

On 1 April 2026, Gartner® published a research note by Jonathan Nunez and Jaime Anderson called Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations.
“CTI is now moving beyond assistive AI toward agentic AI …”
Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.
Every thing that follows is our reading of what that shift demands operationally. It is Anomali’s opinion rather than the research’s position.
For most of the last decade, a CTI program was measured on what it could see. More feeds, more sources, more reports, broader coverage. Teams got good at that, and the visibility problem is now largely solved for anyone with a funded program.
What did not get solved is what happens next. An analyst who receives 300 pieces of relevant intelligence in a week and can meaningfully act on twelve has a decision problem. The bottleneck sits in figuring out what to act on, understanding why, and getting a control change made before the window closes.
This is the part we would put in front of any team evaluating agentic capabilities right now. An agent is a fast, actor with no instinct for whether its inputs are trustworthy. A human analyst who sees the same host appear under three different names in three consoles pauses and reconciles it. An agent doesn’t pause; it reasons over what it has, reaches a conclusion, and (if it’s been given authority) acts on it.
So the risk profile of bad data changes when you introduce agents. Duplicate records, conflicting schemas, missing provenance and stale indicators used to cost you analyst hours. In an agentic model they cost you wrong actions, taken quickly, with an audit trail that cannot explain itself.
The Anomali platform digests everything, normalizes it into one schema using OCSF, removes duplicates before they reach the lake, and fuses vetted intelligence into every event as it arrives. That way, what an agent reasons over is one comprehensive picture, and it can be traced back to where each part of it came from.
Governance is the word everyone uses. When a vendor tells you their agents operate under governance, these are the questions we would ask:
1. Which specific actions can execute without a human, and which cannot? A named list, not a posture.
2. What is shown to the analyst at the approval point, and can they see what the agent based its recommendation on?
3. Is blast radius calculated before an action runs, or explained after it runs?
4. Can the action be rolled back, and how long does that take?
If you are building toward agentic intelligence operations, the sequencing matters. Unify and clean the data first, make provenance survive the trip, then extend autonomy one governed action at a time and measure what each one changed
Read the Gartner research report, then talk to us about what your own data foundationwould need before an agent could safely act on it.
Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.
Gartner does not endorse any company, vendor, productor service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
FEATURED RESOURCES


