Most companies have a policy on which software employees can install. Far fewer have one for AI agents, the programs that can read files, call tools, and take actions on a person’s behalf. That gap is now the subject of a commercial product category, and the clearest sign came on September 1, 2026, when CrowdStrike launched Falcon Guardian at its Fal.Con conference in Las Vegas.
The launch is worth reading closely, not because a single product settles anything, but because of what it assumes: that unapproved AI agents are already running on company machines and that the endpoint is where they need to be caught. Two statistics have been attached to the story, and they need careful handling. Here is what is confirmed, what the numbers actually show, and what the practical lesson is for AI security and AI governance teams.
What CrowdStrike announced
According to CrowdStrike’s press release and coverage from SiliconANGLE, Security Boulevard, and BizTech, Falcon Guardian does four things.
First, it discovers known and shadow AI agents across Windows and macOS endpoints. Second, it blocks agents that are not on an approved list from running on managed systems. Third, it ties agent behavior to endpoint telemetry, linking user prompts to identities, the tools an agent invoked, and the resulting system changes. Fourth, it detects attacks aimed at agents and agents that misbehave, and it estimates the blast radius when an incident occurs.
CrowdStrike also announced supporting pieces: an AI Gateway for centralized control of enterprise AI traffic, a managed service called Falcon Complete for Guardian, a threat hunting service called Falcon Adversary OverWatch for Guardian, and integration with its Next-Gen SIEM.
Availability is uneven, and that matters for anyone planning around it. SiliconANGLE reported that the core Guardian features and the managed threat hunting service are available now, while the AI Gateway is pre-beta and expected to reach general availability next quarter, and Falcon Complete for Guardian is due later this quarter. CrowdStrike’s press release did not list pricing.
CEO George Kurtz framed the pitch in one line: AI has not changed the attack, it has changed its speed. The company’s argument is that the endpoint, which it has long positioned as the control point for stopping attacks, is also the place where agents execute.
What the sources do not say is equally useful. They name Windows and macOS as the supported endpoints and say nothing about other environments. They do not list which agent tools or frameworks Guardian recognizes. And none of the coverage we reviewed includes an independent evaluation of how well it works. Treat this as a vendor announcement, not a tested result.
What shadow AI means in practice
The term is borrowed from shadow IT, where employees adopt tools without approval from the technology or security team. Shadow AI is the same pattern applied to AI: assistants, coding agents, browser extensions, and automation tools that staff install or connect on their own.
It happens for understandable reasons. The tools are free or cheap, they are useful on day one, and many can be installed in minutes without any request to IT. A developer adds a coding agent. A marketer connects an assistant to a shared drive. A finance analyst runs an automation that reads email. Each decision looks small. Together they create a set of programs with real access to company data that nobody has inventoried.
Agents raise the stakes over ordinary shadow IT because they act, not just store. A file-sharing app that nobody approved holds data. An agent that nobody approved can read that data, send it somewhere, and run commands, often with the permissions of the person who installed it.
The two numbers, and what they do and do not show
Two statistics have been attached to this story. They come from different sources and they measure different things.
The first is 89%. CrowdStrike’s 2026 Global Threat Report, published on February 24, 2026, states that AI-enabled adversaries increased their activity by 89%, measured year over year from 2024 to 2025. That is a statement about attackers using AI, not about employees installing unapproved agents. It is also about activity, which is broader than the attacks some summaries describe. The same report says adversaries exploited legitimate generative AI tools at more than 90 organizations by injecting malicious prompts to steal credentials and cryptocurrency. That second figure is closer to the shadow AI concern, because it shows AI tools themselves being used as an attack path.
The 89% is real, and it comes from the company selling the product. It supports the argument that the threat is accelerating. It does not show how many unapproved agents are running inside any given company.
The second number is 17,800. AIR Security, a startup that announced $50 million in funding on September 3, 2026, reported finding more than 17,800 public AI add-ons, with 6.7 million installations in total, that rely on untrusted external sources for their instructions. The company also reported finding AI skills that impersonate Anthropic and OpenAI and are designed to get past security reviews and run arbitrary code. Coverage describes add-ons as skills, plugins, and MCP servers, which are the extensions that give agents new abilities.
Two cautions apply. AIR Security sells a firewall for AI agents, so it has a commercial interest in the finding, and it is a separate company from CrowdStrike. The coverage we reviewed also did not include a published methodology or a link to a full report, so the count cannot be independently checked. That does not make it wrong. It means it should be read as a vendor’s research and used to understand the type of risk, not as a measured baseline.
