CrowdStrike Holdings, Inc. Class A Common Stock Fal.Con Day 2
Review the key takeaways and the transcript of this earnings call.
- CrowdStrike highlighted the transformative impact of AI on cybersecurity, emphasizing that AI changes who or what can act and how trust is established in digital environments.
- The company introduced Falcon Guardian, a new AI detection and response solution that provides runtime visibility and control over AI agents on endpoints, preventing unauthorized actions and data exfiltration.
- CrowdStrike demonstrated how its platform can detect and block malicious AI agent activities, including credential theft and unauthorized package installations, leveraging integrated supply chain protection policies.
- The CrowdStrike Agentic SoC was showcased as an autonomous security operations center that triages, investigates, and resolves threats at machine speed with human oversight, enabling coordinated investigations across endpoint, identity, and cloud data.
- CrowdStrike announced the CrowdStrike Agentic identity provider solution to enforce continuous, task-specific, and short-lived access for AI agents, enhancing identity governance and reducing standing privileges.
- The company emphasized the need for AI governance, runtime security, and integrated platform solutions rather than isolated products to address the evolving AI-driven threat landscape.
- Adam Myers discussed the rapid increase in AI-driven detections, the acceleration of vulnerability discovery and exploitation, and CrowdStrike's role in responsible disclosure and threat hunting.
- CrowdStrike introduced Falcon adversary Overwatch for cross-domain threat hunting across AI, endpoint, identity, cloud, and next-gen SIM environments.
- The company released new AI-powered agents for threat intelligence and dark web reconnaissance, enabling faster prioritization and automated response to exposures and adversary activities.
- Customer case studies from United Airlines, Salesforce, Providence Health and Services, Mondelez International, and Anthropic highlighted successful adoption of CrowdStrike's AI-driven security platform and transformation initiatives.
- Amazon CISO CJ Moses shared insights on the scale of threat interactions observed, the speed and automation of AI-driven attacks, and the importance of integrated identity and control for AI agents at the endpoint.
- Moses emphasized that AI does not create new attack types but accelerates existing ones, and that defenders must leverage AI tools effectively to maintain security.
- Moses praised CrowdStrike's Guardian solution and discussed the need for a distinct AI agent identity with scoped, task-specific permissions enforced at the infrastructure level.
- The event celebrated the power of community, partnerships, and collaboration in advancing cybersecurity in the AI era, with NVIDIA recognized as CrowdStrike's 2026 Global Partner of the Year.
STOCKNOW INSIGHTS
Continue with outlook and guidance.
Log in to unlock executive comments and Q&A highlights.
Log in for the full summaryStockNow uses AI to translate and summarize earnings calls. Accuracy and completeness are not guaranteed.
Transcript
Preview the first fifteen paragraphs, organized by speaker.
Please welcome President of CrowdStrike, Michael Sentonas.
Morning, Stockholm. Welcome to day 2. I hope everyone had a great first day yesterday. I hope you all got a chance to head over to the expo hall or got a chance to walk around. I kind of realized that this AI thing is a bit of a big deal, huh? There is a lot of AI everywhere, and it is obviously something that I am going to be talking a lot about. Here is the thing, there is a reason why AI is dominating every conversation, and there is a reason why you are seeing it all over social media. We are watching the biggest technology transformation of our generation unfold right in front of our eyes. Every major shift in technology forces a security transformation. Cloud did it. Mobile did it. The internet did it. AI will dwarf them all.
That creates an extraordinary opportunity for businesses, an opportunity for defenders, for all of us. Unfortunately, it creates incredible opportunity for the adversary. You heard this yesterday. I believe we crossed the line. In the last few weeks, we have seen something fundamentally change. Agents have escaped evaluation environments. They have discovered vulnerabilities. They have moved across systems. They have compromised infrastructure they were never supposed to touch. We crossed a line. It is a big thing to say, but I think it is the right thing to say. We have seen AI agents pursue an objective, encounter an obstacle, change their approach, and keep going straight through. Adam is going to talk to you a lot today about how we are seeing AI used to orchestrate attacks against real-world targets. Think about what has changed. The software we use has become an actor. For decades, software did what we programmed it to do.
