CrowdStrike has introduced its SafeMind frontier AI models, developed with Nvidia's Nemotron open models and custom harnesses, with cost reduction as a core objective alongside improved AI-powered security performance, according to CrowdStrike CEO George Kurtz and Nvidia CEO Jensen Huang. The system was revealed Tuesday at Fal.Con 2026, where the two CEOs underscored the importance of open AI models and specialized harnesses in making agentic security tools financially viable for the long term. Solution provider partners told CRN that while many vendors are building promising "agentic SOC" technologies, the expense of premium frontier AI models could impose significant limitations going forward.
The SafeMind system pairs newly built offensive and defensive AI models—Red Tempest for offensive security and Blue Solano for defense—with fresh agent harnesses, according to CrowdStrike. The models operate by continuously launching attacks and deploying defenses inside a digital twin of an organization's environment. Most agentic SOC vendors currently focus on constructing wrappers and harnesses to guide powerful general-purpose models rather than creating or tailoring models themselves, relying on premium frontier models such as Anthropic's Claude Mythos and OpenAI's GPT Cyber models, which security experts have flagged as especially costly in recent months. For many startups, growing customer adoption can trigger surging model expenses that may become unsustainable over time, with the risk that ventures relying on investor funding to cover general-purpose frontier AI costs "will run out of money at the token burn rates that you're seeing," according to Chris Ebley, CTO at Annapolis, Maryland-based Blackwood, No. 96 on CRN's Solution Provider 500 for 2026.
"The harness makes a massive difference, and the training makes a massive difference, to get to the best outcome with the lowest cost," Kurtz said during Fal.Con 2026 in Las Vegas, adding that the harness "really is the 10X factor in getting additional results at the lowest cost." SafeMind represents the industry's "first complete agentic system for cybersecurity, including the first frontier models [that are] purpose-built for defenders," Kurtz stated. Huang emphasized that Nemotron was built explicitly to allow major vendor partners like CrowdStrike to develop tailored, efficient models for highly specialized needs such as cybersecurity, noting that "we don't need every AI to be super smart at everything. But in some areas, we need to be extraordinarily good at something—and cyber defense is something we want to be incredibly good at." Nemotron was created "in a way that is very cost-effective," Huang said, designed to be "both smart but also fast."
Companies like CrowdStrike are "uniquely positioned because [they] have a large enough war chest to be able to actually lean in on model development," Ebley told CRN, explaining that building a small language model with high efficacy over time can avoid "huge amounts of compute costs" compared to relying on third-party frontier models. Open models have the potential to ensure security teams can fully leverage AI and agentic capabilities without ongoing concerns about usage costs, according to Jordan Hildebrand, global cyber practice director at St. Louis-based World Wide Technology, No. 10 on CRN's Solution Provider 500 for 2026. The goal should be removing any cost-related worries from SOC analysts, who already face highly demanding and critical responsibilities and should be empowered to use AI whenever it's likely to enhance security outcomes, Hildebrand said. By integrating lower-cost AI models into its platform, CrowdStrike has the potential to democratize advanced AI-powered defense, making it accessible more broadly than just at the largest well-funded enterprises, Hildebrand noted.
CrowdStrike will continue enabling the use of proprietary frontier models within its Falcon platform, with customers able to deploy any combination of CrowdStrike's models, other frontier models, and open-source models, Kurtz said during Fal.Con 2026. "We're not going to lock you into our models," he stated, emphasizing that customers can choose to use CrowdStrike's models, frontier models, open-source models, or combine all the models together within "an open ecosystem." Developing this type of capability often requires substantial upfront investment, potentially giving large security vendors like CrowdStrike an edge over startups that depend on third-party frontier models and venture backing, Ebley said. The strategic bet on open models paired with high-performance harnesses could reshape competitive dynamics in the security sector, as vendors face a stark choice between costly agility and capital-intensive autonomy.

