DruckFin

CrowdStrike unveils AI token business and pulls forward $20 billion ARR target to FY2035

Fal.Con 2026 conference, Las Vegas, September 2, 2026

CrowdStrike used its largest-ever Fal.Con customer conference to unveil a fundamentally new monetization layer for the business: a token-based pricing model tied to a proprietary family of cybersecurity AI models called SafeMind. The announcement, combined with an accelerated timeline to the company's long-term ARR targets, represents one of the more significant strategic disclosures from CrowdStrike since its EDR launch redefined the endpoint security category over a decade ago.

SafeMind: CrowdStrike becomes a frontier AI lab for cybersecurity

The centerpiece of the event was SafeMind, described by founder and CEO George Kurtz as "cybersecurity's first frontier model and harness family combined as an agentic system." Built in partnership with NVIDIA using Nemotron as a base and hosted on CoreWeave's infrastructure, SafeMind consists of two model classes: Red Tempest, an offensive model designed to find vulnerabilities and exploits, and Blue Solano, a defensive model trained to detect and remediate threats using CrowdStrike's own telemetry. Kurtz framed the effort as filling a gap left by general-purpose frontier labs, which have focused heavily on offensive capability discovery without an equivalent defensive counterpart. "The adversaries have Frontier caliber AI, but the defenders didn't," he said. The performance claims are notable. In benchmark testing shared on stage, Blue Solano showed detection rates 37% and 29% better than two unnamed frontier lab models, at up to 99% lower cost per task, and with detection speeds 6 times faster. CrowdStrike's Chief AI and Autonomous Systems Officer Bartley Richardson cited a cost-per-remediation drop from $10 using an off-the-shelf frontier model and harness to $0.03 with SafeMind, alongside a 70% increase in accuracy. Those figures matter because token costs have become a growing pain point for enterprises; Kurtz relayed an anecdote about a customer whose executive assistant inadvertently ran up $10,000 in monthly token spend because a chatbot kept rebuilding a parser for every email it processed.

A new revenue stream: CrowdStrike tokens

Perhaps the most consequential disclosure for investors was the introduction of token-based pricing as a new monetization mechanism layered on top of Falcon Flex, the company's subscription commitment model. Customers will purchase initial token packs and expansion packs, with usage pooled across the organization to avoid what Kurtz called the "variability" and "runaway spend" that has frustrated enterprise AI buyers elsewhere. Access to SafeMind will be gated to Falcon Flex customers only. CFO Burt Podbere confirmed that SafeMind's token revenue has not yet been baked into the FY2027 guidance given at last quarter's earnings call, calling it "early days," but said it is contemplated for FY2028 — a modest incremental catalyst not yet reflected in the current numbers. CrowdStrike is also positioning itself as a distribution channel for third-party frontier labs. A new model routing layer lets customers choose between SafeMind, open-weight models, or frontier models from partners like OpenAI and Anthropic, with CrowdStrike collecting economics across that token flow regardless of which model a customer selects. Chief Business Officer Daniel Bernard highlighted a new integration announced with Anthropic's marketplace, the first security vendor listed there, that lets customers burn down a single AI/security commitment across both companies' products.

Guardian ships instantly, reframes the AI security TAM

CrowdStrike also launched Falcon Guardian, its AI agent security product, making it generally available to customers within roughly 30 seconds of George Kurtz's keynote announcement, according to President Michael Sentonas. The company reported a "flood" of customer requests overnight. Guardian covers the full agent lifecycle — discovery, permissions, runtime, and decommissioning — across endpoint, cloud workloads, and SaaS environments, and fuses prompt-level visibility with CrowdStrike's runtime detection heritage. Sentonas described the category shift bluntly: "EDR defines how we secure the endpoint. AIDR will define how we secure the estate, and Guardian is how we deliver it." Management sized the agentic security market at $115 billion by calendar 2034, the agentic SOC opportunity (next-gen SIEM) at $52 billion, and agentic identity at $48 billion, for a combined AI security TAM of $215 billion. Applying the company's historical 3.5%-4% average market share capture rate to that opportunity implies roughly $7.5 billion of incremental ARR by 2034 — about 38% of the company's long-term $20 billion ARR target. Kurtz separately estimated the AI security opportunity could range from $36 billion to $291 billion depending on what share of overall AI spend (sized by Gartner at $2.67 trillion in 2026, rising to $5.95 trillion by 2030) flows into security.