Now, software can decide how to accomplish a goal. It has moved from execution to agency. Think about that concept. That changes cybersecurity. The question is no longer can AI conduct a sophisticated cyber attack? We know it can. We have seen that. We have talked about it. The question now really becomes what happens when millions of AI agents can act, and sometimes together, at machine speed on both sides? Software has agency. Think about that concept. Are we, as defenders, ready for that? Because this is bigger than cybersecurity. Every company, every employee, every developer, every attacker is using AI. There is not a person in this room that is online that is not using AI. But AI is different from every computing revolution that came before it. The PC changed where we compute. The internet changed how we connect, how we communicate. Mobile changed where we work.
Cloud changed where applications run. AI changes who or what can act, and that changes something more fundamental. AI changes how we trust. A couple of big topics for the morning here. It also changes just everything about how we think about what we have spent years protecting. Applications, devices, identities, infrastructure, data, those things all still matter. Of course, they do. They always will. AI is changing every one of them. There is not a single thing on that slide that is not being changed. Many of you are already writing code with AI. Your coworkers are using enterprise and public models. You are deploying agents with access to your systems and your data. They are touching your identity. Cloud workloads are more dynamic than ever, and human and non-human identities are multiplying faster than anyone can govern them. Here is the thing, AI is part of the enterprise.
The business is driving it. The business is wanting it. Everybody is adopting it. The enterprise is not simply using AI anymore. AI is part of the enterprise. Once AI becomes part of the enterprise, it becomes part of what we have to defend. We all understand that, but it is also now changing how we defend. The speed of innovation, the speed of exploitation, we are going to talk a lot more about that in Adam Meyers' session. Those two numbers coming closer together. While we are thinking about regulation, we are thinking about privacy, you have AI lawyers. The adversary does not care. They are not waiting. They are using it for reconnaissance, for vulnerability research, exploit development, social engineering. The agent breakout that we discussed yesterday, think about that. This is not what AI might do in the future. This is not pondering about what is going to happen at Black Hat in five years.
This is what it did on its own. That debate is now over. The question is not whether AI changes cybersecurity. It is about who uses it better, and it is a very simple question. Do you use it better, or does the adversary use it better? Very simple. When we start to think about how this all works, you are the adversary, and we start to think about where this is all going to play out, it gets answered on the endpoint, on your agents. This is where we start to talk about AI Detection and Response. Let us talk a little bit about AI governance. Organizations heavily investing in it, discovery, posture, policy, compliance, those things all matter. Of course they are. I am not going to tell you they do not. They all answer one question, what could happen?
The question that I want answered, the question that I want to answer with you all is what is happening right now, because AI does not necessarily run on simple policy, it executes at runtime. Tool calls happen at runtime. Threats unfold at runtime. We have seen this before. We know this story. The internet created network security. The endpoint created EDR. The cloud created cloud security. Just like EDR secured the endpoint at runtime, AI needs its own runtime category. We call that AI Detection and Response. Here is the fundamental change. AI agents do not just generate answers, they take action. We have talked about this. The architecture goes well beyond just agents. You have models, you have identities, you have data, you have applications, there is infrastructure. All of this has to be protected.
You need to secure how AI is built, how it is accessed, how it behaves, what it is allowed to do at runtime. This requires a totally different category. AIDR brings this all together, discovery, posture, identity, data protection, runtime guardrails and response across SaaS, endpoint, cloud. This is not just another security product. I talked about this. EDR defined how we secured the endpoint, AIDR defines how we secure the AI estate. Guardian is how CrowdStrike delivers it. George introduced this yesterday, incredibly proud to see this announcement. The product went live at the very minute George put that slide up, which is absolutely fantastic. I want to show you why it matters. Because once AI becomes part of the enterprise, visibility is no longer enough. You need to know what is running, what it can access, what it is doing, where to draw the line.
