CrowdStrike Launches Cyber Superintelligence Lab to Fight AI Threats
CrowdStrike has launched a new Cyber Superintelligence Lab dedicated to using frontier artificial intelligence for cyberdefense and AI safety, bringing together AI researchers, offensive security specialists and incident responders to develop security systems capable of operating at machine speed.
The new lab is being built around the security data, threat intelligence and testing environments of CrowdStrike’s Falcon platform. The company says its systems process trillions of security events every day across endpoints, identity systems, cloud workloads and data environments, while its threat intelligence and incident-response records span 15 years.
The move comes as AI is changing the cybersecurity landscape on both sides. The same technology that can help defenders analyse huge volumes of security information can also allow attackers to automate reconnaissance, identify vulnerabilities and move more quickly through compromised systems. CrowdStrike is now focusing on developing AI that can continuously learn from those threats and help security teams respond faster.
CrowdStrike Builds AI for the Cybersecurity Front Line
The Cyber Superintelligence Lab is led by Dr. Bartley Richardson, CrowdStrike’s chief AI and autonomous systems officer. Its work combines the company’s AI research with the experience of threat hunters, offensive security operators and incident responders who deal with real-world attacks.
A key advantage for the lab is the security data generated by Falcon. CrowdStrike says the platform brings together telemetry from endpoints, identity systems, cloud workloads and data stores, with analyst-verified information about whether activity represents a genuine threat. This gives the company a large pool of real security scenarios for training and evaluating AI systems.
The lab will also use high-fidelity cyber ranges that reproduce enterprise environments. These controlled environments allow AI agents to simulate attacks and defensive responses without putting real customer systems at risk.
SafeMind Puts Offensive and Defensive AI in One Loop
One of the first systems associated with the new lab is SafeMind, an agentic AI cybersecurity system developed with NVIDIA.
SafeMind combines two specialised AI model families. Red Tempest is designed for offensive security operations, including simulating attackers and searching for exploitable paths. Blue Solano focuses on defensive operations, identifying weaknesses, generating protections and testing whether those protections work.
The two sides can operate in a continuous loop. An offensive agent can attempt to find a route into a simulated environment, while defensive agents analyse the activity, create potential protections and test them. The system can then repeat the process against the updated environment.
SafeMind uses NVIDIA’s Nemotron open models and CrowdStrike’s cybersecurity intelligence. The companies are also using simulated enterprise environments to evaluate how the system performs across different attack and defence scenarios.
NVIDIA is serving as the AI compute design partner for the Cyber Superintelligence Lab and plans to invest $100 million in the collaboration over five years.
From Detecting Threats to Responding Automatically
The broader objective is to move cybersecurity AI beyond simply flagging suspicious activity. Instead, the systems are being developed to understand how an attack could progress, test possible responses and help validate defensive measures.
CrowdStrike is also integrating SafeMind into its Falcon platform, potentially allowing research from the lab to become part of the company’s wider security operations. The company has separately been expanding its use of autonomous AI agents for security assessment, prioritisation and remediation workflows.
That approach becomes increasingly important as organisations face a growing number of vulnerabilities and security alerts that human teams cannot investigate at the same speed as automated systems. Frontier AI can analyse and act on information much faster, but it also creates new risks if powerful agents are allowed to operate without adequate controls.
CrowdStrike’s new lab is therefore focused on both sides of that problem: building AI capable of defending systems against increasingly automated attacks while developing safer ways to deploy autonomous AI in cybersecurity. As attackers and defenders increasingly use the same underlying technology, the ability to test, learn and respond continuously could become a central part of how enterprise security is managed.
