Skip to main content
CrowdStrike AI training on private threat data with NVIDIA Nemotron, cybersecurity, data analysis, machine learning.

Editorial illustration for CrowdStrike Trains AI on Private Threat Data Using NVIDIA Nemotron

CrowdStrike Trains AI on Private Threat Data Using...

3 min read

CrowdStrike used NVIDIA's Nemotron open models as the base for a new defensive AI system, post-training them on its own threat data gathered from years of incident response and endpoint monitoring. The announcement came Tuesday at Fal.Con 2026 in Las Vegas, where CrowdStrike CEO George Kurtz and NVIDIA founder Jensen Huang unveiled CrowdStrike SafeMind before a crowd of 10,000 security professionals. The system, built by CrowdStrike's Cyber Superintelligence Lab, pairs the company's own frontier-capable models with Nemotron-based defensive models in what the two companies describe as a continuous loop, offense and defense models sparring against each other and improving in the process.

The launch landed alongside two other announcements: CrowdStrike Falcon IQ, aimed at operationalizing something called Project QuiltWorks through automated agentic workloads, and an expansion of the company's Guardian AI safety product. Attendees at Fal.Con this year included security leaders from banks, hospitals, government agencies and infrastructure operators, all facing the same problem Kurtz has been flagging for months: attackers already have frontier AI tools, and until now, defenders mostly didn't.

SafeMind combines CrowdStrike’s purpose-built, beyond frontier-capable models and customized agentic harnesses, with defensive models built on NVIDIA Nemotron, in a continuous coevolution loop where offense and defense repeatedly challenge and improve each other.

Why this matters

The interesting part isn't SafeMind itself, it's the mechanism. CrowdStrike took an open model, Nemotron, and post-trained it on threat data it never had to hand to NVIDIA or anyone else. That's the part worth watching if you build or buy security tools: a closed API model can't offer that arrangement, because the provider controls the weights and often the training loop too.

Open weights let CrowdStrike keep its telemetry in-house while still getting a frontier base model to build on. For founders in security or any regulated vertical, that's the pitch to study, not the "asymmetric advantage" line Huang gave the Fal.Con crowd. Sovereignty over training data, paired with a capable open base, is going to be a recurring architecture choice, not a one-off.

We'd push back gently on the "new age of cybersecurity" framing, that's convention-stage bravado, but the underlying technical move, post-training an open model on proprietary threat data without exporting it, is a real template. Expect competitors and customers alike to ask why they aren't doing the same thing with their own data.

LIVE05:25CrowdStrike Trains AI on Private Threat Data Using NVIDIA Nemotron