That is Guardian. It gives you runtime visibility across the entire AI estate, what your agents are doing, what they are accessing, what actions they are taking, whether you know about it or not, and where you need to step in, importantly, before something goes wrong. We know everybody is talking about securing AI. The industry is talking about it. When we talk about Guardian, what is really, really exciting about this is we have been running this inside CrowdStrike for some time. We have people in this room that have been running this for some time. We want our people at CrowdStrike building with AI. We do not want to slow that down. We want to use the power, the benefit, the advantages that comes, but we need to know what everybody is doing. We need to know what every agent is doing, where it is deployed, and who is using it.
We want to set the rules for what people can use and what it can do. That is what we use it for. Let me show you how it works. Incredibly proud to show you a big demo. Roll the demo of Guardian.
Introducing Falcon Guardian, our new solution for securing AI agents where they execute, on the endpoint, at runtime. The Falcon sensor now extends to AI agents. No hooks, no SDK. Guardian fuses AI and OS telemetry from prompt to process across your entire AI estate. Let us see this in action. Last month, a Fortune 500 company found 18,000 AI agents running across their endpoints. They approved 300. Every dot you are looking at is an AI agent running right now discovered by Guardian on day one, from OpenAI Codex, Claude Code, Cursor, and Kiro to unclassified shadow AI. Active, dormant, or hiding in plain sight, they are detected by sensor, scheduled scans, and DNS queries. You see them, now you can control them. Start with the simplest case. Ken, in customer service, is working on a billing dispute. He reaches for Gemini out of habit. It is what he uses at home.
Guardian blocks it and points him to Claude, the approved app. He moves to Claude and pastes in the customer record, including a full credit card number. Guardian masks it at the prompt. The number never reaches the model. Ken gets a policy notice, the security team gets the event. Ken was typing. Agents do not type, they act, and they can act on text that is invisible to humans. Marcus in engineering prompts Claude Code to debug a Lambda deployment and walks away. The agent gets to work. Unaware, Marcus just put his whole company at risk. Falcon Guardian brings these risks into sharp focus. In a cluster of high-risk Claude Code agents, one lights up as critical with a threat score of 90. Guardian identifies it as Marcus' agent and resolves it to his AD identity.
Unknowingly, his agent introduced three critical risks, a malicious skill, an attempt to transmit data to an external destination, and AWS credentials were accessed outside of their expected scope. His agent footprint shows every skill, tool, MCP server, and connection, feeding one composite threat score. The sensor builds a single causal timeline, prompts, skills, and tool calls from the agent fused with process spawns, file reads, and network egress from the operating system. One story end to end. This is the agent graph. Marcus' agent follows a link in the repo docs to a GitHub issue thread. Buried in that thread, a hidden instruction, an indirect prompt injection. It tells the agent to load a skill and exfiltrate Marcus' credentials. Marcus never sees it. Guardian stops it. The credential exfiltration is blocked before the keys leave the machine. Where else is the skill running?
In an AI first world, security teams can now use their agents to directly investigate these events with the Falcon MCP server. In Claude Code, an analyst queries the Falcon platform for agents that have previously used the skill. 12 found, every attempt blocked, no credentials left any machine. The hosts are quarantined for investigation. That was the prompt layer. Here is an attack that never touches it. On another workstation, Claude Code installs a new plugin from a public repo. It registers a local MCP server to assist with project indexing. The prompt layer looks clean, the model is not being manipulated. But that MCP server quietly performs credential theft and exfiltration on each tool call to index project. The sensor layer catches the exfiltration. Prompt-only security tools see a clean plugin. The sensor sees the attack. That is layered protection. Now the operational side.
FULL TRANSCRIPT
Continue the full translated transcript in StockNow.
Log in to unlock every statement, the English original, and speaker-by-speaker history.
Log in for the full transcriptCall participants
7 people spoke on this call — only 1 are shown here.
PARTICIPANT LIST
View participant details in StockNow.
Log in to see executives and analysts, their roles, and complete speaking history.
Log in to view all participantsKeep exploring
