CrowdStrike has widened its partnership with OpenAI, extending enterprise security to Codex, OpenAI's coding agent. At the same time, it is bringing OpenAI's defensive model GPT-5.6 Cyber onto the Falcon platform. The approach is not to keep agents out, but to watch them while they run and stop them when needed.
The announcement splits in two directions
CrowdStrike published the news on September 2, timed to Fal.Con 2026, its own event in Las Vegas. It breaks into two parts. One concerns monitoring and controlling how Codex agents execute. The other concerns using an OpenAI model inside CrowdStrike's own analysis. Packaging two opposite-facing items into a single announcement says a lot about the shape of this partnership.
Once agentic AI enters day-to-day operations, software with real permissions touches files, runs commands, and connects to outside services on a person's behalf. Managing that with governance documents alone leaves no way to reconstruct what actually happened. This announcement reads as an attempt to close that gap.
Codex gets pinned down where it executes
The monitoring side rests on Falcon Guardian, which CrowdStrike introduced at Fal.Con 2026. The company calls it an AIDR product, for AI Detection and Response, and the goal is to intervene at the moment an agent is actually running work rather than stopping at policy documents and configuration checks.
Four capabilities are described for Codex. First, a live inventory of supported Codex agents running across the enterprise, covering who deployed them, what they can reach, and their security status. Second, Codex behavior is connected directly to the endpoint telemetry Falcon already collects, so what an agent is doing becomes visible in real time. Third, compromised or unauthorized agent behavior is detected and handled before it spreads. Fourth, permitted actions can be defined, turning governance policy into controls that bite at runtime.
The scope is not limited to the endpoint. CrowdStrike says coverage spans endpoint, SaaS, cloud, and browser environments. Falcon Guardian itself discovers agents on Windows and macOS, and links a user prompt, an identity, a tool call, and skill use to the downstream system actions that follow, forming a single causal chain. The aim is to catch warning signs such as prompt injection, jailbreaks, and unauthorized data access before they escalate.
GPT-5.6 Cyber is not allowed to fire on its own
The other half, the part that uses OpenAI's model, is built just as cautiously. GPT-5.6 Cyber lands first in the FAIRR service, for Frontier AI Readiness and Resilience, and is to expand across the Falcon platform from there.
CrowdStrike's point is that advanced reasoning pays off only when paired with relevant context, expert oversight, and well-designed workflows. In practice, GPT-5.6 Cyber runs inside a purpose-built harness that combines adversary intelligence, frontline expertise, structured threat modeling, exploit validation, and workflow orchestration. For approved and authorized defensive use cases only, it assesses risk, analyzes attack paths, and informs remediation priorities, with human oversight in place.
Refusing to hand judgment wholesale to a model is not unusual in this field. On the defensive side, letting AI perform automatic blocking means a single false positive can halt the business. Here too, the line is drawn at investigation and prioritization.
What the quotes reveal about the intent
Daniel Bernard, Chief Business Officer at CrowdStrike, said securing the agentic era means both controlling the AI agents organizations depend on and harnessing frontier AI to assess and act on risk at machine speed, and that the two companies are doing both together. Secure AI, in his phrasing, is the foundation for everything AI can do for the world.
Greg Brockman, President and Co-founder of OpenAI, said status quo security is no longer enough, but that AI gives defenders a real opportunity to become fundamentally stronger. Working with CrowdStrike, he said, brings frontier AI into the tools defenders already use, helping them move faster from finding a problem to securing their systems.
Put differently, both companies start from the same premise. Enterprises will not stop adopting agents, so the defenses have to be ready first. Whether that premise holds will be answered by how much authority companies actually hand to Codex.
Summary
On September 2, CrowdStrike and OpenAI expanded their partnership, adding Codex agents to what Falcon Guardian monitors and bringing OpenAI's GPT-5.6 Cyber onto the Falcon platform. On the Codex side, four points are covered: inventory, runtime visibility, detection and response, and action controls, with scope reaching from the endpoint to SaaS, cloud, and browser. GPT-5.6 Cyber enters through the FAIRR service and is used only for approved defensive purposes under human oversight. Taken together, it is a shift toward control at the moment of execution, on the assumption that agents are here to stay.
