{"canonicalLink":"https://www.snowflake.com/en/artificial-intelligence/industries/ai-in-cybersecurity/","robotsTags":["index","follow"],"templateName":"fundamentals-template","cssClassNames":"fundamentals-page page basicpage summit-page","allowedRenditionsWidth":["320","480","640","768","960","1200","1440","1920"],"description":"Learn how AI in cybersecurity helps detect threats, automate response, and strengthen defenses. Explore use cases, benefits, and what's ahead.","language":"en","title":"AI in Cybersecurity: How It Works, Key Use Cases & Benefits","analyticsPageType":"homepage","analyticsCategory":"general","analyticsSubCategory":"","excludeFromAnalytics":false,":type":"snowflake-site/components/structure/page",":mappedPath":"/en/artificial-intelligence/industries/ai-in-cybersecurity/",":hierarchyType":"page",":path":"/content/snowflake-site/global/en/artificial-intelligence/industries/ai-in-cybersecurity",":items":{"root":{"columnCount":12,"columnClassNames":{"experiencefragment-banner":"aem-GridColumn aem-GridColumn--default--12","experiencefragment-header":"aem-GridColumn aem-GridColumn--default--12","responsivegrid":"aem-GridColumn aem-GridColumn--default--12","experiencefragment-footer":"aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--default--0 aem-GridColumn--default--none","experiencefragment":"aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--default--0 aem-GridColumn--default--none","markup_editor":"aem-GridColumn aem-GridColumn--default--12","modal_container":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12",":items":{"experiencefragment-banner":{"id":"experiencefragment-6fbe344e0c","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/pushdown-banner/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/pushdown-banner/master.xfmodel.json"},"experiencefragment-header":{"id":"experiencefragment-29d1b46d13","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/mega-nav-header/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/mega-nav-header/master.xfmodel.json","languageNavPath":"/content/snowflake-site/global/en/artificial-intelligence/industries/ai-in-cybersecurity.languagenav.json"},"markup_editor":{"id":"markup-editor-85bcd1943b","title":" ","cssContent":"div.snowflake-breadcrumb a.snowflake-breadcrumb-item,.snowflake-breadcrumb div.snowflake-breadcrumb-item{text-transform:none;font-weight:500}.snowflake-breadcrumb svg{display:none !important}.snowflake-breadcrumb a:has(svg)::after{content:'/';margin:0 12px;color:#666}.fundamentals-hero .display-2-v2{text-transform:none !important}@media screen and (min-width:1024px){.fundamentals-hero .snowflake-hero-system-inner snowflake-container snowflake-hero-system-layout-60-40{width:80% !important;max-width:700px !important}}.snowflake-hero-system-buttons-container+div:has(.snowflake-manual-breadcrumbs),.snowflake-hero-system-buttons-container+div:has(.fundamentals-hero__breadcrumbs),.snowflake-hero-system-buttons-container+div:has(.snowflake-breadcrumb){order:-1}.fundamentals-hero__breadcrumbs ol li:not(:last-child)::after{content:'';display:inline-block;width:12px;height:12px;background-image:url(\"data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' fill='none' viewBox='0 0 10 10' data-testid='button-link-icon' class='link-icon'%3E%3Cpath d='m1.572 9.515 4.417-4.447L1.497.548' stroke='%23666'%3E%3C/path%3E%3C/svg%3E\");background-size:contain;background-repeat:no-repeat;background-position:center;margin:0 12px}.fundamentals-hero__breadcrumbs ol{margin:0;padding:0;list-style-type:none;display:flex;flex-direction:row;align-items:center}#subNav .subnav__item.subnav__item--features{color:var(--ui-01)}#subNav .subnav__item.subnav__item--features::after{content:'';display:block;width:100%;height:4px;margin:0 12px;background:var(--ui-01);position:absolute;bottom:-18.5px;left:0}.use-case-hero__architecture{background:#fff;border-radius:8px}@media screen and (min-width:768px){.use-case-body\u003E.snowflake-flexible-column-container-items\u003Ediv:first-child{position:sticky;top:200px}}.page-toc ul{list-style-type:none;padding:0}.page-toc li{padding:8px 16px;border-left:4px solid var(--ui-01);cursor:pointer;transition:300ms ease all}.page-toc li:hover{color:var(--ui-01);border-color:#7fd3f1;transition:300ms ease all}.story-highlights{padding:48px;border-radius:4px}.logo-container{max-width:180px}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container{align-items:center;justify-content:center;gap:48px;flex-wrap:nowrap}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container\u003Ediv{width:auto;margin:0 !important}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container\u003Ediv:last-child{flex-grow:1}.flex-container .aem-Grid::before,.flex-container .aem-Grid::after{display:none !important}.use-case-body table{margin-top:24px;margin-bottom:24px;width:100%;background-color:var(--ui-background-01);border-collapse:collapse;border:2px solid var(--ui-background-09);font-family:'Lato',sans-serif;color:var(--ui-background-09)}.use-case-body table thead{background-color:var(--ui-01)}.use-case-body th,.use-case-body td{min-width:120px;border:2px solid var(--ui-background-09);padding:var(--spacing-01)}.use-case-body ol{margin-top:0 !important}.use-case-body ol li{margin-bottom:1rem !important}#subNav .subnav__item.subnav__item--features{color:var(--ui-01)}#subNav .subnav__item.subnav__item--features::after{content:'';display:block;width:100%;height:4px;background:var(--ui-01);position:absolute;bottom:-18.5px;left:0}.use-case-hero__architecture{background:#fff;border-radius:8px}@media screen and (min-width:768px){.use-case-body\u003E.snowflake-flexible-column-container-items\u003Ediv:first-child{position:sticky;top:200px}}.page-toc ul{list-style-type:none;padding:0}.page-toc li{padding:8px 16px;border-left:4px solid var(--ui-01);cursor:pointer;transition:300ms ease all}.page-toc li:hover{color:var(--ui-01);border-color:#7fd3f1;transition:300ms ease all}.story-highlights{padding:48px;border-radius:4px}.logo-container{max-width:180px}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container{align-items:center;justify-content:center;gap:48px;flex-wrap:nowrap}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container\u003Ediv{width:auto;margin:0 !important}.flex-container\u003E.container\u003E.cmp-container\u003E.aem-container\u003Ediv:last-child{flex-grow:1}.flex-container .aem-Grid::before,.flex-container .aem-Grid::after{display:none !important}.snowflake-highlights{overflow:hidden;background-color:var(--ui-background-05);padding-left:24px;padding-right:24px;border:1px solid #ccc;border-radius:8px}div.use-case-body .snowflake-text h2,div.use-case-body .snowflake-text .heading-2-v2,div.use-case-body .snowflake-text h3,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-title-v2 .heading-3-v2,div.use-case-body .snowflake-text h4,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-title-v2 .heading-4-v2,div.use-case-body .snowflake-text h5,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-title-v2 .heading-5-v2,div.use-case-body .snowflake-text h6,div.use-case-body .snowflake-title-v2 .heading-6-v2,div.use-case-body .snowflake-text .heading-6-v2{text-transform:none !important}div.use-case-body .snowflake-text h2,div.use-case-body .snowflake-text .heading-2-v2,div.use-case-body .snowflake-text h3,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-text h4,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-text h5,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-text h6,div.use-case-body .snowflake-text .heading-6-v2{margin-top:1.5rem !important;line-height:1.1 !important}div.use-case-body .snowflake-text h3,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-title-v2 .heading-3-v2,div.use-case-body .snowflake-text h4,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-title-v2 .heading-4-v2,div.use-case-body .snowflake-text h5,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-title-v2 .heading-5-v2,div.use-case-body .snowflake-text h6,div.use-case-body .snowflake-text .heading-6-v2,div.use-case-body .snowflake-text .heading-6-v2,div.use-case-body .snowflake-title-v2 .heading-6-v2{font-family:Lato,sans-serif !important;font-weight:800 !important}div.use-case-body .snowflake-text h2,div.use-case-body .snowflake-text .heading-2-v2,div.use-case-body .snowflake-title-v2 .heading-2-v2{text-transform:none !important;font-size:28px !important}div.use-case-body .snowflake-text h3,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-title-v2 .heading-3-v2{font-size:22px !important}div.use-case-body .snowflake-text h4,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-title-v2 .heading-4-v2{font-size:18px !important}div.use-case-body .snowflake-text h5,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-title-v2 .heading-5-v2{font-size:16px !important}div.use-case-body .snowflake-text h6,div.use-case-body .snowflake-text .heading-6-v2,div.use-case-body .snowflake-title-v2 .heading-6-v2{font-size:14px !important}@media screen and (min-width:992px){div.use-case-body .snowflake-text h2,div.use-case-body .snowflake-text .heading-2-v2,div.use-case-body .snowflake-title-v2 .heading-2-v2{font-size:38px !important}div.use-case-body .snowflake-text h3,div.use-case-body .snowflake-text .heading-3-v2,div.use-case-body .snowflake-title-v2 .heading-3-v2{font-size:26px !important}div.use-case-body .snowflake-text h4,div.use-case-body .snowflake-text .heading-4-v2,div.use-case-body .snowflake-title-v2 .heading-4-v2{font-size:22px !important}div.use-case-body .snowflake-text h5,div.use-case-body .snowflake-text .heading-5-v2,div.use-case-body .snowflake-title-v2 .heading-5-v2{font-size:18px !important}div.use-case-body .snowflake-text h6,div.use-case-body .snowflake-text .heading-6-v2,div.use-case-body .snowflake-title-v2 .heading-6-v2{font-size:16px !important}}","jsContent":"window.addEventListener('click',(e)=\u003E{if(e.target.tagName==='LI'&&e.target.dataset.anchor){const target=document.getElementById(e.target.dataset.anchor);if(target){const targetPosition=target.getBoundingClientRect().top+window.pageYOffset-220;window.scrollTo({top:targetPosition,behavior:'smooth'});}}});",":type":"snowflake-site/components/markup-editor","isGSAPEnabled":false},"responsivegrid":{"columnCount":12,"columnClassNames":{"container":"aem-GridColumn aem-GridColumn--default--12","container_411970921_":"aem-GridColumn aem-GridColumn--default--12","hero_system_copy":"aem-GridColumn aem-GridColumn--default--12","container_copy":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12",":items":{"hero_system_copy":{"id":"hero-system-4ef2c994cc","additionalClasses":"fundamentals-hero","heroStyle":"primary","headline":{"id":"headline","type":"display2","lines":["AI in Cybersecurity: How It Works, Use Cases and What’s Ahead"],":type":"snowflake-site/components/title-v2"},"subheadline":{"id":"subheadline","text":"\u003Cp\u003EThis guide explains how AI is used in cybersecurity today, where it delivers the most value, which limitations organizations need to account for, and how security leaders can build a strategy that aligns AI adoption with governance, operational design and real-world risk.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text"},"layout":"60-40","buttons_container":{"layout":"SIMPLE","id":"container-249522f0fd",":type":"snowflake-site/components/button/buttons-container",":items":{},":itemsOrder":[]},"flexible_container":{"layout":"SIMPLE","id":"container-ed49c7b5c1",":type":"snowflake-site/components/container",":items":{"breadcrumb":{"id":"breadcrumb-4c6393a339","items":[{"id":"breadcrumb-4c6393a339-item-4b75ed29e6","link":{"valid":true,"url":"/en/artificial-intelligence/"},"active":false,"current":false,"title":"Artificial Intelligence","appliedCssClassNames":"summit-page",":type":"snowflake-site/components/structure/page"},{"id":"breadcrumb-4c6393a339-item-2ad6169dd6","link":{"valid":true,"url":"/en/artificial-intelligence/industries/"},"active":false,"current":false,"title":"AI in Industries","appliedCssClassNames":"summit-page",":type":"snowflake-site/components/structure/page"},{"id":"breadcrumb-4c6393a339-item-2bffd67d9e","link":{"valid":true,"url":"/en/artificial-intelligence/industries/ai-in-cybersecurity/"},"active":true,"current":true,"title":"AI in Cybersecurity","appliedCssClassNames":"summit-page",":type":"snowflake-site/components/structure/fundamentals-page"}],":type":"snowflake-site/components/breadcrumb"}},":itemsOrder":["breadcrumb"]},":type":"snowflake-site/components/hero-system","appliedCssClassNames":"snowflake-hero-system-background-grad-white"},"container_copy":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"container":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-c13a43f42b","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"container":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"flexible_column_cont":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-8af34d80db","appliedCssClassNames":"snowflake-container snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"flexible_column_cont":{"id":"flexible-column-container-52f57ae5d0","type":"2-column-25-75","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"medium","bottomPadding":"medium","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"use-case-body","backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-f7938282de","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"text":{"id":"text-bc7817c95b","additionalClasses":"page-toc","text":"\u003Cul\u003E\u003Cli data-anchor=\"what-is-ai-in-cybersecurity\"\u003EWhat is AI in cybersecurity?