CrowdStrike used its Fal.Con 2026 conference in Las Vegas on September 1, 2026, to unveil Falcon Guardian — a new AI Detection and Response (AIDR) solution that treats the endpoint as the enforcement point for autonomous AI agents. Falcon Guardian is designed to discover, monitor, control and detect agents across Windows and macOS endpoints, cloud, SaaS and browser surfaces.
Discovery, inventory and shadow-agent control
The Falcon sensor now maintains a live inventory of every running and dormant AI agent inside an enterprise — including shadow agents deployed outside IT approval — and captures who deployed each, its security posture and its current activity. Agent Access Controls let admins define which agents may run on managed endpoints, translating governance policy into enforceable runtime blocks.
Runtime detection and blast-radius containment
Falcon Guardian correlates AI agent behaviour to Falcon endpoint telemetry, drawing a causal chain from user prompt and identity through tool call, skill use and every downstream system action. Runtime Detection and Response reconstructs the full execution graph, determines blast radius in real time, and contains malicious agent behaviour before it spreads. CrowdStrike is also adding an AI Gateway for MCP-aware traffic control, plus Falcon Complete for Guardian and Adversary OverWatch for Guardian for 24/7 managed AIDR.
Building on Pangea, feeding Falcon Next-Gen SIEM
Guardian extends CrowdStrike's 2025 Pangea acquisition, which delivered human-prompt-level protection, into runtime enforcement against autonomous agents. Because agents generate orders of magnitude more telemetry than traditional apps, Guardian streams data into Falcon Next-Gen SIEM as first-party data — a differentiator CrowdStrike is pitching against agentic-security startups still bolting on external SIEMs. The launch lands alongside JetStream's zero-trust agent authorisation work and the wider push for AIDR standards.
Reporting based on coverage from CrowdStrike, Channel Insider and SC Media.
