CrowdStrike launches Cyber Superintelligence Lab and releases SafeMind security models
CrowdStrike has announced the establishment of a Cyber Superintelligence Lab, which it describes as a frontier AI research organisation focused on cyber defence and AI safety. The company also introduced SafeMind, a family of security models and “harnesses” developed by the new lab and intended to operate within the CrowdStrike Falcon platform.
According to CrowdStrike, the lab will bring together AI researchers, offensive security operators and incident responders under a single charter. The lab will be led by Dr. Bartley Richardson, CrowdStrike’s chief AI and autonomous systems officer.
The company said the lab’s work will be based on data and environments associated with its Falcon platform, including endpoint, identity, cloud and data-store telemetry, as well as inputs from its next-generation SIEM. In the release, CrowdStrike said this architecture produces “trillions of events every day” and includes 15 years of threat intelligence and incident response material.
“Security is how AI scales,” said George Kurtz, CEO and founder of CrowdStrike. “The Cyber Superintelligence Lab concentrates the PhDs, AI researchers, and the threat hunters who stop real attacks every day on the Falcon platform.”
“The real test for AI in security is whether it can stop breaches,” said Dr. Richardson. “To accomplish this today, we need intelligence that operates at machine speed, continuously learning and improving.”
In a separate announcement, CrowdStrike introduced SafeMind, which it said is designed as an “agentic system” combining offensive and defensive security models with harnesses that run in a closed loop. CrowdStrike said the SafeMind agentic system will operate natively in the CrowdStrike Falcon platform, while “trusted access” for standalone models and harnesses will be provided through its Project QuiltWorks program.
SafeMind launches with two models: Red Tempest, described as an offensive red team model built to emulate AI adversaries in advanced attack scenarios, and Blue Solano, described as a defensive blue team model built to help protect enterprise assets.
CrowdStrike said it is building the models using NVIDIA Nemotron open models in collaboration with NVIDIA, and that the program includes CoreWeave’s AI Cloud for training and inference.
“The future of cybersecurity won’t be defined by AI that simply identifies threats, it will be defined by AI that defeats them,” Kurtz said. “SafeMind brings offensive and defensive models together in a system trained on CrowdStrike’s unique cyber data.”
Jensen Huang, founder and CEO of NVIDIA, said: “SafeMind combines NVIDIA Nemotron open models with CrowdStrike’s deep cybersecurity expertise, trusted security data, purpose-built agent harnesses, rigorous evaluations, and safeguards – creating a frontier agentic cybersecurity stack designed to operate at machine speed.”
Michael Intrator, co-founder and chief executive officer of CoreWeave, said: “We’re proud to power SafeMind across training and inference as CrowdStrike puts specialised AI to work against real-world threats.”
CrowdStrike also cited internal evaluation results, stating SafeMind delivered a 29% higher detection rate, six times faster end-to-end remediation, and 99% cost savings on detection and remediation when compared to “leading frontier models and open-source baselines.” The company did not provide additional methodology details in the release.