CrowdStrike redefines cybersecurity with agentic AI
The integration of OpenAI and Anthropic marks a shift toward autonomous defense through the strategic use of AI 'harnesses'.
September 9, 2026 · 4 min read
TL;DR: CrowdStrike has integrated GPT-5.6 Cyber and Claude into its Falcon platform to automate defense via agents. This move, focused on the use of AI 'harnesses', allows companies to convert model budgets into operational cybersecurity capabilities.
The new frontier of defense: beyond detection
CrowdStrike's annual Fal.Con conference in Las Vegas has made it clear that the cybersecurity industry has moved past the era of passive detection and into the age of agentic systems. Historically, defensive security has operated under a 'notification and human response' model, where tools alerted of an anomaly and an analyst intervened. However, the volume and speed of contemporary threats, powered by offensive AI, have rendered this approach obsolete. CrowdStrike is now proposing a paradigm shift: the transition toward autonomous defense systems that not only analyze, but execute countermeasures in real time.
The key to this evolution lies in the concept of the cyber harness, a technical framework that acts as a conduit between Large Language Models (LLMs) and operational security tools. This 'harness' solves the problem of hallucination and the lack of specific context in general models, allowing the AI to maintain focus on critical security tasks, transforming the raw power of artificial reasoning into tactical and precise response capability.
OpenAI inside the product: The GPT-5.6 Cyber case
The integration of GPT-5.6 Cyber into the Falcon platform, launched under the Frontier AI Readiness and Resilience initiative, represents an unprecedented strategic deepening. Unlike the superficial integrations we have seen in the sector over the last two years, CrowdStrike is embedding the model directly into the core of its platform. The goal is to solve an emerging security gap: the uncontrolled proliferation of code agents (Codex) and generative AI tools within corporations.
With the deployment of Falcon Guardian, the company introduces a vital layer of governance. In an enterprise environment where employees deploy AI agents to automate workflows without proper oversight from the IT department, visibility has become the greatest challenge for CISOs. GPT-5.6 Cyber allows for auditing which agents have access to which resources, establishing a hierarchy of privileges and automated remediation priorities. It is, in essence, the application of AI to audit AI itself, a level of meta-governance that will be the standard in enterprise software over the next five years.
Anthropic and the agent market: The operating model
If the integration with OpenAI is a bet on operational depth, the collaboration with Anthropic is an exercise in market architecture. By integrating the Falcon platform into the Claude Marketplace, CrowdStrike is not only facilitating technical access, but is also hacking the corporate spending model. Many companies already have spending commitments (commitments) in the cloud or with AI model providers; allowing these budgets to be applied directly to the acquisition of cybersecurity tools eliminates significant financial friction in the B2B buying cycle.
The launch of Charlotte AI AgentWorks is, perhaps, the most disruptive proposal of the event. It allows security teams to define objectives in natural language, delegating technical execution to agents operating within the Claude ecosystem. Historically, configuring a firewall rule or isolating an infected host required deep technical knowledge of the platform's syntax; now, natural language becomes the user interface. This democratizes cybersecurity, allowing less experienced analysts to execute advanced-level operations under the supervision of Anthropic's agents.
Analysis: The 'harness' factor and the Booz Allen lesson
The concept of a 'harness' is not mere marketing rhetoric. According to the recent Cyber Weapon Index published by Booz Allen, the performance of an AI in cybersecurity depends 80% on its support structure. In their tests, a model like Claude Sonnet 5 barely reached 13 points out of 100 in cybersecurity tasks when operating in isolation. However, when connected to a robust 'harness'—the software that keeps the model on task and gives it access to the correct APIs—its effectiveness soared to rival the best tools on the market, reaching 80 points.
CrowdStrike has understood that the same engineering that attackers are using to scale their phishing and vulnerability exploitation campaigns (the use of agents with connected tools) is what the defense must adopt. The company is applying this architecture in reverse. It is an arms race where the advantage will not go to the one who possesses the largest model, but to the one who possesses the 'harness' most integrated with the company's operating systems.
Despite the enthusiasm, there is an intrinsic risk. As Greg Brockman of OpenAI rightly pointed out, status quo security is insufficient, but total automation carries dangers. The possibility of false positives or an agent making blocking decisions that interrupt critical business processes is a legitimate concern. Although CrowdStrike ensures that these operations occur under human supervision, the ability of CISOs to oversee agents operating at millisecond speeds will be the next great management challenge. We are at the beginning of an era of 'autonomous security' where the human moves from being the executor to the supervisor of a digital workforce.