Modern data security depends on understanding sensitive data as it is created, accessed, and moved in real time directly on the endpoint.
In addition to identifying predefined patterns such as credit card numbers or Social Security numbers, organizations must protect unstructured information including documents, chat logs, support tickets, AI prompts, medical records, and free-text fields. When protecting this data, understanding the meaning and context of the content is just as important as recognizing patterns.
Consider the below message:
"Hey, I set up the environment for you - the login is j.harrison and the passphrase we agreed on is Sunrise@2026"
There is no structured pattern to match; no username field, password label, or predefined format. A rule-based system would need to anticipate every possible way a person might share credentials in natural language, which would be impossible. Yet the meaning of this message is unambiguous: Someone is sharing account credentials in plain conversation.
Language models understand the meaning and context of content, enabling accurate classification across a broader range of sensitive data. However, delivering accurate AI-powered classification locally introduces a difficult challenge: balancing model efficacy and computational feasibility.
To address this challenge, CrowdStrike worked closely with Intel to introduce a new capability in CrowdStrike Falcon® Data Security that classifies sensitive data using language models that run on-device using dedicated hardware for AI. This is the first step in a broader strategy to extend our existing rule-based engines with AI-based classifications across a range of AI acceleration hardware, starting with Intel’s NPU.
The Challenge: Powerful AI Running on the Device #
The most capable language models contain billions of parameters and demand massive, GPU-backed cloud infrastructure to run. Cloud-based inference wasn't an option for endpoint security: Cloud latency introduces delays, and sending sensitive customer data off the device creates privacy considerations that Falcon Data Security strives to avoid.
The most secure way to run these language models directly is on the device. However, running them on a traditional laptop CPU alone wasn't fast enough for real-time protection. Even the smallest relevant language model took too long to process large inputs, exceeding our strict real-time latency requirements for AI-based classification.
Solving this challenge required rethinking the hardware story. Rather than accepting the tradeoffs of cloud inference or CPU-based processing, CrowdStrike saw an opportunity to get ahead of an emerging shift in enterprise hardware: the rise of dedicated, on-device AI acceleration. Our goal was to future-proof it for data security.
Using Dedicated AI Hardware #
Modern processors offer dedicated hardware built for AI workloads: the integrated GPU and the neural processing unit (NPU), a dedicated AI accelerator optimized for AI inference.
Recognizing the potential of dedicated AI acceleration, CrowdStrike worked closely with Intel to release first-to-market support for AI-enhanced data protection on Intel® Core™ Ultra-powered AI PCs. CrowdStrike developed OpenVINO-supported, NPU-optimized models to get the best performance on Intel hardware. Through joint engineering and early access to Intel’s AI PC architecture, we worked together to optimize inference on the NPU and validate that real-world enterprise security that workloads could execute with the latency, efficiency, and consistency required for always-on protection.
This work builds on CrowdStrike and Intel’s broader focus on securing the next generation of AI PCs. We combined Falcon Data Security’s on-device AI-powered classification with Intel’s AI acceleration to help organizations protect sensitive data without sacrificing performance or privacy.
To understand the value of AI-accelerated hardware, we benchmarked inference latency on common documents across all three compute options on Intel Core Ultra 7 (Series 2) hardware: