CrowdStrike to boost AI security by acquiring Pangea for Falcon
CrowdStrike has announced an agreement to acquire Pangea, a company focused on AI security, as part of a broader effort to enhance security for enterprise artificial intelligence environments.
Pangea acquisition
Under the terms of the agreement, the acquisition will enable the integration of Pangea's security capabilities into CrowdStrike's Falcon platform, with the aim of delivering AI Detection and Response (AIDR) that secures data, models, agents, identities, infrastructure, and interactions.
According to CrowdStrike, this move will address the growing risk landscape created by rapid developments in enterprise AI and the diverse ways AI is being used across organisations.
"AI is rewriting the enterprise attack surface at breakneck speed. Each prompt becomes an entry point for the adversary," said George Kurtz, CEO and founder of CrowdStrike. "With Pangea, CrowdStrike will secure the entire AI lifecycle, detecting risks, enforcing safeguards, and ensuring compliance, so our customers can confidently build, deploy, and scale AI without risk."
Extending the Falcon platform
CrowdStrike's Falcon platform, which already provides endpoint and cloud protection, will be extended through the acquisition. The platform currently offers security for environments and models where AI operates, restricts sensitive data from leaving endpoints and cloud workloads, and safeguards AI agents used within the software-as-a-service (SaaS) stack.
With the addition of Pangea, Falcon will address the interaction layer within enterprises, where AI is built and accessed, providing protection across the AI lifecycle and offering the visibility and control organisations need to secure prompts and AI systems at scale.
Pangea's technology
The integration of Pangea's technology will enable several features, including:
- Complete AI Detection and Response (AIDR), providing control and oversight of AI agents and workflows and unifying detection, response, and compliance across AI usage and development;
- Protection against prompt injection attacks and model jailbreak attempts, claiming efficacy rates of up to 99% at sub-30 millisecond latency, based on internal testing;
- Control over conversations and topics within chatbot and generative AI environments, offering oversight into activity and the ability to enforce governance policies to block risky behaviour;
- Security for AI applications in both development and production stages, with the ability for security teams to monitor and manage enterprise-developed and integrated AI alongside existing protections for SaaS agents;
- Measures designed to enable teams to introduce AI features to market more quickly without giving up governance and oversight.
Operational expansion
CrowdStrike emphasised the evolving landscape of AI security, noting that AI environments now exist across cloud infrastructure, datacentres, user endpoints, and through a variety of identities - both human and non-human. The company stated that as AI adoption expands, attackers are increasingly looking for ways to exploit weak points created by this wider attack surface.
"Pangea was founded to make AI adoption safe and secure, giving enterprises the visibility and guardrails to embrace AI with confidence," said Oliver Friedrichs, CEO and founder of Pangea. "By joining CrowdStrike, we will be able to deliver this vision on a global scale, unifying AI security with the Falcon platform and creating the industry's first complete AI Detection and Response platform."
CrowdStrike believes that the acquisition and integration with the Falcon platform will deliver unified visibility, compliance and enforcement mechanisms, carrying the company's detection and response approach from endpoints and clouds to the broader AI ecosystem that includes development platforms, production environments and workforce usage.
Industry context
CrowdStrike has noted its history in developing Endpoint Detection and Response (EDR), which has become a widespread industry standard. The organisation intends to use similar principles in addressing novel security challenges introduced by artificial intelligence and associated workflows throughout the enterprise environment.
The company stated that ready-to-use safeguards, prompt-layer protections, and governance controls offered through the extended Falcon platform and Pangea's technology are aimed at helping enterprises securely develop and deploy AI solutions while managing new and emerging risks. Performance metrics cited by CrowdStrike are based on internal benchmark testing on GPU-based edge deployments.