For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/crowdstrike-september-2026-falcon-ai-security-news.md.
AI Security ↗

News from Fal.Con: CrowdStrike's September AI security announcements

Falcon Guardian, agent identities, package protection and Charlotte AI: what CrowdStrike announced in September and what businesses should check before adopting it.

AI-generated illustration: CrowdStrike announcements on a tablet beside a Fal.Con programme.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

CrowdStrike’s September announcements bring several parts of AI security closer together: the agent running on a computer, the credentials it uses, the packages it installs and the investigation when something goes wrong. That is the useful thread through the Fal.Con 2026 news.

For Norwegian businesses, the pressure comes from both directions. Employees want AI tools that can finish work for them. Attackers can use those tools too, or manipulate the ones already inside the business. A list of approved chatbots leaves much of this activity outside the security team’s view.

These are the announcements worth bringing into the next discussion about AI access and security operations. They were made on 1–2 September; this is a roundup of the published material, with availability separated from the product direction.

Falcon Guardian follows what an agent actually does

Falcon Guardian builds on Falcon AIDR, adding endpoint agent discovery and a connection between AI interactions and subsequent system activity. CrowdStrike describes controls for supported agent types and investigation across their actions.

Its launch blog lists the native AI gateway as pre-beta, targeting Q4. Falcon Complete for Guardian is planned for later in Q3. OverWatch Cross-Domain hunting support is available, but requires both OverWatch Cross-Domain and Guardian.

The buying question is therefore quite specific: does the supported coverage match the agents, operating systems and execution paths your business uses? Ask for a demonstration that starts with a prompt and follows the resulting file access or command, including what happens when an action is blocked. The Guardian article goes further into that assessment.

Agentic IdP addresses the credentials behind the action

On 2 September, CrowdStrike announced its Agentic Identity Provider. The proposed model registers agents, gives them verifiable identities, brokers short-lived access and associates actions with the person or workload behind them.

That addresses an awkward question: when an agent acts through an employee’s account, can you stop the agent without disrupting everything the employee needs? Shared credentials make that difficult. Separate identities and narrowly scoped access give the business a more precise control point.

Before adopting it, map which applications can use that model and which still depend on long-lived keys. The announcement includes capabilities still in development; it is not evidence that every integration is ready.

Package protection reaches the developer’s endpoint

CrowdStrike also announced Real-Time Supply Chain Attack Protection, describing interception of npm and pip package installation, package-age policies, inventory and response. The release includes a warning that unreleased features remain subject to change.

This deserves attention wherever coding agents can install dependencies. Reviewing the final application is too late to prevent a malicious installation script from running on the machine that built it. Ask which package managers and sensor versions are supported today, and whether a block can be enforced before installation code executes. Keep dependency review and isolated build environments in place alongside endpoint protection.

Charlotte AI brings investigations and response controls together

The agentic SOC announcement describes coordinated investigations across security domains. It also introduces Charlotte Agentic SOAR as a workspace where customers set workflow autonomy, from human approval to automatic execution.

The business decision is how much authority to grant those workflows. Enriching an alert and disabling a production identity have very different consequences. Before enabling an automated response, define its scope, approval rules and recovery path. Ask to see the evidence behind an investigation’s conclusion, including what happens when sources disagree.

Start with one workflow you can explain

A useful first review might follow an AI coding agent from its laptop to a repository, a package registry and a deployment account. Name the owner of each permission. Establish what is logged, who receives an alert and who can stop the workflow.

That exercise makes the announcements easier to assess. Guardian concerns agent activity; identity controls concern access; package protection concerns what gets installed; SOC workflows concern investigation and response. A gap between them remains a gap even when the products share a console.

Businesses that have not yet mapped their AI use can start with Shadow AI discovery. Then choose a controlled pilot against a known workflow, with success measured by observable coverage and enforceable limits.

The cover is an AI-generated editorial illustration, not a photograph from Fal.Con.

← Back to all insights
Questions or inquiry? [email protected] Contact us →