Targets pulled forward: $10 billion ARR by FY2030, $20 billion by FY2035

Sentonas disclosed that CrowdStrike now expects to reach its $10 billion ARR milestone within fiscal 2030, a year earlier than the FY2031 timeline given at last year's investor briefing, and the $20 billion target within FY2035, also a year ahead of the prior FY2036 guide. Podbere reinforced the point with a walk through net new ARR guidance revisions over the past year: from an initial 20% growth target to 22.5% after the fourth quarter, then a 520-basis-point beat in the first quarter, and 34% growth last quarter — a cumulative $220 million raise to the FY2027 net new ARR outlook. He now expects "20% plus year-over-year net new ARR growth" heading into next year, implying an ARR base equal to or above $1.626 billion by the end of next fiscal year versus $1.355 billion at the midpoint this year. Second-quarter results referenced during the event included $333 million in net new ARR (up 51% year-over-year) and non-GAAP operating income of $372 million, both records. Ending ARR reached $5.8 billion, a 23% two-year CAGR and roughly 30% of the way to the $20 billion target.

Anthropic: "You cannot Claude Code your way to CrowdStrike"

In a rare direct rebuttal to a lingering investor worry, Anthropic's enterprise cybersecurity go-to-market lead Ashraf Alhashim appeared on stage to explain why his own company, despite building frontier coding models, remains a CrowdStrike customer rather than building security in-house. "This isn't something that a Claude Code or even a team of very talented engineers working at a company like Anthropic can just build overnight," he said. "This takes time, skill, distribution, network effects, a level of determinism that comes with experience... you can't reason your way into building something like a CrowdStrike." Kurtz echoed the point in the analyst Q&A, arguing that CrowdStrike's 7 trillion daily security events represent proprietary data unavailable anywhere else, comparing it to frontier labs now scanning out-of-print books for training data because they have exhausted public sources. The Anthropic relationship also extends to commercial mechanics: a newly launched marketplace integration allows joint customers to apply Anthropic token commitments toward CrowdStrike purchases and vice versa, which Bernard said eliminates the internal "fight" between AI budget owners and security budget owners inside customer organizations.

Identity: a direct challenge to the legacy PAM market

CrowdStrike launched an Agentic Identity Provider built on its SGNL.AI acquisition, targeting what Sentonas called a broken model in privileged access management. Rather than granting standing privileges to users and agents, the new architecture grants zero standing access, entitlements are issued only for the specific task and window of execution and then revoked. Kurtz argued this directly addresses the mechanism behind most modern breaches: "If you think about all these attacks that you read about, it's mostly a user name and a password and an MFA that's compromised... they pulled it out of some vault that has standing privileges. That's the difference." CrowdStrike is sizing the agentic identity market at $48 billion by calendar 2034 and says it is not starting from zero, citing roughly $585 million in existing next-gen identity ARR growing at 33%, well above the 14% CAGR needed to hit its internal targets.

Falcon Flex economics and margin trajectory

Falcon Flex, the company's consumption-style commitment model, has grown to $2.3 billion in total contract value, up 101% year-over-year, with 935 new Flex opportunities added last quarter alone. Podbere noted the average ARR uplift from converting a non-Flex deal to Flex has risen to 40% from 34% a year ago, and that new bookings mix has shifted from 61% enterprise/39% non-enterprise to an even 50/50 split as sales teams increasingly default to Flex-first selling. Podbere said he envisions a future in which "there is no such thing as a non-Flex deal." On profitability, gross margin sits at 81% against a target band of 82%-85%, with Podbere attributing further room to cloud infrastructure optimization, vendor renegotiation, and AI-driven reductions in duplicate data storage. Operating margin is at 24% against a 28%-32% target, and free cash flow margin guidance for FY2028 was set at 32.5% or higher, alongside a slight uptick in capital expenditure to 11%-12% of revenue.

Where the growth argument could get tested

Analysts pressed management on execution risk given the sheer number of new moving pieces — token pricing, model routing, multiple new product categories launching simultaneously. Podbere acknowledged the token-based SafeMind revenue is not yet in guidance, and Kurtz conceded pricing is still evolving: "I wish I had the crystal ball on pricing... I know it's going to be meaningful." Management's own framing — that AI security demand is a "sustained" tailwind rather than a "spike" — implies the growth curve should be durable rather than explosive in any single quarter, a distinction Kurtz drew explicitly when pressed by Oppenheimer's Ittai Kidron on why growth shouldn't simply accelerate into the FY2035 target rather than staying on a steady compounding path.

Disclaimer: This article is for informational purposes only and does not constitute investment advice or a recommendation to buy, sell, or hold any security. Our analysts provide detailed coverage of corporate events but can make mistakes, always conduct your own due diligence. The views and opinions expressed do not necessarily reflect those of DruckFin. We have not independently verified all information used herein, and it may contain errors or omissions. Before making any investment decision, consult a qualified financial advisor. DruckFin and its affiliates disclaim any liability for any losses arising from reliance on this content. For full terms, see our Terms of Use.