CrowdStrike Adds AI-Agent Runtime Controls Through Google Cloud and OpenAI
The Fal.Con rollout puts CrowdStrike’s controls closer to the point where enterprise AI agents act on connected systems. The unresolved commercial question is whether customers turn those integrations into broad, profitable platform adoption.
Listen to this story
The audio brief
Story brief
3 key pointsCrowdStrike is extending Falcon Guardian beyond conventional endpoints into enterprise AI workflows: Google Cloud deployments use Agent Gateway and Gemini Enterprise, while supported OpenAI Codex agents receive monitoring and action controls at execution time. The OpenAI partnership also plans to add GPT-5.6 Cyber to Falcon’s FAIRR service for authorized defensive analysis. The announcements establish integrations...
- 01
September 1: Falcon Guardian was announced for Google Cloud’s Agent Gateway and Gemini Enterprise workflows.
- 02
Codex controls include agent inventory, access visibility, Falcon telemetry, behavior detection, and permitted-action enforcement.
- 03
CrowdStrike cites prompt injection, sensitive-data leakage, and malicious AI activity as Google Cloud detection targets.
CrowdStrike is taking Falcon Guardian into enterprise AI systems run through Google Cloud and OpenAI’s Codex agents. The releases focus on controls while agents are operating, aiming to give security teams visibility into activity and a way to constrain unauthorized or risky behavior.
The broader catalyst was CrowdStrike’s Fal.Con package, which included Falcon Guardian, Agentic Identity Provider and real-time supply-chain protection. It also expanded integrations with Google Cloud, OpenAI, Anthropic, NVIDIA, Rubrik, EY and other partners, with the stated goal of putting Falcon tools into cloud, data, identity and AI-agent workflows.
On September 1, CrowdStrike said it was extending Falcon Guardian through Google Agent Gateway to provide runtime protection for enterprise AI applications built on Google Cloud. CrowdStrike says the integration is designed to identify and stop prompt injection, sensitive-data leakage and malicious AI activity while keeping continuous visibility across agents and applications.
The Google Cloud work also reaches Gemini Enterprise. CrowdStrike says Falcon MCP brings its threat intelligence, detections and security context into Gemini-enabled workflows; Charlotte AI is intended for natural-language security operations; and Falcon Shield is intended to help govern AI agents through Google Cloud’s Agent Registry.
A day after the Google Cloud announcement, CrowdStrike and OpenAI said they would extend CrowdStrike enterprise security to Codex agents. CrowdStrike describes Falcon Guardian as an AI Detection and Response product that can protect AI agents and workloads across endpoint, cloud and SaaS environments; for Codex, its stated focus is the point of execution, where an agent takes actions.
CrowdStrike’s stated controls for supported Codex agents
- Maintain a live inventory of supported agents, including who deployed them, what they can access and their security status.
- Connect agent activity to Falcon telemetry, giving security teams runtime visibility into what agents are doing.
- Detect compromised or unauthorized behavior, respond before it spreads, and enforce which supported actions are permitted.
The partnership also includes a plan to bring GPT-5.6 Cyber to Falcon. CrowdStrike says its FAIRR service will initially use the model for approved, authorized defensive cases, combining it with adversary intelligence, structured threat modeling, exploit validation, workflow orchestration and expert oversight to assess risk, analyze attack paths and prioritize remediation.
Together, the Google Cloud and OpenAI releases describe two related but distinct paths. One embeds Falcon in an enterprise AI application and governance ecosystem; the other applies Falcon Guardian to supported Codex-agent activity and pairs Falcon with a cyber-focused model for defined defensive work. Falcon Guardian is also tied to CrowdStrike’s Falcon Next-Gen SIEM platform, linking the new agent-security push to its existing security operations product.
The announcements establish intended integrations and controls, not evidence of customer deployment at scale. Simply Wall St identifies increased AI-related research-and-development costs and execution complexity as risks if Falcon Guardian and Agentic Identity Provider fail to achieve broad, profitable adoption. The next material signal will be whether enterprises deploy these controls across live agent workflows and make Falcon a durable layer in their security operations.
Sources
- ir.crowdstrike.comCrowdStrike Extends Falcon Platform Capabilities Across Google Cloud’s Enterprise AI Ecosystem | CrowdStrike Holdings, Inc.
- crowdstrike.gcs-web.comCrowdStrike and OpenAI Expand Partnership to Secure the Agentic Era | CrowdStrike Holdings, Inc.
- simplywall.stWill CrowdStrike’s (CRWD) New AI Security Suite and Partnerships Change Its Core Growth Narrative?