All Posts
AI
Operationalized Threat Intelligence
1
min read

From Feeds to Agents: What the AI Shift Asks of Your Data Foundation

Published on
September 28, 2026
Table of Contents

On 1 April 2026, Gartner® published a research note by Jonathan Nunez and Jaime Anderson called Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations.

“CTI is now moving beyond assistive AI toward agentic AI …”
Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.

Every thing that follows is our reading of what that shift demands operationally. It is Anomali’s opinion rather than the research’s position.

The Constraint Moved, but Many Programs Didn’t Move With It

For most of the last decade, a CTI program was measured on what it could see. More feeds, more sources, more reports, broader coverage. Teams got good at that, and the visibility problem is now largely solved for anyone with a funded program.

What did not get solved is what happens next. An analyst who receives 300 pieces of relevant intelligence in a week and can meaningfully act on twelve has a decision problem. The bottleneck sits in figuring out what to act on, understanding why, and getting a control change made before the window closes.

Agents Inherit the Data They Are Given

This is the part we would put in front of any team evaluating agentic capabilities right now. An agent is a fast, actor with no instinct for whether its inputs are trustworthy. A human analyst who sees the same host appear under three different names in three consoles pauses and reconciles it. An agent doesn’t pause; it reasons over what it has, reaches a conclusion, and (if it’s been given authority) acts on it.

So the risk profile of bad data changes when you introduce agents. Duplicate records, conflicting schemas, missing provenance and stale indicators used to cost you analyst hours. In an agentic model they cost you wrong actions, taken quickly, with an audit trail that cannot explain itself.

The Anomali platform digests everything, normalizes it into one schema using OCSF, removes duplicates before they reach the lake, and fuses vetted intelligence into every event as it arrives. That way, what an agent reasons over is one comprehensive picture, and it can be traced back to where each part of it came from.

Governed Means Specific Things

Governance is the word everyone uses. When a vendor tells you their agents operate under governance, these are the questions we would ask:

1.     Which specific actions can execute without a human, and which cannot? A named list, not a posture.

2.     What is shown to the analyst at the approval point, and can they see what the agent based its recommendation on?

3.     Is blast radius calculated before an action runs, or explained after it runs?

4.     Can the action be rolled back, and how long does that take?

Where to Start

If you are building toward agentic intelligence operations, the sequencing matters. Unify and clean the data first, make provenance survive the trip, then extend autonomy one governed action at a time and measure what each one changed

Read the Gartner research report, then talk to us about what your own data foundationwould need before an agent could safely act on it.

‍

‍

Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.

GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

Gartner does not endorse any company, vendor, productor service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

FEATURED RESOURCES

September 28, 2026
AI
Operationalized Threat Intelligence

From Feeds to Agents: What the AI Shift Asks of Your Data Foundation

New Gartner® research examines AI in cyberthreat intelligence operations. Our view on why the data foundation decides what your agents can safely do.
Read More
September 23, 2026
No items found.

When Criminals Hack Criminals: ShinyHunters' Breach of Clop and What It Reveals About the Ransomware Underground

Read More
September 22, 2026
Anomali Cyber Watch

NightEagle GhostContainer Backdoor, SparroWocky Against Government, RatHat Malware Uses AI to Target Banking, Jade Sleet Targets Indian IT, BragJack Hijacks AI Agents, OpenAI Identity Design Flaw, and more

NightEagle APT Expands from Asia to Russia Using GhostContainer Backdoor and Tunneling Tools. FamousSparrow Deploys SparroWocky Backdoor Against Latin American Government Agencies. RatHat Android Malware Uses AI Automation to Target Banking Credentials. Jade Sleet Targets Indian IT Provider With FLATROOF and ROOFDECK Backdoors. BragJack Proof-of-Concept Hijacks AI Browser Agents via Malicious Extensions. Researchers Chain libheif Over-Read and OpenAI Identity Design Flaw to Reach Internal Code Repository.
Read More
Explore All