SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
CrowdStrike launches AI security challenge with AWS

CrowdStrike launches AI security challenge with AWS

Thu, 6th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

CrowdStrike has launched a USD $100,000 international AI security challenge with AWS. The virtual game focuses on attacks against AI agents.

Called AI Unlocked: Agents of Chaos, the challenge asks players to use prompt injection and related tactics to manipulate AI agents turned into tools by a fictional adversary. Participants must then stop those agents before an attack is carried out in the game scenario.

The online initiative is designed as an AI red-teaming exercise. Players move through three acts in which they go undercover, test live AI agents, avoid detection, and try to halt the operation before their cover is exposed.

Each mission is designed to show how AI agents can be pushed into unauthorised actions, how they can operate independently, and why security controls must cover them while they are running. Scoring is based on puzzle completion, with points reduced by the number of tokens used in prompts, and players can replay missions to improve their score.

The prize pool is split across three stages: USD $10,000 for the first act, USD $20,000 for the second, and USD $70,000 for the third. The highest score at the close of each act wins.

CrowdStrike is framing the contest around a broader shift in cyber risk as companies adopt more autonomous AI systems. It argues that AI agents create new machine identities inside organisations, with access to systems and data that can be abused if controls are weak.

That reflects a growing debate in the cybersecurity industry over the risks linked to agentic AI, particularly systems that can act on behalf of users or connect directly to enterprise tools. Security researchers have increasingly focused on prompt injection, unauthorised tool use, and ways automated systems may be manipulated into bypassing intended restrictions.

Jennifer Johnson, Chief Marketing Officer at CrowdStrike, described those concerns in direct terms.

"Prompt injection, agent hijacking, and rogue AI behaviour aren't theoretical anymore. Agents are already breaking containment and taking actions no one authorised," Johnson said.

She said the game is intended to give security teams practical exposure to those attack methods.

"The security community has to learn how to stop these novel threats. AI Unlocked: Agents of Chaos is an interactive and educational way to gamify that challenge, giving defenders a hands-on experience, with 100,000 reasons to play," Johnson said.

The game places participants inside a fictional clandestine organisation using AI agents to deploy malicious AI at scale. To disrupt that effort, players must turn the adversary's own agents against their operators by eliciting information and provoking actions that should not be allowed within the game environment.

AWS is collaborating on the challenge, although CrowdStrike has provided most of the detail on how the exercise will work. Players can join virtually from any location.

AI security focus

The launch also highlights a push by cybersecurity vendors to define a new market around AI protection and monitoring. As businesses move from experimenting with chatbots to deploying software agents that can retrieve data, trigger workflows, and interact with other systems, suppliers are trying to position themselves around tools and services aimed at controlling this new layer of risk.

CrowdStrike has been using the term AI Detection and Response, or AIDR, to describe its approach. The challenge gives it a public demonstration of the attack paths it believes security teams need to understand as AI systems become more deeply embedded in enterprise operations.

For defenders, the game offers a simplified version of a problem becoming more urgent in production environments. Unlike traditional software, AI agents can interpret instructions in difficult-to-predict ways, and they may be given access to enterprise credentials, internal documents, or external tools. That creates opportunities for attackers to manipulate the model through language rather than conventional exploits alone.

The competition's emphasis on token use adds another element tied to how AI systems operate in practice. By penalising excessive prompt consumption, the scoring system encourages participants to refine their inputs rather than rely on brute-force attempts.

The broader significance lies in how quickly security testing is adapting to generative AI. Red-teaming exercises have long been used to uncover weaknesses in networks and applications, but games such as this show how vendors are trying to make AI-specific attack methods more familiar to a wider pool of practitioners.

The top prize in the final act is worth USD $70,000.