Back to Feed
AI SecurityAug 27, 2026

The Future of AI-Driven Security Depends on Complete Data

AI-driven security needs complete, high-fidelity data, not just logs, to detect complex attacks.

Summary

The article argues that current AI-driven security solutions are hampered by relying on incomplete, lossy log data. To effectively detect sophisticated, multi-domain attacks, AI requires full-fidelity telemetry, including infrastructure, operational, identity, and sensitive business data. This comprehensive data approach is crucial for understanding user behavior, identifying subtle deviations, and reconstructing attack chains, especially when adversaries are already inside the network.

Full text

I’ve always been drawn to investigative documentaries — the kind where detectives reconstruct an entire crime from fragments of evidence. The breakthrough never comes from a single clue. It comes from connecting everything: movements, relationships, timing, and intent. Miss one piece and the case stalls, or worse, you chase the wrong suspect. Cybersecurity works the same way. In one of my previous articles, I wrote that the Security Operations Center (SOC) struggles because of architecture, not headcount. We keep layering AI onto systems that were never designed to give it what it needs: complete, high-fidelity data. Without that foundation, even the most advanced model will fail to deliver on its promise. What “complete data” actually means For twenty-five years, “data” in security meant logs and events. But logs are a lossy representation of reality. Security products pre-filter and normalize telemetry before forwarding it, so the logs and alerts that reach the SIEM are roughly 10–20% of what the environment generated. A process-creation event arrives already stripped of its full context and its timing relationship to adjacent events. The AI era raised the stakes. Modern AI-powered attacks now span multiple domains. Detecting and stitching them together requires complete, multi-product data. Consider a departing employee who opens a competitive-analysis document, downloads it, uploads it to his or her personal cloud storage, and emails a copy externally. That attack chain spans four distinct systems. A traditional SIEM catches only isolated fragments — a DLP alert on the download, a CASB flag on the upload — but cannot reconstruct intent without the file’s lineage: what the document contained, who else had accessed it, how this user’s behavior compared to his or her six-month baseline. Analyzed through lineage and timeline, isolated anomalous activities can reveal an attack sequence in progress.Advertisement. Scroll to continue reading. With AI lowering the barrier to cyberattacks, we also need to assume attackers are already inside, and focus on identifying subtle deviations from what is normal. But patterns do not surface in small samples. A single login at 1 am is ambiguous. Fifty logins from the same account over six months – correlated with device telemetry and access patterns – tell you whether it’s the CFO on international travel or an adversary using stolen credentials. In short, AI-powered security demands complete, full-fidelity data – unfiltered from the source. It needs security telemetry, but also the infrastructure and operational data that is part of the environment: network, OT sensors, IoT devices, SaaS, cloud. It needs identity – both human and non-human – to understand which user, service accounts, API keys, or tokens an event is tied to. It needs end-user data — the files, documents, and content moving through users, servers, and applications. And ideally, it needs proprietary data – your crown jewels. The crown jewels are important The most valuable data in any enterprise is often the least visible to security systems: business documents, source code, intellectual property, customer records, financial models. These are the assets adversaries target first, and they are routinely excluded from security analysis — over privacy concerns, regulatory constraints, or the simple fact that a CISO will not (understandably) ship proprietary data to a third-party cloud. AI blind to source-code repositories cannot detect the developer cloning the entire codebase before leaving for a competitor. AI blind to financial models will miss the insider exfiltrating quarterly projections. It is the equivalent of a fraud investigator barred from examining financial records: the investigation continues, but the fraud goes undetected. That exclusion is an architectural choice, not a technical limit. Security systems leave sensitive data out because cloud-dependent architectures cannot be trusted with it under GDPR, the US CLOUD Act, DORA, or HIPAA. Remove that dependency — run the AI inside the organization’s own environment, under its own control — and the crown jewels can finally be part of your AI-powered security analysis. Complete data and sovereignty go hand in hand In every great investigation, success turns on the missing piece — the one detail that changes everything. In cybersecurity – all data and all details matter. Completeness of data is what separates superior AI-driven security outcomes from a mediocre one because every filtered log, every truncated dataset, every excluded system creates a blindspot. But completeness then runs directly into a question of control. The moment you feed AI your source code, financial models, customer records, security data, network telemetry, external SaaS and cloud data, you have to answer where that data goes to be analyzed, who owns the output, which models are being used, and which government can compel access to it. Completeness and sovereignty are “similar” requirements viewed from two angles: one asks what the AI can see, the other asks who controls what it sees and produces. Data privacy along with sovereignty over your data, your models, and weights is becoming a key requirement for any organization or nation that wants to put AI to work in security. Ultimately, the future of AI-driven security won’t be defined by who has the most sophisticated models, but by who gives their AI the most complete data – at full fidelity, with deep operational context, and without giving up control. Related: Realizing the Potential of AI-Driven Security Operations Written By Danelle Au Danelle Au is a cybersecurity and AI go-to-market leader with 20+ years of experience bringing disruptive security, cloud, and AI technologies to market. She is currently VP of Product Marketing at Cylake. Danelle has held multiple CMO and VP roles across startups and market leaders—including Infoblox, Ordr, Blue Hexagon, SafeBreach, and Adallom—helping define emerging security categories and scale go-to-market engines. She is a co-founder and co-author, has multiple U.S. patents, and holds an M.S. in Electrical Engineering from UC Berkeley. The opinions and views expressed within her articles are those of Danelle alone in her personal capacity and do not necessarily reflect the positions of Cylake or any of her prior employers. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Danelle Au Is Patching Dead? Vulnerability Management in the Post-Mythos EraThe AI Token Costs That Can Break CybersecurityEverybody Is Vibe Coding But Nobody Told the Security TeamIs the SOC Obsolete, and We Just Haven’t Admitted It Yet?From Ex Machina to Exfiltration: When AI Gets Too CuriousInside the Verizon 2025 DBIR: Five Trends That Signal a Shift in the Cyber Threat EconomyDNS: The Secret Weapon CISOs May Be Overlooking in the Fight Against CyberattacksFrom Warnings to Action: Preparing America’s Infrastructure for Imminent Cyber Threats Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveNaveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.Trellix h

Entities

AI (technology)SIEM (technology)DLP (technology)CASB (technology)OT (technology)IoT (technology)