The launch of CrowdStrike’s SafeMind frontier AI models, created using Nvidia’s Nemotron open models and specialized harnesses, includes cost reduction as one of its goals in addition to boosting AI-driven security outcomes, according to CrowdStrike CEO George Kurtz and Nvidia CEO Jensen Huang.
The use of open AI models and specialized harnesses is expected to be increasingly pivotal to making agentic-powered security tools financially sustainable into the future, as underscored by the launch of a new set of CrowdStrike-Nvidia frontier AI models this week, experts at top CrowdStrike solution provider partners told CRN.
While numerous other vendors are building promising technologies for the “agentic SOC” (Security Operations Center), the cost of relying heavily on premium frontier AI models could create major challenges and constraints moving forward, according to Chris Ebley, CTO at Annapolis, Md.-based Blackwood, No. 96 on CRN’s Solution Provider 500 for 2026.
By contrast, the approach unveiled by CrowdStrike and Nvidia showcases the potential cost advantages of open models alongside specialized training and harnesses, Ebley said. CrowdStrike’s new SafeMind agentic system, which was created using Nvidia’s Nemotron open models, was unveiled Tuesday at Fal.Con 2026 by CrowdStrike co-founder and CEO George Kurtz, who was joined on stage by Nvidia co-founder and CEO Jensen Huang.
Solution provider experts told CRN that while accelerating cyber defense through greater autonomous capabilities is the foremost goal, being able to limit the costs of frontier AI models is an important consideration as well. Frontier cyber models from leading platforms, such as Anthropic’s Claude Mythos model and OpenAI’s GPT Cyber models, have been singled out as particularly expensive by security experts in recent months.
“At the end of the day, for any of this to be sustainable, the use of open models—the use of non-premium frontier models for costing purposes—is huge,” Blackwood’s Ebley said.
The current reality is that many agentic SOC vendors are mainly focused on building wrappers and harnesses—which provide instructions and tools for leveraging powerful, general-purpose models—rather than developing or customizing models themselves, according to Ebley.
“The majority of the AI SOC space right now—they’re building wrappers, they’re building harnesses, they’re giving guidance to models—but they are using frontier models,” he said. “These are premium models that have a very real cost to them.”
For many startups, that can create a situation where increased customer adoption leads to surging model expenses, which may not continue to be absorbable over time, Ebley said.
The risk for some startups—which are relying on venture investment to afford general-purpose frontier AI—is that “you’re not going to survive. You will run out of money at the token burn rates that you’re seeing,” he said.
On the other hand, “companies like CrowdStrike are uniquely positioned because [they] have a large enough war chest to be able to actually lean in on model development,” Ebley said. “If you can take your time and build a small language model that has high levels of efficacy, you will win in the end, [ultimately avoiding] huge amounts of compute costs.”
Without a doubt, the use of open models could help ensure that security teams are able to take full advantage of AI and agentic capabilities without having to continually worry about usage costs, said Jordan Hildebrand, global cyber practice director at St. Louis-based World Wide Technology, No. 10 on CRN’s Solution Provider 500 for 2026.
Ultimately, the goal should be to remove any cost-related concerns from SOC analysts, who already have a highly demanding and critical role and should be empowered to utilize AI whenever it’s likely to improve security outcomes, Hildebrand said.
In other words, the focus with AI model adoption in the SOC should be on doing “whatever’s going to make that easier for the teams,” he said. “The SOC analyst doesn’t care [about], ‘How many tokens have you got? What did you spend? How many times did you search?’”
Open models certainly have the potential to significantly reduce such constraints, according to Hildebrand.
“If we are able to leverage these open LLMs as open models, I think it’s going to be incredible for alleviating any type of burden that could go on,” he said.
All in all, by incorporating lower-cost AI models into its platform, CrowdStrike has the potential to democratize advanced AI-powered defense, making it available more broadly than just at the largest well-funded enterprises, Hildebrand said.
“You now have this economically safe [option]—CrowdStrike is now providing that,” he said. “I think it’s security for all, versus just for the elite or for the wealthy.”
CrowdStrike’s SafeMind system combines newly developed offensive and defensive AI models—Red Tempest for offensive security and Blue Solano for defense—with new agent harnesses.
The SafeMind models work by continuously attacking and deploying protections within a digital replica of an organization’s environment, the company said.
SafeMind is ultimately the industry’s “first complete agentic system for cybersecurity, including the first frontier models [that are] purpose-built for defenders,” Kurtz said Tuesday during Fal.Con 2026 in Las Vegas.
In addition to utilizing Nvidia’s Nemotron open models, SafeMind’s specialized training and harnesses also assist with reducing the cost associated with achieving strong, AI-powered security outcomes, Kurtz said.
“The harness makes a massive difference, and the training makes a massive difference, to get to the best outcome with the lowest cost,” he said. “[The harness] really is the 10X factor in getting additional results at the lowest cost.”
Crucially, CrowdStrike is continuing to enable the usage of proprietary frontier models within its Falcon platform, CrowdStrike executives said during Fal.Con 2026. Customers will be able to use any combination of CrowdStrike’s models, other frontier models and open-source models, Kurtz said.
“For me, it’s important to talk about choice. Because I want to be clear about this—we’re not going to lock you into our models,” he said.
“If you want to use our models, if you want to use frontier models [or] you want to use open-source models—or you actually want to put all the models together—that’s fine, Kurtz said. “It’s an open ecosystem, and we’re not talking about vendor lock-in. But we want to give our customers choice in what they want to use as part of the overall platform.”
At the same time, Huang emphasized during the discussion Tuesday that Nemotron was developed specifically to enable major vendor partners—such as CrowdStrike—to create customized, efficient models for highly specialized needs such as cybersecurity.
Obviously, “we should use closed models and proprietary models and off-the-shelf [models] as much as you can. Why build something unless you have to build?” Huang said. “However, there are many applications in the world where you have to. You must have the ability to fine-tune, to post-train—to, in the context of SafeMind, create an AI that is super good at a particular domain.”
There’s no question that “we don’t need every AI to be super smart at everything. But in some areas, we need to be extraordinarily good at something—and cyber defense is something we want to be incredibly good at,” Huang said.
Thus, Nemotron was created “for precisely that—to enable you, enable CrowdStrike in partnership with us, to create a super intelligence who is incredible at cyber defense,” the Nvidia CEO said. “And it was also created in a way that is very cost-effective. It was designed to be both smart but also fast.”
Ultimately, “with Nemotron being cost-effective,” Huang said, security vendors such as CrowdStrike “have the ability to have an asymmetric advantage against whatever comes your way.”
Blackwood’s Ebley said the potential for uniting a lower-cost open model with a high-efficacy harness is a powerful combination for SafeMind.
Generally with such an approach, “what we’ve seen in terms of efficacy is that you can take, I’ll call them lower-tier models with high-efficacy harnesses, and achieve very positive results,” he said.
Developing this type of capability, however, often requires substantial up-front investment—potentially giving large security vendors such as CrowdStrike a leg up over startups that depend on third-party frontier models and venture backing, according to Ebley.
“You have to have a lot of money to be able to go develop the thing that will eventually cost you way less money,” he said. “For a company with [limited] funding coming out of their Series A—that’s going to go fast.”





