The CrowdStrike co-founder and CEO used his Fal.Con keynote to discuss the unprecedented threat of hacking by autonomous agents—and make the case for bringing frontier AI to cyber defense teams.
Amid the unprecedented threat of hacking by autonomous agents, it’s increasingly pivotal to bring frontier AI capabilities to cyber defense teams—something CrowdStrike is now seeking to do for the first time in the industry, according to CrowdStrike co-founder and CEO George Kurtz.
During his keynote at CrowdStrike’s Fal.Con 2026 conference in Las Vegas Tuesday, Kurtz dissected the recent autonomous compromise of AI model platform Hugging Face by rogue OpenAI frontier models—and concluded that most of the industry “drew the wrong lesson” from the incident.
[Related: Jensen Huang: CrowdStrike Is Nvidia’s ‘No. 1 Cybersecurity Partner’]
A more damaging outcome was only avoided because the OpenAI agents had been given a limited goal—not because security tools stopped them, he said during the keynote.
“The company was spared because of the agent’s intent, not the defense,” Kurtz said. “I think as an industry, we got lucky, because it wasn’t really intent on damage.”
The reality, however, is that cyber defense teams need to be equipped with capabilities that can counter autonomous threats—which will inevitably be leveraged by threat actors who place no such limitations on their agents, he said. Rather than nation-state hacking groups constituting the “apex predator” of the threat landscape, “this is really the rise of the ‘agent state,’” Kurtz said. “Every [attacker is] now operating with nation-state capabilities.”
To better equip defenders in the era of AI-accelerated attacks, CrowdStrike on Tuesday unveiled its new SafeMind agentic system, which was created in collaboration with Nvidia. SafeMind provides autonomous offensive and defensive AI models that are capable of helping cyber defense to rapidly identify and close real-world security gaps, according to CrowdStrike.
The SafeMind models work by continuously attacking and deploying protections within a digital replica of an organization’s environment, the company said, and the system also features newly designed agent harnesses.
SafeMind is ultimately the industry’s “first complete agentic system for cybersecurity, including the first frontier models [that are] purpose-built for defenders,” Kurtz said during the keynote session Tuesday.
For Kurtz, the fundamental lesson from the Hugging Face incident is that the agents that carried out the compromise utilized frontier AI, while the defenders didn’t. “That changes now,” he said. “[CrowdStrike is] giving the power back to the defender. Adversaries have frontier capabilities. Now you do too.”
What follows are more of Kurtz’s boldest AI statements at Fal.Con 2026.
The ‘New Apex Predator’ In Cyberthreats
“For years, we ranked our adversaries in [a] pyramid. … Hacktivists were on the bottom, e-crime in the middle, nation-state on the top. … The top really represented the apex predator—the greatest capabilities, the most sophistication. The bottom [had] many more, least sophisticated. The pyramid existed for exactly one reason—the offensive capability was scarce. It took a nation to fund the talent, the tooling, the infrastructure, the patience. But the scarcity is over. … It used to be capabilities that separated the tiers. The apex predators were at the top—time, resources and sophistication. But the new apex predator is the agent. … What I mean by that is, this is really the rise of the ‘agent state.’ We hear about nation-state—it’s now the agent state. Because when apex capabilities become a prompt, guess what happens? There are no tiers at all. Every [attacker is] now operating with nation-state capabilities. The pyramid has just been obliterated.”
Cyberattacks At ‘Inference Speed’
“For years, I stood on a stage like this one and tracked this number called breakout [time]—62, 48, 29 [minutes]. The fastest one that we saw last year was 27 [minutes], and we called that machine speed. We were wrong. I was wrong. This was human speed with better tools, and breakout time is over. I don’t know what we’re going to do for next year’s report, but we’re going to have to come out with another metric—because it’s gone. But this is what I want you all to understand: Attacks now happen at inference speed. Think about that. Attacks are happening at inference speed. And when an attacker has inference speed, there is no breakout time. There’s actually no time at all to deal with these attacks.”
Intent, Not Security, Stopped The Hugging Face Attack
“The [Hugging Face] intrusion succeeded. Credentials were stolen. Forged identities and tokens stolen. They held admin access across multiple internal clusters. But this is an important point—intent stopped the attack. What did they want to do? Those agents wanted to pass the test—goal-seeking in a way that I think we’ve never seen before in cybersecurity. It’s really powerful and fascinating. The agent was cheating, but it wasn’t trying to do damage. So let me make it clear: The company was spared because of the agent’s intent, not the defense. … Security saw it, generated a lot of information. But it failed to raise enough alarms that the administrators were paged. It cost them time. They saw some activity and didn’t know how to put it all together. By the way, this is not a knock on anyone. You have a sophisticated company with incredible people, but it’s a lot of data they have to go through. And these agents, again, are acting in an autonomous fashion … This is not a hypothetical threat. This is something that happened. And again, I think as an industry, we got lucky, because it wasn’t really intent on damage.”
Frontier AI For Everyone-Except The Defenders
“The best AI on earth was built for everyone. Remember what happened in Hugging Face. They turned to AI for the forensics, and the model refused. The guardrails that stopped the model from writing exploits, stopped one from taking it apart. In the moment of crisis, the best AI on earth was really built for everyone, except for the folks in the audience [at Fal.Con]—except for the defenders. Think about that. The best AI on the planet was built for everyone but the defenders. General-purpose models are general-purpose. However, as defenders, we need models that are built for defenders—that understand security, that have been trained on some of the largest datasets in the world.”
The Real Lesson Of The Hugging Face Attack
“Most people drew the wrong lesson from Hugging Face. Some saw [the] autonomous agents act in a way that we haven’t seen before. Some saw the swarm. Some read about the message boards. Some saw about [agents] covering up their tracks. And some saw the agents work as a collective group for the good of the entire group. But the real gap that I saw was that the attackers had frontier AI, and the defenders didn’t. And that changes now … [CrowdStrike is] giving the power back to the defender. Adversaries have frontier capabilities. Now you do too.”





