CrowdStrike put OpenAI in the product and Anthropic at the checkout

CrowdStrike will run OpenAI's cyber-tuned model inside what it calls a purpose-built cyber harness, and police OpenAI's Codex agents at runtime. Hours later it put the Falcon platform on Anthropic's marketplace, payable from existing Anthropic commitments.


The red CrowdStrike falcon logo and wordmark mounted on the grey facade of an office building in Sunnyvale, California.

CrowdStrike signage in Sunnyvale, California. The company made four announcements at its Fal.Con conference this week.

Image Credits Credit: bluestork / Shutterstock

CrowdStrike said on Wednesday that it will run OpenAI’s GPT-5.6 Cyber inside a purpose-built cyber harness. That word is doing a great deal of work. It is also the word that made this week’s other cybersecurity story alarming.

The expanded OpenAI partnership, announced at the company’s Fal.Con conference in Las Vegas, has two halves. CrowdStrike will police OpenAI’s Codex agents at runtime. It will also put OpenAI’s cyber-tuned model to work assessing risk for customers.

Why the word matters

A day earlier we reported Booz Allen’s Cyber Weapon Index. It tested 18 models as autonomous attackers against a live network. Its third finding was that an attack harness can matter as much as the model itself, or more. A harness is the software that connects a model to tools and keeps it on task.

Booz Allen demonstrated the effect bluntly. Claude Sonnet 5 finished 15th of 18 on a score of 13. Fitted with a harness, the firm says, it rivalled the leader on 80. The report’s conclusion was that the model is no longer the unit of risk, and the system is.

CrowdStrike is now selling that same architecture pointed the other way. Its Frontier AI Readiness and Resilience service applies GPT-5.6 Cyber “within CrowdStrike’s purpose-built cyber harness”. The stated jobs are assessing risk, analysing attack paths and setting remediation priorities. The company says this happens under human oversight, and for approved defensive use only.

Booz Allen also scored the previous version of that model. GPT-5.5-Cyber came eighth on 34 and reached lateral movement inside the target network. It was one of nine American models tested, alongside nine Chinese ones. The index found no substantial difference between the two groups. That conclusion sits oddly beside a fortnight of renewed external testing framed around foreign threats.

The sibling problem

There is a sharper detail in the index. One model refused a task because it had no credentials. Its cyber-tuned sibling, given the identical task, complied and carried it out. Booz Allen’s inference was that guardrails belong to the configuration rather than to the model, so a refusal in one setting predicts nothing about another.

The report does not name either model, and neither will we. But cyber-tuned variants are a small category. CrowdStrike is now shipping the newest one to enterprise customers, and its release does not address the point.

Policing the agents it also sells

The other half is Falcon Guardian, CrowdStrike’s AI detection and response product, applied to Codex agents. The company promises a live inventory of every Codex agent running in an organisation. That inventory shows who deployed each one and what it can reach.

Falcon Guardian then watches what those agents do in real time and flags unauthorised behaviour. Administrators can define which actions are permitted. CrowdStrike describes that last part as turning governance policy into enforceable runtime controls.

The pitch assumes something worth stating plainly. Enterprises are already running coding agents they cannot fully see. That is why an inventory is the first feature on the list, ahead of any detection.

Greg Brockman, OpenAI’s president and co-founder, said in the release that status quo security is no longer enough. AI, he added, gives defenders a real opportunity to become fundamentally stronger.

Anthropic turns up on the other side of the counter

Five hours later CrowdStrike announced a second deal, this time with Anthropic. The Falcon platform is going onto the Claude Marketplace, and Anthropic customers will be able to buy it using part of the spending they have already committed to Anthropic.

That is a procurement mechanic rather than a product, and it is the more novel of the two announcements. Committed AI spend becomes a currency for buying unrelated enterprise software. Daniel Bernard, CrowdStrike’s chief business officer, said AI is changing how technology is procured as well as how it is run.

The technical part is Charlotte AI AgentWorks. Security teams describe an outcome in plain language, the system builds an agent grounded in Falcon data, and the agent runs from inside Claude. Ash Alhashim, who leads enterprise cybersecurity sales at Anthropic, said customers get a platform they trust on commitments they have already made.

Anthropic also collected CrowdStrike’s Global Leadership Impact Award at the same conference.

What the week adds up to

CrowdStrike used Fal.Con to announce a good deal more than two deals. It also introduced an Agentic Identity Provider, which issues AI agents their own identities and treats that as the control plane for the enterprise. A separate product blocks malicious open-source packages at the endpoint before their code runs.

On Tuesday it unveiled coordinated multi-agent investigations across five domains, letting customers dial autonomy up to fully automatic execution. It also spent the week dismantling Sality, a botnet that predates the iPhone.

Read together, the announcements describe a company that now sells the agents, the identity layer those agents authenticate through, the system that investigates them, and the frontier model that reasons about the risk they create. Both leading AI labs appear in the product line within a single afternoon.

One model is absent from all of it. OpenAI’s Astra, which the company said this week had reached its critical cybersecurity capability threshold, was not part of either announcement and was not in the Booz Allen index either.

Booz Allen expects most of the models it tested to match the leader within six months. CrowdStrike is betting that the same engineering that makes attackers faster will make defenders faster too. Nobody has published a test of the defensive half.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top