At the Fal.Con 2026 conference in Las Vegas, a fundamentally new cybersecurity architecture was announced. CrowdStrike, together with NVIDIA, presented the SafeMind system, which introduces an "eternal cycle" of confrontation between offensive and defensive AI models. The solution will be natively integrated into the Falcon platform, turning it into a self-learning protective mechanism.
The key innovation lies in the symbiosis of two specialized models. Red Tempest acts as the "red team," simulating an attacker's actions and actively seeking out compromise vectors. Its opponent, Blue Solano, analyzes attack telemetry, synthesizes new detection rules, and immediately tests their effectiveness. This "attack-defense" cycle repeats continuously, allowing the system to adapt to new threats faster than traditional signature-based methods.
Architecture and Training
The SafeMind defensive loop is based on the open weights of NVIDIA Nemotron models. Nemotron 3 Ultra handles orchestration: reconstructing the attacker's sequence of actions, planning response steps, and managing the agents' toolkit. A lighter, further-trained version, Nemotron 3 Super, specializes in generating and correcting detection rules. For its tuning, CrowdStrike used an array of 9,349 examples with 59 types of programmatically simulated errors, as well as 15 years of incident response data and Falcon telemetry.
The use of open weights is not just a technical decision but a strategic maneuver. It allows organizations to fine-tune models on their own data without the risk of confidential information leaking to an external provider of cloud AI services. Computing power for training and inference is provided by CoreWeave infrastructure.
Performance Figures
CrowdStrike's internal tests demonstrate impressive results: threat detection rates increased by 29% compared to leading commercial and open-source solutions, issue resolution time was reduced sixfold, and associated costs dropped by 99%.
NVIDIA, in turn, revealed details of the defensive loop's backtesting. In the standard configuration, rules created by Nemotron 3 Ultra detected an attack on average in 16.5% of cases. After adding the fine-tuned Nemotron 3 Super, domain-specific context, and automated verification, this figure rose to 41.9%. During "live-fire" trials, the open loop achieved a result of 45% versus 29% for a proprietary competing system, and three of its detections received the highest gold category, covering all eight test attacks.
Strategic Context
In parallel, CrowdStrike announced the creation of a research division, the Cyber Superintelligence Lab, led by Bartley Richardson. NVIDIA will act as a partner of the lab, investing $100 million in it over five years. Also presented was the Falcon IQ tool for automating risk management, which uses more than 50 AI agents.
This step is a direct consequence of the growing threat from AI attacks, as warned by OpenAI and 127 other organizations. We are witnessing a transition from reactive protection to proactive autonomous defense, where AI confronts AI. However, as the tests themselves show, even the best loop does not guarantee absolute protection: an effectiveness of 41.9% in an isolated environment underscores that the technology still requires human oversight and continuous refinement. The market is entering a phase where the main asset is not the number of rules, but the quality of the algorithms that generate them.