Extend Falcon Guardian with an AI Gateway

Falcon Guardian brings discovery, governance, data protection, runtime security, investigation, and response together in CrowdStrike’s flagship solution in the AIDR market category, extending protection from AI interactions into the new agent execution layer.
This new capability is currently pre-beta and will go to GA next quarter (Q4).
CrowdStrike is also announcing CrowdStrike Falcon® Complete for Falcon Guardian to extend CrowdStrike’s industry-leading MDR service to AI applications and autonomous AI agents.

Extend Expert-Led Defense to AI

This new service will be available to customers later this quarter (Q3).

Falcon Adversary OverWatch Hunts Threats Targeting AI Agents

As AI agents operate autonomously across enterprise environments, organizations need the expertise to identify suspicious behavior, uncover emerging adversary tradecraft, and respond when AI systems are targeted or compromised. CrowdStrike is extending managed cross-domain threat hunting and MDR services to Falcon Guardian, bringing expert-led defense to AI applications and autonomous agents.
Falcon Complete for Falcon Guardian will deliver continuous, expert-led detection, investigation, and response for AI agents. CrowdStrike’s elite analysts will use Falcon Guardian’s rich runtime context to assess agent intent, distinguish legitimate AI activity from malicious behavior, and stop attacks in real time. With CrowdStrike analysts monitoring AI environments 24/7, customers can realize the full operational value of Falcon Guardian with expert protection around the clock. 
Learn more about Falcon Guardian

Falcon Complete MDR for the AI Era

Falcon Guardian will soon include a native AI gateway capability, offering a new centralized control point for enterprise AI traffic and will provide expanded visibility, access management, and policy enforcement as applications and agents communicate with AI models and services. The gateway feature will also use context from the Falcon platform, including the user, agent, endpoint, identity, asset, and security posture, to inform policy decisions.  
As AI applications and agents communicate with a growing ecosystem of models, services, and MCP infrastructure, organizations need a consistent way to monitor and govern AI traffic beyond the endpoint.
Falcon Guardian natively exports agent telemetry into CrowdStrike Falcon® Next-Gen SIEM as first-party data, pre-mapped to its schema for immediate correlation, detection, and automation, and correlated with identity, cloud, and SaaS data across the Falcon platform for cross-domain investigations. Since Falcon Guardian data is treated as first-party data rather than a separate ingest-based line item, this integration can eliminate potentially millions in annual third-party SIEM costs with agent telemetry, with default retention included to support compliance-ready visibility into AI agent activity.  

Falcon Next-Gen SIEM Delivers Scalable, Cost-Effective Agent Data Capture

CrowdStrike Falcon® Adversary OverWatch™ Cross-Domain, available today, extends 24/7 proactive threat hunting to AI applications and autonomous agents using Falcon Guardian’s runtime context. CrowdStrike’s expert hunters combine this rich behavioral context with frontline adversary intelligence to uncover manipulation, abuse, and emerging tradecraft that automated detections may miss.
Customers must have both Falcon Adversary OverWatch Cross-Domain and Falcon Guardian.

CrowdStrike Defines the Next Generation of AI Security

Disclaimer
AI agents generate orders of magnitude more telemetry than traditional applications or human users. Routing this volume to third-party SIEMs can cause ingest costs to spiral out of control. 
CrowdStrike pioneered detection and response for the endpoint. Today, we are defining the AIDR category and applying that same focus on deep visibility, rich security context, and decisive response as we did with endpoint detection and response (EDR). With Falcon Guardian, organizations can build a stronger foundation to accelerate secure AI adoption and innovation.
This helps security teams identify and disrupt adversaries before they can expand access and escalate AI activity into a broader intrusion.
This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.

Similar Posts