8 Ways AI is Changing Threat Intelligence

  • The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now move at machine-speed, which means the intelligence behind every decision has to move just as fast.
  • AI cuts both ways. The same automation that lets defenders orchestrate faster is available to attackers too, and whoever uses it more creatively will often hold the advantage at any given moment.
  • Trust in automation is being built one decision at a time. Human-in-the-loop approval is today's norm, but most security leaders expect that to shift toward human oversight of largely autonomous systems within the next few years.

AI is changing the threat landscape faster than most security organizations can keep up. Recorded Future co-founder Christopher Ahlberg, CTO and co-founder Staffan Truvé, and Head of Threat Intelligence Levi Gundert unpack what’s actually happening in a recent conversation — and what it means for your defenses. Read on for their 8 takeaways.

1. The threat landscape now moves at machine speed.

AI has made exposure discovery instant. Your unknown exposures are now part of your attack surface, and threats are multiplying faster than most teams can triage. While most security organizations are responding by trying to move faster, speed without accuracy isn’t an advantage. Staying ahead means having intelligence that makes machine-speed defense more effective, not just fast.

As Truvé put it, intelligence has always been the way to stay proactive instead of reactive, and as "clock speed" increases across the industry, staying even a little ahead requires acting on intelligence faster than ever.

“External attack surface, security operations, vulnerability management, prioritizing — so many of these use cases and workflows take on a new level of urgency because of the speed component,” Gundert said.

2. "Defend the right things" is now a multi-bear problem.

The team agreed that the old security adage — you don't have to outrun the bear, just the person next to you — no longer holds.

AI removes that comfort almost entirely. Attackers only need one way in. Defenders have to cover just about everything. That asymmetry has always been the challenge and AI is making it structurally worse. It’s no longer one bear chasing the herd anymore — it's one bear chasing each member of the herd, since attackers can automate at scale even more efficiently.

3. Attacks are already becoming more clever, not just faster.

The panel discussed a real-world software supply chain compromise where attackers used compromised credentials to push a malicious package update, then had an LLM already present on infected developer machines search out AWS keys, SSH keys, and other credentials locally. The stolen data was encrypted and exfiltrated through a public GitHub repository — activity that never tripped EDR because it looked like ordinary LLM usage.

It was a preview of a much bigger wave of clever attacks that will likely quietly repurpose and weaponize the AI tools already installed on a target's machine.

4. Locking down devices isn't the only answer — context-aware access might be.

Locking down every endpoint isn't realistic, and it probably is not the answer. Situational permissions, such as access that flexes by location, time, and context are zero trust logic applied to the AI era.

5. Whether AI favors attackers or defenders depends on execution.

Everyone is talking about what AI can do. Fewer are asking who AI will ultimately benefit. Will the advantage belong to attackers or defenders?

It’s a question of how well organizations manage the trade-off between innovation and guardrails. Teams that articulate boundaries tend to build stronger solutions.

Truvé broadened the definition of "AI" beyond LLMs to include things like anomaly detection, and predicted an ongoing arms race. “At any given point in time, depending on who's more creative in using the new technology,” he said, “one side or the other will have the upper hand.”

6. Human-in-the-loop is a bridge, not a destination.

Expect humans to stay involved in approving high-stakes actions.

“Hopefully that just becomes very minimal decision points on all of the articulation that has been built around an incident,” Gundert said. “All the telemetry has been gathered, everything's been enriched. The agent wants to take an action. Maybe they want to isolate a machine on the network, maybe they want to revoke credentials, and it comes to you over Signal or Slack or whatever it is to hit Approve.” But he compared it to the first few rides in a self-driving car: Comfort builds with repeated exposure.

In five years, requiring a human in the loop for every decision may look as outdated as manual patch management does today — replaced by an expectation of an agent in the loop with lighter human oversight.

7. Intelligence will be critical for more than effective resource allocation.

With AI expected to surface a flood of newly discovered vulnerabilities, prioritization will become a major challenge. While work is being done to identify which vulnerabilities are likely to be weaponized and which are likely to target a given organization, the explosion of AI-generated "dark code" is predicted to expand the attack surface by as much as tenfold.

Intelligence should become the mechanism for deciding where limited security resources and token budgets get allocated first. This is why intelligence accuracy is paramount — organizations need to be able to prioritize the right things to defend.

8. Real-time data beats built-in model knowledge.

The team emphasized that relying on a model's internal knowledge risks working from information that's months old — precisely when speed matters most.

LLMs with search still only reach the open web and surface-level open-source intelligence. They don't have access to the technical detail or restricted spaces needed to understand what adversaries are actually doing.

And there are plenty of reasons an LLM won't deploy agents into the internet's bad neighborhoods — which is exactly why the underlying data feeding an intelligence program can matter as much as the model interpreting it.

Stay ahead of AI-enabled attacks.

AI is raising the stakes in terms of speed, prioritization, and trust in automation. The organizations that will weather what follows are building two things now: intelligence they can trust, and comfort with autonomous action.

They need to be able to:

Teams that invest now in high-quality, real-time intelligence — and start building comfort with agentic decision-making in lower-stakes workflows — will be better positioned when fully autonomous attacks eventually arrive.
Take Recorded Future’s interactive tour to see what defending at machine speed looks like in practice. Learn more and launch the interactive tour.

Watch the full conversation with Recorded Future leaders as they discuss how AI is reshaping threat intelligence, the evolving threat landscape, and what it means for defenders.