Breakout time is over: Key takeaways from CrowdStrike Fal.Con 2026:
How agentic AI is accelerating cyberattacks and transforming defense strategies

 |   | 

Reading Time: 6 minutes
In brief:

CrowdStrike Fal.Con 2026 highlighted a fundamental shift in cybersecurity: AI-powered attacks now occur at inference speed, leaving security teams little time to respond manually. Learn how CrowdStrike is using frontier AI research, agentic security operations, runtime enforcement, and identity controls to help organizations defend against this new generation of threats.

In his annual Fal.Con keynote, CrowdStrike CEO George Kurtz typically highlights breakout time, a measure of how quickly an adversary can move laterally from a compromised machine to other parts of a network. 

But the agentic AI era changes everything. Malicious AI agents now autonomously execute attacks at inference speed, effectively erasing this metric. In this landscape, attacks happen almost instantly. Human defenders no longer have time to manually triage, respond to, and contain breaches. 

“For years, I stood on the stage like this one, and I tracked this number called breakout time… We call that machine speed. We were wrong. I was wrong. This was human speed with better tools, and breakout time is over. Attacks now happen at inference speed. And when an attacker has inference speed, there is no breakout time. There’s actually no time at all to deal with these attacks.” — George Kurtz, CEO at CrowdStrike 

NVIDIA CEO Jensen Huang joined Kurtz’s keynote to emphasize this shift and make the case for bringing frontier AI to security teams. 

“We’re at an inflection point in cybersecurity for obvious reasons,” Huang said. “We have now had agentic AI, the ability to automate attacks, and the attacks on companies are going to grow exponentially. This is the beginning of a new age of cybersecurity. On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever.” 

If breakout time is truly over, human-speed security operations can no longer keep up with attacks. The innovations announced at Fal.Con 2026 highlighted CrowdStrike’s vision for the future of security, combining autonomous defense, runtime visibility, and agent-specific identity controls to help defenders respond at machine speed. 

What CrowdStrike’s announcements signal for security teams 

Frontier AI research for defense 

Threat actors increasingly use AI to automate reconnaissance, exploitation, and lateral movement. To keep up, security teams need AI to learn from adversaries and anticipate new attack techniques.

CrowdStrike introduced SafeMind, an agentic system designed to bring offensive and defensive AI together. SafeMind was developed through CrowdStrike’s Cyber Superintelligence Lab. 

The system consists of: 

  • Red Tempest: An offensive model built to proactively find hidden attack paths. 
  • Blue Solano: A defensive model engineered to close those vulnerabilities. 
  • Specialized harnesses: A framework that operates both models in a closed-loop system. 

CrowdStrike builds these security models using NVIDIA Nemotron open models, leveraging CoreWeave’s AI Cloud for high-performance training and inference.  

By pitting Red Tempest and Blue Solano against each other, SafeMind continuously tests and strengthens defenses. The harnesses are also designed to work with other frontier and open-source models, giving organizations greater flexibility while maintaining cost control.

“The basic framework of SafeMind — an adversarial model acting on a digital twin of the environment, with a defender model in a continuous cat-and-mouse loop, eventually learning how to secure itself — applies to robotics, edge computing, enterprise computing, and just about everything.” — Jensen Huang, CEO at NVIDIA

The agentic SOC 

The future SOC will shift from analysts investigating alerts to security teams orchestrating and governing specialized AI agents.

CrowdStrike announced the next evolution of its agentic SOC to handle attacks occurring at inference speed. Powered by Charlotte AI AgentWorks, the solution deploys coordinated multi-agent investigations across endpoints, identity, SaaS, cloud, and network environments. 

AgentWorks provides a no-code ecosystem where teams can build, customize, and deploy hyper-specialized AI security agents in plain English. Grounded directly in the unified CrowdStrike Falcon platform, these custom agents automatically ingest trillions of real-time security events alongside local enterprise data.  

By orchestrating collaboration between specialized AI agents while keeping humans in control through approval gates and audit logs, AgentWorks helps security teams respond to machine-speed attacks in seconds. 

Runtime AI agent security 

As AI agents take on more authority, organizations need visibility into what those agents are doing in real time, not just where they exist. 

CrowdStrike launched Falcon Guardian, a dedicated AI Detection and Response (AIDR) solution, to meet this need. Moving beyond AI posture management, Falcon Guardian focuses on visibility into runtime: the critical moment when an AI agent translates a user prompt or poisoned data into system actions.

Because agentic AI relies on autonomous tools to modify files and execute commands, waiting for post-event logs is a losing strategy against inference-speed attacks. 

By utilizing an Agent Graph, Guardian fuses AI agent prompts and tool calls directly with core Falcon endpoint telemetry, allowing security teams to instantly map out their entire agent fleet, uncover hidden shadow AI, and block malicious behaviors as they happen.

Securing agentic identity 

Identity is becoming the primary control plane for AI.

Stopping inference-speed attacks requires fundamentally changing how AI agents are authorized to access enterprise data. Today’s identity solutions treat AI agents like static service accounts or API keys, frequently allowing them to inherit broad, permanent permissions that they can abuse at machine speed. 

CrowdStrike unveiled the CrowdStrike Agentic Identity Provider (Agentic IdP) to bridge this gap. Working hand-in-hand with Falcon Guardian’s discovery capabilities, Agentic IdP automatically registers newly deployed AI agents into a single authoritative directory and issues them a cryptographically verifiable identity. 

Instead of giving agents permanent credentials, Agentic IdP acts as the identity control plane, brokering short-lived, tightly scoped tokens that grant the absolute minimum access required for a specific task.  

By enforcing this model of continuous identity and maintaining end-to-end attribution back to the original human user, this solution ensures that even if an AI agent is compromised, it can’t be weaponized to move laterally or execute unauthorized data exfiltration.  

Turning CrowdStrike’s vision into reality 

Adapting to machine-speed attacks requires more than new tools. Organizations need a strategy for securely adopting AI, protecting agentic identities, modernizing security operations, and reducing the complexity that slows response times. 

SHI helps you translate the capabilities introduced by CrowdStrike into actionable security strategies. Whether you’re evaluating how to secure AI agents, improving identity governance, consolidating security tools, or accelerating detection and response workflows, our experts can help you build a roadmap that aligns technology investments with business priorities. With strategic guidance, implementation expertise, and ongoing optimization, we can prepare you for the challenges of the agentic AI era. 

CrowdStrike 2026 Global Flex Partner of the Year 

SHI was recognized as CrowdStrike’s 2026 Global Flex Partner of the Year during the CrowdStrike Global Partner Summit at Fal.Con 2026. 

Falcon Flex is a flexible subscription and licensing program that allows organizations to pre-negotiate a spending commitment and draw down that balance over time. 

“Falcon Flex provides our mutual customers with the flexibility to adapt as security needs evolve while reducing the risk of underutilized investments. Through SHI’s Flex Success model, we help customers maximize the full value of the CrowdStrike platform through thoughtful planning, accelerated adoption, and ongoing optimization of the solutions that stop breaches.” — Jared Crowley, VP of Security at SHI 

Securing innovation in the agentic AI era 

Fal.Con 2026 made one thing clear: organizations can no longer rely on human-speed processes to defend against inference-speed attacks. As AI agents become more deeply embedded across enterprise environments, security teams need new approaches to operations, runtime protection, and identity governance. 

The organizations that succeed will be those that can securely adopt AI while maintaining visibility, control, and resilience as the threat landscape continues to change. 

NEXT STEPS 

  • Join SHI experts and industry peers at SHI Fall Summit to discover practical approaches for strengthening resilience and preparing for the next era of cybersecurity.