\u003C/li\u003E\u003Cli data-anchor=\"why-ai-in-cybersecurity-matters-now\"\u003EWhy AI in cybersecurity matters now\u003C/li\u003E\u003Cli data-anchor=\"how-ai-is-used-in-cybersecurity\"\u003EHow AI is used in cybersecurity\u003C/li\u003E\u003Cli data-anchor=\"ai-powered-cybersecurity-tools-and-technologies\"\u003EAI-powered cybersecurity tools and technologies\u003C/li\u003E\u003Cli data-anchor=\"the-rise-of-agentic-ai-in-cyber-defense\"\u003EThe rise of agentic AI in cyber defense\u003C/li\u003E\u003Cli data-anchor=\"how-attackers-use-ai-and-how-defenders-should-respond\"\u003EHow attackers use AI — and how defenders should respond\u003C/li\u003E\u003Cli data-anchor=\"benefits-of-ai-in-cybersecurity\"\u003EBenefits of AI in cybersecurity\u003C/li\u003E\u003Cli data-anchor=\"challenges-and-limitations-of-ai-in-cybersecurity\"\u003EChallenges and limitations of AI in cybersecurity\u003C/li\u003E\u003Cli data-anchor=\"building-an-ai-cybersecurity-strategy-a-practical-roadmap\"\u003EBuilding an AI cybersecurity strategy: a practical roadmap\u003C/li\u003E\u003Cli data-anchor=\"where-ai-in-cybersecurity-is-heading-next\"\u003EWhere AI in cybersecurity is heading next\u003C/li\u003E\u003Cli data-anchor=\"what-it-takes-to-use-ai-well-in-cybersecurity\"\u003EWhat it takes to use AI well in cybersecurity\u003C/li\u003E\u003Cli data-anchor=\"ai-in-cybersecurity-faqs\"\u003EAI in cybersecurity FAQs\u003C/li\u003E\u003Cli data-anchor=\"resources\"\u003EResources\u003C/li\u003E\u003C/ul\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"experiencefragment":{"id":"experiencefragment-a63b8061d7","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/share-icons/share-icons-no-title/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/share-icons/share-icons-no-title.xfmodel.json"}},":itemsOrder":["text","experiencefragment"]},"flexible_column_content_container_2":{"layout":"SIMPLE","id":"fundamentals-main-content","appliedCssClassNames":"snowflake-responsive-container-inner-padding-large",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"section_0":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","text":"aem-GridColumn aem-GridColumn--default--12","text_696922189":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"what-is-ai-in-cybersecurity","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"text":{"id":"text-be5f313bae","text":"\u003Cp\u003E\u003Cu\u003E\u003C/u\u003EThe typical enterprise security environment produces more signal than any team can process manually. What slows teams down is not just alert volume, but also the effort required to connect events across systems and decide which patterns point to actual risk. A login from a known user looks routine until you pair it with a new device, an unusual time of day and a sudden burst of queries against a sensitive system. By the time those signals have been manually connected across multiple tools, the window for early intervention may already be closing.\u003C/p\u003E\r\n\u003Cp\u003EThe use of AI in cybersecurity is helping teams meet this challenge by correlating signals across systems, surfacing what merits attention and shortening the distance between data and decision.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"title_v2":{"id":"title-v2-36ef31c301","type":"heading2","lines":["What is AI in cybersecurity?"],":type":"snowflake-site/components/title-v2"},"text_696922189":{"id":"text-a4e4d677c0","text":"\u003Cp\u003E\u003Cu\u003E\u003C/u\u003EAI in cybersecurity refers to the use of \u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/machine-learning/\"\u003Emachine learning\u003C/a\u003E, natural language processing, behavioral analytics and related techniques to detect suspicious activity, prioritize risk and automate parts of security operations. In practice, this means models are trained or tuned to work across security-relevant data — authentication events, endpoint telemetry, network traffic, cloud logs, email signals, vulnerability feeds, query history or asset metadata — then used to identify patterns that merit investigation.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"text_0":{"id":"text-d121beffe8","additionalClasses":"list--blue-bullets","text":"\u003Cul\u003E\r\n\u003Cli\u003E\u003Cb\u003EA behavioral model\u003C/b\u003E can establish a baseline for normal access patterns, then flags a departure from that baseline.\u003C/li\u003E\r\n\u003Cli\u003E\u003Cb\u003EA classification model\u003C/b\u003E can score whether an email resembles known phishing attempts.