4 min read · Updated September 2026
AI in cyber threat intelligence means using machine learning and language models to process volume, automate routine analysis and surface patterns, while the questions asked, the validation of what comes back and the business interpretation remain human work. It is a force multiplier on expertise rather than a substitute for it.
Read first: The intelligence cycle
Two things are true at once about AI in this field, and most writing on it manages only one. It genuinely changes what a small team can process. And it is being marketed well beyond what it does, including by vendors who have rebadged a decade of machine learning as something new.
That second point is worth being precise about. Machine learning has been in security products for years, doing specific jobs: spam filtering, anomaly detection, endpoint protection. Equating that with current language models is misleading in both directions, because today's systems do bring genuinely new capability in natural language processing and context-aware reasoning. Vendors claiming they have always had AI are usually describing the older thing.
The honest list is shorter than the marketing and still substantial. AI processes volume at a speed no team can match, which shortens the path from data to detection. It automates the repetitive work, log analysis and alert triage, that consumes analyst hours without using analyst judgement. It identifies patterns across datasets large enough that a human would not find them. And it adapts as the landscape changes rather than requiring every rule to be written by hand.
The common use cases follow from that: anomaly detection in real time, automating triage and containment, contextualising and prioritising risk, identifying cloud misconfiguration, and detecting identity anomalies.
The limitations are not edge cases; they are structural.
Introducing these systems introduces new things to defend. Training and decision data raises privacy obligations. Models can be attacked directly, with small modifications to inputs designed to deceive them. And input data can be manipulated deliberately to produce the outputs an attacker wants. A programme that adopts AI without treating the AI as part of its attack surface has traded one problem for two.
This is the part most likely to be glossed over, and it is the most important. Language models can ease the burden of routine work and draft basic reporting, and they do not replace the expertise around them. A practitioner is still required to:
AI is a force multiplier, and it multiplies whatever expertise is guiding it. Without the right question or a competent reading of the answer, a capable model produces confident and misguided output faster than a person could produce it by hand.
Systems that act independently, running threat hunts, simulating attack paths, triggering mitigations, are arriving. Early uses include hunting agents, validation bots and remediation assistants.
The necessary caution is specific rather than general. Without transparency, fail-safes and explicit constraints, tools that take autonomous action become attack vectors themselves. Anything with the power to change your environment is worth compromising, and that should shape how much independence it is given.
The shortage of skilled practitioners shows up as delayed incident response, overstretched teams and organisations struggling with basic hygiene, and it affects leadership and governance roles as much as technical ones.
AI eases the symptoms by absorbing routine work. It does not close the gap, because the work it cannot do is precisely the work that requires the expertise in short supply. Treating it as an easy button produces a team that processes more material and understands less of it.
Conundrum uses language models for the parts of the cycle that consume time without requiring judgement: collection at volume, first-pass analysis, drafting. What it deliberately does not do is act on its own conclusions. There is no autonomous dissemination and no autonomous attribution; a person decides both, every time.
Generated reporting is checked against its own sources before publication, and reports asserting what their sources do not support are held for review rather than published. That mechanism exists because the failure described above, a confident model with thin grounding, is the realistic risk rather than a hypothetical one.