
CrowdStrike and OpenAI have expanded their partnership to secure AI agents while they are operating, bringing OpenAI’s Codex agents into CrowdStrike’s Falcon Guardian security platform and adding OpenAI’s GPT-5.6 Cyber to planned Falcon capabilities.
The companies announced the partnership on September 2, 2026, during Fal.Con 2026 in Las Vegas. The deal extends CrowdStrike’s enterprise security capabilities to supported Codex agents and combines OpenAI’s cyber reasoning capabilities with CrowdStrike’s security data and threat intelligence.
The announcement follows CrowdStrike’s introduction of Falcon Guardian on September 1. CrowdStrike describes Guardian as an AI Detection and Response system designed to provide visibility, governance and runtime security for AI agents across enterprise environments.
For Codex, the new integration is designed to go beyond monitoring. CrowdStrike says Falcon Guardian can control supported Codex agent activity at runtime, allowing organizations to see what agents are doing, identify compromised or unauthorized behavior and take action while those activities are taking place.
The controls are designed to operate across endpoint, SaaS, cloud and browser environments.
Organizations will also be able to maintain a live inventory of supported Codex agents operating across the enterprise. That inventory is intended to show which agents are running, who deployed them, what they can access and their security status.
Falcon Guardian can connect Codex activity with CrowdStrike telemetry so security teams can see agent actions in real time. CrowdStrike says this allows organizations to connect an agent’s activity with downstream processes and system actions rather than viewing those events separately.
The platform can also be used to define which supported agent actions are allowed. CrowdStrike says this translates governance policies into enforceable controls at runtime.
That approach is a central part of the companies’ announcement. Instead of relying only on policies that determine how AI should be used, the integration is designed to provide controls capable of acting while an agent is executing.
CrowdStrike says Falcon Guardian can detect compromised AI agents, reconstruct what happened and determine the potential blast radius across affected agents and systems. It can then deploy containment actions intended to stop an attack before it spreads.
The company identifies prompt injection and poisoned tools among the threats that can affect AI agents. Its Guardian platform is designed to inspect AI interactions at runtime and detect malicious activity before it can manipulate agents, expose sensitive information or trigger unsafe actions.
CrowdStrike says its internal benchmark testing has shown 99% detection efficacy for prompt attacks and detection latency of 100 milliseconds or less. The company notes that these performance figures are based on internal benchmark testing.
Guardian is broader than the new Codex integration. CrowdStrike says it can discover AI use and agents across endpoints as well as cloud and SaaS environments, helping security teams identify so-called shadow AI activity outside established organizational controls.
The system is also designed to protect sensitive information in AI interactions. CrowdStrike says its security policies can redact, encrypt or block sensitive data before it is exposed through AI services.
CrowdStrike is also developing an AI Gateway capability for Falcon Guardian. The company says the gateway will centralize visibility and control over enterprise AI traffic and allow policies to be informed by Falcon context involving users, agents, endpoints, identities, assets and security posture.
That AI Gateway capability has been announced as coming soon and should therefore be distinguished from the capabilities CrowdStrike has already introduced.
AI-agent activity is also being incorporated into Falcon Next-Gen SIEM. CrowdStrike says telemetry from AI agents can be treated as first-party Falcon data and correlated with identity, cloud, SaaS, endpoint and other security events.
The company says keeping this telemetry within Falcon can help organizations correlate AI-agent activity with the wider security environment without having to send all of the data to separate SIEM platforms.
CrowdStrike is extending its managed security services to Guardian as well. Falcon Complete for Guardian is designed to provide 24/7 detection, investigation and response for AI agents, while Falcon Adversary OverWatch for Guardian extends threat hunting to AI-agent activity.
The second part of the partnership focuses on OpenAI’s GPT-5.6 Cyber.
CrowdStrike says it will bring GPT-5.6 Cyber’s advanced cyber reasoning into the Falcon platform, beginning with its Frontier AI Readiness and Resilience Service, known as FAIRR, before expanding the use of the technology across Falcon.
According to CrowdStrike, FAIRR will combine GPT-5.6 Cyber with adversary intelligence, security expertise, structured threat modeling, exploit validation and workflow orchestration.
The objective is to use the model with security-specific context so that defenders can assess risks, analyze attack paths and prioritize remediation.
CrowdStrike says its Falcon platform already combines real-time indicators of attack, threat intelligence, adversary tradecraft and telemetry collected across enterprise environments. The planned GPT-5.6 Cyber integration is intended to add advanced cyber reasoning to those existing capabilities.
The partnership builds on earlier cooperation between the companies.
In August 2025, CrowdStrike announced an integration with the OpenAI ChatGPT Enterprise Compliance API. CrowdStrike said its Falcon Shield technology could discover GPTs and Codex agents created within ChatGPT Enterprise while expanding SaaS visibility across more than 175 applications.
The relationship expanded further in March 2026 when OpenAI selected CrowdStrike for its Trusted Access for Cyber program. CrowdStrike has also said OpenAI models are being used across parts of its Falcon platform, including its AgentWorks framework.
OpenAI has been developing its own security controls around Codex alongside these partnerships. In its Codex security guidance, OpenAI describes controls including managed configuration, constrained execution, network policies and agent-native logs.
OpenAI says Codex does not operate with unrestricted outbound network access in its managed environments. Its controls can allow expected destinations, block unwanted destinations and require approval for unfamiliar domains.
Codex also supports OpenTelemetry logging for events such as user prompts, tool approval decisions, tool execution results, MCP server usage and network proxy allow or deny events. OpenAI says these logs can be centralized in SIEM and compliance systems.
Those capabilities are important because conventional endpoint logs can show that a process ran, a file changed or a network connection was attempted, but they may not explain the user’s original request or the agent’s reasoning context. OpenAI says Codex telemetry can provide that additional agent-aware context.
The expanded CrowdStrike partnership adds another layer to that model by connecting Codex activity with Falcon’s endpoint and enterprise security telemetry.
OpenAI has separately positioned GPT-5.6 Cyber as a cybersecurity-focused model for approved defensive work, including vulnerability research, exploit validation and security testing. Access to those capabilities is subject to OpenAI’s trusted-access controls.
With the expanded partnership, CrowdStrike is positioning Falcon Guardian as a point where AI-agent activity can be observed, governed, detected and controlled while an agent is executing, while OpenAI’s cyber model is being positioned as a reasoning layer for security assessment and defensive workflows.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