Together the two figures make a reasonable case for taking the issue seriously. Attackers are using AI more, and the supply chain of extensions that agents rely on is largely unvetted. Neither figure tells you your own exposure.
Why this is a governance problem first
The most important detail in the product description is easy to miss. Guardian blocks agents that are not on an approved list. That means someone has to create the list.
A detection tool can tell you which agents are running. It cannot decide which ones should be. That decision is AI governance: defining which agents are allowed, for which tasks, with which permissions, approved by whom, and reviewed how often. Without it, a discovery tool produces an inventory and a set of alerts with no policy to measure them against.
Kurtz described the aim as turning policy into protection. The order of that phrase is the point. Policy comes first. Organizations that buy enforcement tooling before they write the policy tend to discover that the hardest questions were never technical. Who can approve a new agent? What counts as sensitive data an agent may not touch? Which extensions and MCP servers are acceptable? What happens when a team needs something that is not on the list?
What a practical response looks like
You do not need to buy a product to start. The same steps apply whether you use an endpoint platform, a gateway, or manual review.
Find out what is already running. Ask every team which AI assistants, agents, and extensions they use, and check managed devices where you have the tooling to do so. Expect the first answer to be incomplete.
Write an approved list and a request path. If the only answer to a new tool is no, people will route around you. Make it easy to ask, and give a fast answer.
Vet the extension supply chain. Skills, plugins, and MCP servers can pull in instructions from outside your control. Review where each one loads content from, what permissions it requests, and who publishes it. Be cautious with anything that carries a familiar brand name but comes from an unverified publisher.
Apply least privilege. This is basic AI security hygiene, and it applies to agents as much as to people. Give agents the narrowest access they need. An agent that only has to read one folder should not be able to reach the whole drive or run commands on the machine.
Log what agents do. Record which identity started an agent, which tools it invoked, and what it changed. If something goes wrong, that record is what lets you estimate the blast radius.
Plan the response. Decide in advance who can disable an agent, revoke its credentials, and notify affected teams.
Evaluate vendors on evidence. When assessing any agent security product, ask which agents and platforms it covers, how discovery works, what it does when it finds an unapproved agent, and what independent testing exists.
For companies that build agents for customers or for internal use, this also shapes design. Teams working on AI agent development should build in identity, scoped permissions, and audit logging from the beginning, so that the agents they ship are ones a security team can actually govern.
Where this leaves you
Falcon Guardian is a confirmed product launch with a defined feature set, some parts available now and others still to come. The 89% figure is CrowdStrike’s own finding about attacker activity. The 17,800 figure is a separate vendor’s research with no published methodology in the coverage we reviewed. None of these prove that your company has a shadow AI problem today.
What they do show is that the industry now treats unapproved agents as an AI security category worth building products for, and that the endpoint is one place to look. The durable part of the story is the AI governance work underneath: an inventory, an approved list, vetted extensions, limited permissions, and a record of what agents do. Companies that have those in place can evaluate any tool from a position of strength. Companies that do not will be buying software to solve a policy gap.
Frequently Asked Questions
1. What is Falcon Guardian?
Answer:Falcon Guardian is CrowdStrike’s AI agent security product, launched on September 1, 2026 at Fal.Con. It discovers known and shadow AI agents on Windows and macOS endpoints, blocks agents that are not approved, and links agent behavior to endpoint telemetry.
2. What is shadow AI?
Answer: Shadow AI refers to AI tools and agents that employees use or install without approval from IT or security. Because agents can read data and take actions, they carry more risk than ordinary unapproved apps.
3. Where does the 89% figure come from?
Answer: It comes from CrowdStrike’s 2026 Global Threat Report, published February 24, 2026, which says AI-enabled adversaries increased their activity by 89% year over year. It measures attacker activity, not unapproved agents inside companies.
4. Is the 17,800 add-ons figure from CrowdStrike?
Answer: No. It comes from AIR Security, a separate startup that sells an AI agent firewall. It reported more than 17,800 public add-ons with 6.7 million installations relying on untrusted instruction sources. The coverage reviewed did not include a published methodology.
5. Do I need a product like Falcon Guardian?
Answer: Not necessarily. Start with an inventory of the agents in use, an approved list, and a request process. A tool can enforce that policy, but it cannot write it for you.
6. What should an AI governance policy for agents include?
Answer: It should define who can approve agents, which data they may access, which extensions and MCP servers are acceptable, what permissions they receive, how their actions are logged, and who can shut them down.
If you want to know which AI agents and tools your teams are already relying on, and where the governance gaps are, that is exactly what we look at in a free AI Readiness Audit.