\u003C/li\u003E\r\n\u003Cli\u003E\u003Cb\u003EA prioritization model\u003C/b\u003E can weight exploitability, asset exposure and business criticality so a vulnerability queue reflects actual risk instead of just a \u003Ca href=\"https://nvd.nist.gov/vuln-metrics/cvss\" target=\"_blank\" rel=\"noopener noreferrer\"\u003ECVSS\u003C/a\u003E score.\u003C/li\u003E\r\n\u003Cli\u003E\u003Cb\u003EA natural-language interface\u003C/b\u003E can let an analyst query a \u003Ca href=\"https://www.irs.gov/privacy-disclosure/security-information-and-event-management-siem-systems\"\u003ESIEM\u003C/a\u003E or summarize an incident without writing every search manually.\u003C/li\u003E\r\n\u003C/ul\u003E\r\n\u003Cp\u003EThese capabilities often sit inside \u003Ca href=\"https://www.snowflake.com/en/fundamentals/ai-security/systems/\"\u003EAI security systems\u003C/a\u003E, where detection, analysis and response functions are applied across multiple parts of the security workflow rather than in isolation.\u003C/p\u003E\r\n\u003Cp\u003ENote that this article focuses on the use of AI for cybersecurity — AI applied to threat detection, prevention and response. This is different from cybersecurity for AI, which deals with protecting models, prompts, training data and AI applications themselves. Many discussions fold together every security-adjacent AI topic into one bucket, but the two disciplines solve different problems, draw on different data and require different controls.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ci\u003EFor a deeper look at securing AI systems themselves, see our \u003Ca href=\"https://www.snowflake.com/en/fundamentals/ai-security/\"\u003Eguide to AI security\u003C/a\u003E.\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["text","title_v2","text_696922189","text_0"]},"section_1":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"why-ai-in-cybersecurity-matters-now","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-b568270b58","type":"heading2","lines":["Why AI in cybersecurity matters now"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-d97e2beee6","text":"\u003Cp\u003ESecurity teams live inside environments that produce massive amounts of data: endpoint events, identity logs, SaaS access records, cloud control-plane activity, network flows, code and pipeline signals, data access history, third-party alerts and more — all arriving with different schemas, retention policies and levels of reliability.\u003C/p\u003E\u003Cp\u003EIn a smaller environment, a senior analyst can often compensate for tool fragmentation with experience. In an enterprise environment, however, where the same identity may move across a SaaS app, a warehouse, an endpoint and a cloud workload within the same hour, correlation has to happen faster and more consistently than manual review allows.\u003C/p\u003E\u003Cp\u003EAt the same time, attackers are using AI to improve the quality and speed of their own work. \u003Ca href=\"https://www.mckinsey.com/about-us/new-at-mckinsey-blog/ai-is-the-greatest-threat-and-defense-in-cybersecurity-today\"\u003EMcKinsey’s 2025 RSA recap\u003C/a\u003E points to AI accelerating cyberattacks, clocking breakout times at under an hour. Hackers are using AI tools to create realistic phishing emails, fake websites and malicious prompts that bypass traditional detection mechanisms — on an exponential scale.\u003C/p\u003E\u003Cp\u003EThere is also a staffing reality behind the urgency. Security programs continue to operate under skill and coverage constraints, often struggling to fill open roles for analysts, engineers and responders. AI is attractive because it frees highly skilled security teams from repetitive work, such as deduplicating alerts, enriching cases, ranking risk, summarizing evidence and routing incidents into the right workflow.\u003C/p\u003E\u003Cp\u003ECost adds to the pressure. \u003Ca href=\"https://www.ibm.com/reports/data-breach\"\u003EIBM’s 2025 Cost of a Data Breach\u003C/a\u003E findings put the global average breach cost at $4.4 million USD, while the use of security AI and automation is associated with $1.9 million cost savings compared to organizations that don’t use AI security solutions.