The new system puts two artificial intelligence models against each other: one searches for ways to break into systems, while the other works to detect and close those paths.
LAS VEGAS — The battle between hackers and cybersecurity teams is entering a new phase.
CrowdStrike and NVIDIA have unveiled SafeMind, a new artificial intelligence system designed to identify potential attack paths before they can be exploited in the real world. The idea is simple but ambitious: instead of waiting for an attacker to discover a weakness, an AI agent attempts to find it first.
SafeMind was unveiled at CrowdStrike’s Fal.Con 2026 conference in Las Vegas and is designed to operate natively within CrowdStrike’s Falcon security platform.
An artificial attacker facing an AI defender
SafeMind is built around two specialised AI models.
Red Tempest is the offensive model. It behaves like a cyber adversary, looking for ways into a system and identifying possible paths that could be used in an attack.
Its counterpart is Blue Solano, the defensive model. It analyses what Red Tempest discovers and attempts to create ways to detect and stop the attack.
The two models are not designed to operate independently.
CrowdStrike has connected them in a continuous loop: the offensive model searches for weaknesses, the defensive model attempts to close them, and the process starts again.
That gives SafeMind a much more autonomous role than traditional AI-assisted security tools.
AI versus AI

In practice, SafeMind is designed to create a controlled contest.
Red Tempest attempts to find an attack path. Blue Solano must identify it, develop a defence and then test whether that defence works.
If the offensive model finds another way through, the process continues.
The approach is part of a wider movement towards autonomous red teaming, where AI agents continuously test an organisation’s security rather than relying solely on periodic human-led assessments.
NVIDIA and CrowdStrike have tested the concept in a virtual environment designed to simulate NVIDIA infrastructure. Within that environment, the agents can search for and close attack paths without directly affecting production systems.
Built with NVIDIA Nemotron
SafeMind uses models from NVIDIA’s Nemotron family, adapted for cybersecurity tasks.
CrowdStrike has also brought its own security data into the system, including information from its Falcon platform, threat intelligence and data gathered through years of incident-response work.
That distinction matters. A general-purpose AI model may be good at analysing text or writing code, but cybersecurity requires a much more specialised understanding of attacker behaviour, enterprise infrastructure and the way real-world incidents unfold.
CoreWeave is providing cloud infrastructure for training and running the models.
CrowdStrike reports significant gains

In its own internal testing, CrowdStrike says SafeMind achieved a 29% higher detection rate, while completing the process from detection through remediation six times faster.
The company also reported a 99% reduction in cost in its comparative tests.
Those figures should be treated as company-reported results rather than independent industry benchmarks.
Performance can vary significantly depending on the data, environment and testing methodology used, particularly in an emerging field such as agentic cybersecurity.
Why the shift matters
For years, security teams have largely focused on detecting attacks after they begin.
AI is changing the equation on the other side as well.
Attackers can use AI to automate parts of their operations, increasing the pressure on defenders to respond at machine speed.
CrowdStrike’s argument is that defence must become increasingly automated too.
Instead of using AI only as an assistant for a human security analyst, the company is pursuing systems that can search for weaknesses, test defences and help drive the response themselves.
NVIDIA chief executive Jensen Huang described the moment as an inflection point for cybersecurity, arguing that if attacks are becoming automated, defence needs to become automated as well.
The beginning of a new race
SafeMind does not mean hackers have been defeated, nor does it suggest that AI can simply replace cybersecurity experts.
But the technology illustrates where the industry is heading.
Rather than relying on a model that simply raises an alert, CrowdStrike is building a system in which one AI searches for vulnerabilities, another attempts to close them, and the two continue testing each other.
If that approach proves effective at scale, part of cybersecurity could shift further away from reacting after an incident and towards continuous testing and prevention.
The question is no longer simply whether hackers will use AI.
It is whether defenders can use it faster.