OpenAI and cybersecurity company CrowdStrike have expanded their partnership to strengthen security around artificial-intelligence agents, combining runtime monitoring of OpenAI’s Codex agents with advanced AI-powered cybersecurity capabilities.
Under the expanded collaboration, CrowdStrike will extend its enterprise security technology to Codex agents through Falcon Guardian, while OpenAI’s GPT-5.6 Cyber will be incorporated into CrowdStrike’s Falcon platform. The companies announced the expansion during CrowdStrike’s Fal.Con 2026 conference in Las Vegas on Sept. 2.
The partnership reflects a broader challenge emerging as AI systems move beyond generating information and increasingly gain the ability to execute tasks, interact with enterprise systems and operate with varying degrees of autonomy.
Securing AI Agents at Runtime
A central component of the partnership involves protecting AI agents while they are actively operating inside enterprise environments.
CrowdStrike said Falcon Guardian will provide organizations with visibility into supported Codex agents running across their systems, including information about who deployed an agent, what resources it can access and its security status.
The system connects agent activity with CrowdStrike’s Falcon telemetry, allowing security teams to observe behavior in real time and identify potentially compromised or unauthorized actions. Organizations can also establish controls defining which supported actions agents are permitted to execute.
The approach is designed to extend cybersecurity controls beyond traditional AI governance. Rather than focusing exclusively on how an AI system is configured or what permissions it has been assigned, Falcon Guardian monitors what agents actually do while operating.
CrowdStrike introduced Falcon Guardian separately on Sept. 1 as its AI Detection and Response, or AIDR, solution. The company said the technology is designed to provide visibility and runtime enforcement across endpoints and enterprise environments where AI agents execute.
GPT-5.6 Cyber Comes to CrowdStrike’s Falcon Platform
The second component brings OpenAI’s GPT-5.6 Cyber into CrowdStrike’s cybersecurity ecosystem.
CrowdStrike plans to initially use the model through its Frontier AI Readiness and Resilience, or FAIRR, Service, combining OpenAI’s advanced reasoning capabilities with CrowdStrike’s threat intelligence, security expertise, threat modeling, exploit validation and workflow orchestration.
For authorized defensive cybersecurity applications, the companies said the technology can be used to assess risks, analyze potential attack paths and help security professionals determine remediation priorities, with expert oversight remaining part of the process.
The integration is expected to expand across the broader Falcon platform.
AI Creates New Cybersecurity Challenges
The partnership comes as autonomous and semi-autonomous AI agents increasingly enter corporate technology environments.
Unlike conventional generative AI applications that primarily respond to prompts, AI agents can potentially execute code, access applications, interact with company data and perform sequences of actions on behalf of users. Those capabilities create new security considerations around identity, permissions, data access and compromised or unauthorized behavior.
CrowdStrike has been expanding its security architecture specifically around these risks. The company says Falcon Guardian connects AI-agent activity with endpoint telemetry to establish visibility between an instruction given to an agent and the actions subsequently performed across enterprise systems.
That shift is also changing how cybersecurity companies approach AI: artificial intelligence is simultaneously becoming a technology that organizations need to protect and a tool that security teams can use to detect and respond to threats.
OpenAI Sees AI Strengthening Cyber Defense
OpenAI co-founder and President Greg Brockman said the collaboration is intended to bring advanced AI capabilities directly into security tools already used by enterprise defenders.
“Status quo security is no longer enough,” Brockman said in the announcement, arguing that AI creates an opportunity for defenders to become stronger.
Daniel Bernard, CrowdStrike’s chief business officer, said securing AI agents while using frontier AI to assess cyber risk are becoming interconnected parts of enterprise security.
The expanded partnership effectively addresses both sides of that equation: CrowdStrike technology will monitor and protect OpenAI-powered agents, while OpenAI technology will be used within CrowdStrike’s platform to help security teams analyze cyber threats.








