Nvidia and CrowdStrike (NASDAQ: CRWD) said at this year’s Fal.Con conference that they have entered a strategic partnership focused on automated cyber defense. The two companies introduced SafeMind, an AI defense system designed to evolve over time by combining open-source models with security data. The project also uses CoreWeave’s AI cloud services for model training and inference.
SafeMind targets AI-driven automated attacks
The announcement comes as AI-powered attacks have risen sharply over the past year, with intrusion times getting shorter and leaving less room for human-led response. CrowdStrike said it worked with Nvidia to build SafeMind as a proactive security system. Led by CrowdStrike’s Counter Adversary Operations and cyber research capabilities as described in the source text, the system combines 15 years of digital threat data with NVIDIA Nemotron open-source models and uses a customized architecture to split defensive tasks across agents.
Core parts of the partnership
- CrowdStrike’s 15 years of accumulated data are combined with NVIDIA Nemotron open-source models.
- NVIDIA Nemotron 3 Ultra is used to coordinate the Defensive Agent Harness.
- NVIDIA Nemotron 3 Super powers the Rule-Generation Sub-Agent inside SafeMind.
- A customized harness architecture serves as the large language model support layer.
Digital twin environment for red-team and blue-team testing
Nvidia and CrowdStrike also built a digital twin simulation environment for red-team and blue-team exercises. SafeMind’s simulation framework runs on a Digital Twins network agent environment jointly developed by the two companies and is used to validate performance under real-world threat scenarios.
In that setup, red-team and blue-team agents operate under an adversarial coevolution model, staying in a continuous cycle of attack and defense. Red-team agents carry out reconnaissance, attacks, and intrusion attempts in order to uncover weaknesses. Blue-team agents monitor activity through sensors, generate defenses in real time, and block malicious actions. As new vulnerabilities are discovered by the red side, the blue side patches them and converts them into detection rules, with the cycle continuing until attacks can no longer succeed. The source says this process improves defensive accuracy.
How Nemotron models are split inside SafeMind
Different Nemotron models handle different functions in the SafeMind architecture. NVIDIA Nemotron 3 Ultra acts as the coordinator and orchestrates the defensive agent harness. NVIDIA Nemotron 3 Super, after fine-tuning, drives the system’s rule-generation sub-agent.
Falcon IQ launches alongside SafeMind
Along with SafeMind, Nvidia and CrowdStrike also introduced Falcon IQ, a multi-agent automation platform built for proactive workload management. The platform runs in a no-code agent development environment, is powered by Nemotron models, and can coordinate more than 50 AI agents.
According to the release summary, Falcon IQ turns time-consuming security assessment, threat prioritization, and remediation work into automated workflows. By dividing tasks across multiple agents, the platform is intended to reduce the operational burden on security teams and shorten response times.

