Most cyberthreat intelligence programs were built to answer a question that no longer decides very much: what is out there. The CTI leads and SOC managers we talk to can already see more thanthey can act on. Feeds arrive, reports pile up, and the real constraint sits downstream, in prioritization and in what actually changes after the intelligence lands.
This Gartner report, , published 1 April 2026 by Jonathan Nunez and Jaime Anderson, examines how AI is changing intelligence operations.
Topics addressed include:
Agentic AI use cases in cyberthreat intelligence, with a governance pattern for each
Which generative AI capabilities are common in CTI platforms today, and which remain early
Predictive and proactive intelligence, including exploit likelihood scoring and attack-path modeling
AI threat intelligence as an intelligence category in its own right
How to evaluate vendor AI claims
CTI is now moving beyond assistive AI toward agentic AI …
Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.
The following is Anomali's opinion. It is not the opinion of Gartner.
Every CTI team we talk to is being asked some version of the same question right now: how much can we hand to agents, and how soon. The answer depends almost entirely on what the agent will be reasoning overwhen it gets there.
An analyst who gets a match on an IP recognizes it as shared hosting before doing anything with it, because blocking it takes down a payment processor along with the threat. That check isunglamorous and largely unmeasured, but it might be doing more work in your SOC than anyone’s accounted for. An agent reasons over what it has been given, reaches a conclusion, and acts if it has the authority to act.
That changes what bad data costs. Duplicate records, conflicting schemas and missing provenance used to cost analyst hours and some rework. Hand those same inputs to something that acts,and they cost you wrong actions taken quickly, with an audit trail that can’t explain how it got there.
So the sequencing matters. Unify and clean the data first, make provenance survive the trip, then extend autonomy one governed action at a time and measure what each one changed. Teams thatrun it the other way end up with fast systems deciding things on a picture nobody trusts, which is harder to unwind than the problem they started with.
Get the research
Complete the form to read the full report.















Gartner, Feeds to Agents: How AI Is Rewiring Cyberthreat Intelligence Operations, Jonathan Nunez, Jaime Anderson, 1 April 2026.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors withthe highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims allwarranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.