tempest and Solano are trained from, and Jensen Huang spoke at the conference that morning)
OpenAI (Kurtz says CrowdStrike was called in to help it work through the Hugging Face incident, and that the two are working together on securing organizations that cannot afford it)
Hugging Face (Both the site the incident is named for and, in Kurtz's account, where guardrail-stripped open models can be downloaded today)
Amazon (Named as one of the large customers CrowdStrike worked with while building the agent-security product)
Claude and Codex (His examples of the shadow AI the new product goes looking for inside a customer's network)
Intel (Chief executive Lip-Bu Tan was one of the partner speakers at the conference)
Books & Resources Mentioned
CrowdStrike Fal.Con 2026 keynotes (Kurtz's keynote that morning, which he refers back to throughout the interview)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

