AI Agents Move From Hype to the Core of Security Workflows
AI agents in security operations are autonomous software systems that use contextual understanding and direct access to distributed enterprise data to investigate threats, correlate signals, and take governed actions across security workflows without requiring analysts to manually move or standardize the data first. That is the real shift: not another dashboard, but AI that behaves like a tireless teammate inside the data layer itself. Denodo Platform 9.5, 7AI’s Federated SIEM and workflow builder, and Cyabra’s Coordinated Activity Detection agent all point to the same conclusion: serious organizations no longer want generic AI bolted onto old tools. They want agents wired into how their data, decisions, and investigations already work. The winners in this wave will be platforms that combine autonomy with federation and context, rather than chasing yet another isolated security product.
Denodo: Active Context Becomes the New Security Primitive
Denodo Platform 9.5 is a bet that the hardest part of enterprise AI is not the model, but the context the model can see. By expanding its Data Marketplace with a 360 graph and asset extensions, Denodo lets teams define an enterprise knowledge graph that connects ETL processes, consuming applications, glossaries, governance controls, data product contracts, and even AI skills into one semantic layer. Denodo calls this "active context"—a living map of what data means and how it is governed, not just where it sits. Metric views add standardized business metrics and KPIs into that same layer, improving every metrics-driven decision. As Air Europa’s data and analytics head notes, this turns scattered assets into "accessible, governed, and interconnected data products" that give business users a unified, trusted view of data. The takeaway: without this kind of contextual backbone, AI agents risk making fast but uninformed decisions. With it, they can act responsibly, because their autonomy is confined by shared meaning and governance.
7AI: Federated SIEM Automation and Threat Investigation AI at Scale
Security teams are tired of shoving every log into a bloated SIEM, then waiting for both alerts and invoices to spike. 7AI’s response is blunt: separate detection from storage and let AI agents query and act on data wherever it already lives. 7AI Federated SIEM connects to existing SIEMs, data lakes, and cloud platforms, then runs detection and investigation on top of that distributed data without forcing duplication or mass migration. With fully federated search and detection abstracted from storage, every customer can define their own SIEM transformation, moving as much or as little data as they want on their own timeline. The numbers matter here: in one year at enterprise scale, 7AI’s agents have run more than nine million investigations and returned more than one million analyst hours to security teams. That is not a pilot; it is proof that threat investigation AI, supported by federated SIEM automation, can reclaim human time at industrial scale.
Cyabra: Autonomous Threat Detection for Coordinated Manipulation Campaigns
Online manipulation is now an operational risk, not a PR problem, and manual analysis cannot keep up with coordinated inauthentic behavior. Cyabra’s Coordinated Activity Detection agent takes a strong stance: customers do not need another set of charts; they need a single, defensible verdict per scan at scale. The agent automates Cyabra’s analyst methodology, evaluating clustering, timing, content, and narrative signals to determine whether activity is coordinated and inauthentic. It moves through a structured sequence—establishing baseline suspicion from account authenticity, identifying peak activity windows, screening clusters for concentrated inauthentic behavior, and examining posting time, content, and profile signals for manipulation or coordination. The output is one of four verdict states—Confirmed Coordination, Likely Coordination, Insufficient Evidence, or No Coordination Detected—each backed by a confidence score and evidentiary report, typically delivered in under 30 seconds and generated automatically for every scan. This is autonomous threat detection aimed at narrative warfare: fast, repeatable, and explainable enough for leadership to defend.
The Real Shift: From Manual Investigation to Coordinated AI Agents
Taken together, Denodo, 7AI, and Cyabra signal a clear pivot: the center of gravity in enterprise security operations is moving from human-led investigation to agent-led workflows, with humans supervising the edge cases. Enterprises want AI agents that can reason over their own reality—users, assets, policies, historical investigations, and institutional knowledge—rather than generic models staring at isolated alerts. They also want those agents acting directly where data lives instead of forcing new data pipelines. Federated SIEM automation makes that possible, while platforms like Denodo supply the contextual backbone that keeps autonomy from turning into chaos. Cyabra shows that when you codify analyst judgment into an agent and give it rich signals, you can convert scattered evidence into clear verdicts at machine speed. The conclusion is blunt: if your security strategy still depends on manual investigation across disconnected tools, you are falling behind. The next generation of enterprise data security will be shaped by AI agents that combine autonomy with federation and context—and they are already in the building.






