IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
CrowdStrike launches SafeMind and cyber defence AI lab

CrowdStrike launches SafeMind and cyber defence AI lab

Wed, 2nd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

CrowdStrike has created the Cyber Superintelligence Lab and launched its SafeMind security models, which it describes as the first frontier AI research organisation built for cyber defence and AI safety.

The move brings together CrowdStrike's AI researchers, offensive operators and incident responders in a single unit led by Dr. Bartley Richardson, Chief AI and Autonomous Systems Officer. Developed through the new lab, SafeMind includes two models, Red Tempest and Blue Solano, and is designed to run within the Falcon platform.

The announcement reflects a broader push across the cybersecurity industry to build AI systems trained on specialist security data rather than general-purpose models. Vendors are trying to show that AI can do more than flag suspicious activity by applying it directly to detection, response and remediation inside live security environments.

The lab is built on telemetry, adversary intelligence and operational environments drawn from the Falcon platform, which CrowdStrike says generates trillions of events a day across endpoints, identity systems, cloud workloads, data stores and its next-generation security information and event management tools.

Those data sets also include 15 years of threat intelligence and incident response material. CrowdStrike argues that verified outcomes from real attacks and responses are central to training models for cyber defence, particularly as attackers also adopt AI tools.

SafeMind is positioned as a system that combines offensive and defensive models in a single operating loop. Red Tempest is designed to model advanced attack scenarios and emulate AI-driven adversaries, while Blue Solano is intended to defend enterprise assets using measures drawn from operational security practice.

Through its Project QuiltWorks programme, CrowdStrike says it will provide trusted access to standalone models and harnesses. The harnesses can work with both frontier and open-source models, alongside CrowdStrike's own models, to support different deployment choices.

Partner Roles

The models were built using NVIDIA Nemotron open models in collaboration with NVIDIA, which CrowdStrike identified as its AI design partner. CoreWeave is providing cloud infrastructure for training and inference.

That partner structure underlines how expensive and technically demanding AI model development has become, particularly in security, where large volumes of telemetry and rapid response times can increase computing needs. It also shows how cybersecurity companies are relying on specialist AI and infrastructure groups rather than building every layer themselves.

CrowdStrike says SafeMind's harnesses continuously test the offensive and defensive models against each other in a closed loop. Its stated aim is to improve performance over time by using one model to probe for attack paths and the other to shut them down.

It also published benchmark claims for the system, saying evaluations showed a 29% higher detection rate, six times faster end-to-end remediation and 99% cost savings on detection and remediation compared with leading frontier models and open-source baselines. The announcement did not provide further methodological detail.

George Kurtz framed the strategy around AI systems that take direct action in security operations.

"Security is how AI scales," said George Kurtz, Chief Executive Officer and Founder, CrowdStrike.

In a separate statement on the launch, he said: "The future of cybersecurity won't be defined by AI that simply identifies threats, it will be defined by AI that defeats them. SafeMind brings offensive and defensive models together in a system trained on CrowdStrike's unique cyber data. It finds weaknesses, strengthens protection, and gets smarter with every cycle, advancing our mission to stop breaches at machine speed."

Richardson linked the initiative to a wider shift in how security teams will need to operate as AI-driven attacks increase.

"The real test for AI in security is whether it can stop breaches. To accomplish this today, we need intelligence that operates at machine speed, continuously learning and improving. It is the standard the whole industry will need to move towards in the face of AI-empowered adversaries," said Dr. Bartley Richardson, Chief AI and Autonomous Systems Officer, CrowdStrike.

He also set out CrowdStrike's view of the new models' role inside its platform. "Our models are the start of a new chapter for cyber defence. With the models and harnesses together in a co-evolving agentic system, defenders can now act at machine speed. This is the foundation for the next decade of AI security, and CrowdStrike is the only company that owns the entire stack, from sensor to harness to model," said Richardson.

NVIDIA cast the project as part of an emerging contest between attackers and defenders using AI.

"Cybersecurity in the age of AI will be a continuous contest between adversaries using AI to scale attacks and defenders using AI to expand detection and response. Cyber defence will be among the most compute-intensive applications of AI. SafeMind combines NVIDIA Nemotron open models with CrowdStrike's deep cybersecurity expertise, trusted security data, purpose-built agent harnesses, rigorous evaluations, and safeguards - creating a frontier agentic cybersecurity stack designed to operate at machine speed. Powered by NVIDIA accelerated computing, SafeMind makes AI a force multiplier for defenders," said Jensen Huang, Founder and Chief Executive Officer, NVIDIA.

CoreWeave highlighted the operational demands of deploying such systems in live environments.

"The real test of AI is what it can do in production, at scale, when the stakes are highest. Few environments put that to the test more than cybersecurity. We're proud to power SafeMind across training and inference as CrowdStrike puts specialised AI to work against real-world threats," said Michael Intrator, Co-Founder and Chief Executive Officer, CoreWeave.