CrowdStrike integrated OpenAI into their product offerings and placed Anthropic at the payment stage.
CrowdStrike announced on Wednesday that it will operate OpenAI's GPT-5.6 Cyber within a specialized cyber harness. This term plays a significant role, as it is also central to this week's concerning cybersecurity news.
The expanded partnership with OpenAI, revealed at the company's Fal.Con conference in Las Vegas, consists of two main components. CrowdStrike will monitor OpenAI's Codex agents during runtime and utilize OpenAI's cyber-optimized model to evaluate customer risk.
Importance of the term
Just a day prior, we reported on Booz Allen's Cyber Weapon Index, which assessed 18 models functioning as autonomous attackers on a live network. One of its key findings was that the attack harness can be as critical, if not more so, than the model itself. A harness refers to the software that connects a model to its tools and maintains its focus.
Booz Allen illustrated this point clearly. Claude Sonnet 5 rated 15th out of 18 with a score of 13. However, when equipped with a harness, it reportedly competed with the leader, scoring 80. The conclusion drawn was that the risk unit is now the system rather than the model itself.
CrowdStrike is marketing this same architecture in reverse. Its Frontier AI Readiness and Resilience service implements GPT-5.6 Cyber "within CrowdStrike's purpose-built cyber harness." The designated tasks include risk assessment, attack path analysis, and remediation prioritization, all under human supervision and for approved defensive purposes only.
Booz Allen also evaluated the earlier version of this model. GPT-5.5-Cyber placed eighth with a score of 34 and successfully achieved lateral movement within the target network. Among the models tested, there were nine American and nine Chinese variants. The index found no noteworthy distinctions between the two sets, which is somewhat perplexing amid renewed external tests focused on foreign threats.
The sibling dilemma
An intriguing detail emerged from the index: one model declined a task due to a lack of credentials. Yet, its cyber-optimized counterpart complied with the same task. Booz Allen inferred that constraints are determined by configuration rather than the model itself, indicating that a refusal in one scenario does not imply anything about a different context.
While the report doesn't identify either model, we will refrain from doing so as well. Nevertheless, cyber-optimized versions are a niche segment. CrowdStrike is currently providing the latest one to enterprise clients, but its launch does not address this aspect.
Supervising the agents it's marketing
The other aspect involves Falcon Guardian, CrowdStrike’s AI detection and response tool, applied to Codex agents. The company promises a real-time inventory of all Codex agents operating within an organization, detailing who deployed each one and their potential access.
Falcon Guardian monitors the activities of these agents in real-time and highlights unauthorized actions. Administrators can define which actions are allowable, with CrowdStrike characterizing this as translating governance policies into enforceable runtime controls.
The underlying assumption is vital to highlight: enterprises are already utilizing coding agents that they cannot fully monitor. This necessitates the inventory feature as the top priority, preceding any detection capabilities.
Greg Brockman, OpenAI's president and co-founder, mentioned in the announcement that conventional security measures are no longer sufficient. He added that AI presents defenders with a genuine chance to become significantly stronger.
Anthropic enters the picture
Later on the same day, CrowdStrike revealed a second partnership, this time with Anthropic. The Falcon platform will be available on the Claude Marketplace, allowing Anthropic customers to purchase it using part of their previously allocated spending to Anthropic.
This represents a procurement strategy rather than a product rollout, and it is the more innovative of the two announcements. Committed AI expenditure transforms into a currency for acquiring unrelated enterprise software. Daniel Bernard, CrowdStrike's chief business officer, noted that AI is influencing both technology procurement and operations.
The technical aspect involved is Charlotte AI AgentWorks. Security teams articulate an outcome in simple terms, the system generates an agent based on Falcon data, and this agent operates within Claude. Ash Alhashim, leading enterprise cybersecurity sales at Anthropic, stated that customers gain access to a trusted platform based on commitments they have already made.
During the same conference, Anthropic also received CrowdStrike's Global Leadership Impact Award.
Summing up the week's developments
CrowdStrike utilized Fal.Con to unveil much more than just two partnerships. It introduced an Agentic Identity Provider, which grants AI agents their own identities and treats this as the enterprise’s control mechanism. Additionally, a separate product prevents malicious open-source packages from executing at the endpoint before their code runs.
On Tuesday, CrowdStrike announced coordinated multi-agent investigations across five domains, allowing customers to adjust autonomy up to fully automated execution. The company also focused on dismantling Sality, a botnet that predates the iPhone.
When viewed together, these announcements portray a company that now offers agents, the identity framework for their authentication,
Other articles
CrowdStrike integrated OpenAI into their product offerings and placed Anthropic at the payment stage.
CrowdStrike will operate OpenAI's GPT-5.6 Cyber within a specially designed cyber harness. A day prior, a report identified the harness as the genuine risk.
