CrowdStrike ships security frontier models built on Falcon telemetry
Security got its own model family today, and the money chasing AI training data got a new benchmark. Both stories point the same way: the AI build-out is hardening into an industry with its own supply chain, its own specialists, and its own arguments with governments.
CrowdStrike used Fal.Con in Las Vegas to launch SafeMind, a pair of cybersecurity models it built with Nvidia, and to open a Cyber Superintelligence Lab to keep building them. The offensive model, Red Tempest, emulates AI-driven adversaries and runs attack scenarios against a customer's environment; the defensive one, Blue Solano, applies the containment moves CrowdStrike responders use on live incidents. Both are built on Nvidia's open Nemotron family and trained on CrowdStrike's own material rather than the open web — Falcon sensor telemetry, threat intelligence, the annotations Falcon Complete analysts attach to confirmed detections, and fifteen years of incident response fieldwork, with CoreWeave supplying the compute. The two models run against a digital twin of a customer's environment in a loop: the red agent finds a way to exfiltrate data, the blue agent writes the rule that would have caught it, and the environment hardens.
The pitch is a direct answer to the asymmetry CrowdStrike's Daniel Bernard described — frontier models "really benefited the adversary," because attackers can rent the same general-purpose systems defenders can. CrowdStrike claims SafeMind detects 29% more, remediates six times faster end to end, and cuts detection and remediation costs by 99%, but it did not name the models it benchmarked against or describe the methodology, so treat those as vendor numbers until someone reproduces them. The more durable asset here is the data: trillions of events a day from endpoints, identity systems, cloud workloads and data stores, which no general-purpose lab has. Alongside it, CrowdStrike launched Falcon Guardian to police AI agents at the endpoint — inventorying known and shadow agents on Windows and macOS, tracing a chain from prompt to identity to tool call to system change, and blocking anything not on the approved list.
AfterQuery is reportedly the fastest company in Y Combinator's history to hit unicorn status, at a $3.2 billion valuation. Forbes first reported the round; TechCrunch could not reach the company for comment. The AI data startup closed a $30 million Series A in April at a $300 million valuation — a more than tenfold jump in five months, against roughly $30 million to $34 million in total disclosed funding. Its edge is a network of about 100,000 verified professionals in finance, medicine, law and software engineering who generate training data and reinforcement learning environments, and its customers reportedly include OpenAI, Google DeepMind and Microsoft AI.
What's being bought is judgment, not labels. AfterQuery's own framing is "encoding the patterns, decisions, and reasoning of the world's best practitioners" — the tacit knowledge that never made it onto the public web, which is exactly the input frontier labs are short of now that the open internet has been scraped dry. The company reported over $100 million in annual recurring revenue in April and described it as "hundreds of millions" by July. A startup selling to all sides, including Chinese labs, is positioning itself as neutral ground in a market where data has become a strategic asset.
The US used a G20 tech meeting in Chapel Hill, North Carolina to press other governments not to write new AI rules at all. US tech adviser Michael Kratsios, co-hosting the two-day gathering of industry figures and commerce ministers, pushed countries to adopt the "Carolina Principles" — signing on means agreeing to "reserve new regulation for novel considerations," invest in foundational research, and strengthen commercial opportunities for new technology. A White House official said the US will also press members not to set up new regulatory organizations to oversee AI development. Sam Altman and Jensen Huang appear before delegates with Commerce Secretary Howard Lutnick on Wednesday; Mark Zuckerberg and Demis Hassabis are addressing ministers by video.
The timing is the story. The meeting runs while Chinese open-weight models keep closing the gap on American proprietary systems and gaining ground with US companies, and a CNAS fellow framed the administration's urgency plainly: keep the rest of the world inside the American tech ecosystem. Canada's delegation said it will argue for balancing innovation with public trust and safety, which is about as far as the public disagreement went. The G20 leaders' summit lands in Miami in December, with more US-hosted gatherings between now and then.
What to watch: whether any independent benchmarker gets SafeMind's numbers to hold up against named frontier models.
If a security vendor owns the telemetry, the models and the harness, does that make it the safest place for your data — or the single biggest target? Tell us in the comments.
Sources: SiliconANGLE — CrowdStrike builds security frontier models with Nvidia · CrowdStrike — Launches frontier models for cybersecurity, created with NVIDIA · CSO Online — CrowdStrike launches cyber frontier AI models, agentic security system · NVIDIA — CrowdStrike strengthen agentic cybersecurity frontier · SiliconANGLE — Falcon Guardian polices AI agents at the endpoint · TechCrunch — AfterQuery reportedly becomes YC's fastest-ever unicorn · Forbes — AfterQuery becomes YC's fastest unicorn at $3.2 billion · Crypto Briefing — AfterQuery's $3.2B valuation · Reuters — US urges hands-off approach to AI regulation at G20 tech meeting · Techmeme — US urged G20 members to avoid new AI regulations