{"slug": "crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them", "title": "CrowdStrike CEO Kurtz: The Agent-State Is Already Here. Slowing AI Won’t Stop Them.", "summary": "CrowdStrike CEO George Kurtz told the Fal.Con 2026 keynote that the \"Agent-state\" era has arrived, arguing the unit of threat is now an autonomous campaign rather than a human hacker, and that \"pacing what comes next doesn't secure what's already here.\" Kurtz cited a Hugging Face incident in which 1,200 agent instances executed 17,600 actions and the company \"was spared because of the agent's intent, not the defense.\" CrowdStrike is responding with its Agentic Identity Provider and SafeMind, built with NVIDIA, as IBM's Institute for Business Value reports only 18% of organizations have a full inventory of their agents and OutSystems reports just 12% have centralized governance, while Gartner predicts 40% of current agent deployments will be canceled by 2027.", "body_md": "For years, George Kurtz stood on stages and tracked a metric called breakout time-62, 48, 29 minutes. The fastest one his team saw last year was 27 minutes, and they called that machine speed. As Kurtz admitted at the [Fal.Con 2026 keynote](https://www.crn.com/news/security/2026/george-kurtz-s-5-boldest-ai-statements-at-crowdstrike-fal-con-2026), he was wrong. “This was human speed with better tools, and breakout time is over,” he told the audience. That changes the math for every defender in the room: if we aren’t racing against a human anymore, the old playbook of reacting to an intruder is effectively obsolete.\n\n## The Rise of the Agent-State\n\nKurtz is pushing a narrative that shifts the focus from the hacker to the tool. “The unit of threat is no longer the hacker. It’s an autonomous campaign. I call it the Agent-state,” he argued. His perspective is that when apex capabilities become a prompt, the traditional security pyramid is obliterated. “Every attacker is now operating with nation-state capabilities,” he noted. “This is really the rise of the agent state. We hear about nation-state – it’s now the agent state.”\n\nThe thing is, Kurtz-like Anthropic CEO Dario Amodei-has a vested interest in defining the threat landscape in a way that necessitates his company’s specific solutions. In a written statement responding to Amodei, which was verified by Yahoo Finance and Benzinga, Kurtz emphasized that “Pacing what comes next doesn’t secure what’s already here.” It is a valid point, yet it ignores the fact that the industry is still struggling to define what “here” even looks like.\n\n## Intent Over Defense\n\nWe saw exactly what this looks like at Hugging Face, where 1,200 agent instances executed 17,600 actions. Kurtz pointed to this as a prime example of the new reality: “The company was spared because of the agent’s intent, not the defense.”\n\nThis is the crux of the problem. If our security posture relies on the “intent” of an autonomous agent rather than our own ability to govern it, we are essentially flying blind. While CrowdStrike is pushing its [three principles to safely scale](https://www.crowdstrike.com/en-us/blog/three-principles-to-safely-scale-agentic-ai/) agentic AI, the reality is that most enterprises are nowhere near that level of maturity. According to IBM’s [Institute for Business Value](https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-orchestration-layer), only 18% of organizations have a full inventory of their agents, and [OutSystems reports](https://www.outsystems.com/1/state-ai-development) that just 12% have centralized governance in place.\n\nThe market is scrambling to fill this void. We have seen a flurry of activity, with companies like Okta, IBM, Broadcom, and Dataiku launching standalone governance products between August and September 2026, as noted in our report on the [forming agent governance stack](/the-agent-governance-stack-is-forming-four-products-two-weeks-one-pattern/). CrowdStrike is entering this fray with its [Agentic Identity Provider](https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/), which aims to give every AI agent a cryptographically verifiable identity, broker short-lived access, and maintain end-to-end attribution.\n\nThey are also betting on SafeMind, which they describe as the “first complete agentic system for cybersecurity, including the first frontier models purpose-built for defenders.” Built in collaboration with NVIDIA, it continuously attacks and deploys protections in a digital replica of an organization’s environment. It is a sophisticated approach, but it faces the same hurdle as every other tool in this space: the [agent measurement problem](/the-agent-measurement-problem-five-competing-metrics-no-standard/). With five competing metrics and no industry standard, Gartner predicts that 40% of current agent deployments will be canceled by 2027.\n\nFor the enterprise security leader, the pressure to deploy is immense, with [Gartner projecting](https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl) more than 150,000 AI agents per Fortune 500 enterprise by 2028, up from fewer than 15 in 2025. The challenge isn’t just about choosing the right vendor; it is about the fundamental lack of visibility into what these agents are actually doing within the network. We are moving toward a world where “adversaries are already using AI to move faster, automate attacks, and evade detection,” as noted in the CrowdStrike blog. If you cannot see the agent, you cannot govern its intent.\n\nThe question for CIOs is no longer whether to adopt agentic AI, but how to maintain control when the unit of threat has evolved beyond human speed. Until we can move beyond the current fragmented state of measurement and identity, the real risk isn’t just the agents themselves-it is the fact that we are deploying them into an infrastructure that was never designed to track them.", "url": "https://wpnews.pro/news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them", "canonical_source": "https://forkast.news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them/", "published_at": "2026-09-14 17:27:30+00:00", "updated_at": "2026-09-14 17:53:18.865711+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "ai-products", "artificial-intelligence"], "entities": ["CrowdStrike", "George Kurtz", "Anthropic", "Dario Amodei", "Hugging Face", "IBM", "NVIDIA", "Gartner"], "alternates": {"html": "https://wpnews.pro/news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them", "markdown": "https://wpnews.pro/news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them.md", "text": "https://wpnews.pro/news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them.txt", "jsonld": "https://wpnews.pro/news/crowdstrike-ceo-kurtz-the-agent-state-is-already-here-slowing-ai-wont-stop-them.jsonld"}}