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0"]},"section_2":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"h3_title_7":"aem-GridColumn aem-GridColumn--default--12","h3_title_3":"aem-GridColumn aem-GridColumn--default--12","h3_title_4":"aem-GridColumn aem-GridColumn--default--12","text_1":"aem-GridColumn aem-GridColumn--default--12","h3_title_5":"aem-GridColumn aem-GridColumn--default--12","text_0":"aem-GridColumn aem-GridColumn--default--12","h3_title_6":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","h3_title_0":"aem-GridColumn aem-GridColumn--default--12","h3_title_1":"aem-GridColumn aem-GridColumn--default--12","h3_title_2":"aem-GridColumn aem-GridColumn--default--12","text_3":"aem-GridColumn aem-GridColumn--default--12","text_2":"aem-GridColumn aem-GridColumn--default--12","text_5":"aem-GridColumn aem-GridColumn--default--12","text_4":"aem-GridColumn aem-GridColumn--default--12","text_7":"aem-GridColumn aem-GridColumn--default--12","text_6":"aem-GridColumn aem-GridColumn--default--12","text_8":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"how-ai-is-used-in-cybersecurity","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-b0d63e85f0","type":"heading2","lines":["How AI is used in cybersecurity"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-7ee44ae59a","text":"\u003Cp\u003EThe best way to understand how teams are using AI in cybersecurity today is to follow the work itself.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_0":{"id":"title-v2-01541dfa36","type":"heading3","lines":["Threat detection and anomaly identification"],":type":"snowflake-site/components/title-v2"},"text_1":{"id":"text-22256a45bb","text":"\u003Cp\u003EThreat detection remains the clearest use case. A modern environment produces identity events, API calls, process launches, file-access patterns, DNS requests, network flows and data queries that look ordinary when viewed individually. AI helps spot anomalies by comparing each event against a wider behavioral context.\u003C/p\u003E\r\n\u003Cp\u003EThis is most useful where \u003Ca href=\"https://www.crowdstrike.com/en-us/cybersecurity-101/malware/malware-detection/\"\u003Esignature-based methods\u003C/a\u003E are weak. Signature and rule-based detection still have a clear role, especially for known malware, but they are less effective when an attacker creates custom payloads, uses legitimate credentials or moves in ways that stay close to normal operations. User and entity behavior analytics (UEBA) helps security teams see departures from expected activity.\u003C/p\u003E\r\n\u003Cp\u003EA useful frame for evaluating detection coverage is \u003Ca href=\"https://attack.mitre.org/\"\u003EMITRE ATT&amp;CK\u003C/a\u003E, the widely adopted knowledge base of adversary tactics, techniques and procedures. Security teams use ATT&amp;CK to map what their current tooling can actually detect, identify gaps in coverage and evaluate whether AI-assisted detection is improving their ability to surface activity across relevant technique categories.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_1":{"id":"title-v2-645a3b8a81","type":"heading3","lines":["Proactive threat hunting"],":type":"snowflake-site/components/title-v2"},"text_2":{"id":"text-4c9b6de7b5","text":"\u003Cp\u003EThreat hunters start with a hypothesis — a belief that an attacker may be operating in the environment in a way that hasn’t yet triggered any alert — and go looking for evidence that confirms or rules it out. The work is analyst-driven and investigative, but AI accelerates it at several points in the process.\u003C/p\u003E\u003Cp\u003EHypothesis generation is one of the earliest leverage points. AI can identify activity worth investigating by spotting low-signal patterns in historical telemetry that passive detection has not flagged — for example, unusual sequences of access, dormant accounts showing small signs of activity, or lateral movement that stayed just below behavioral thresholds. A threat hunter who might otherwise spend hours pulling and filtering data can start with a shorter list of leads worth pursuing.\u003C/p\u003E\u003Cp\u003EQuery assistance is another practical application of AI. Hunting across a large data set requires constructing searches that are precise enough to be useful without being so narrow that they miss variations. AI can help analysts translate a hypothesis into effective queries, suggest related search angles and identify when a line of investigation is producing noise versus signal.\u003C/p\u003E\u003Cp\u003EAI excels in pattern recognition across time and scale. A hunter looking for signs of a slow-moving intrusion — one designed to stay below detection thresholds by mimicking normal behavior — can spot the attack more easily since AI can hold more context across longer time windows and more data sources than an analyst working manually.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_2":{"id":"title-v2-68fd3c02ff","type":"heading3","lines":["Automated incident response"],":type":"snowflake-site/components/title-v2"},"text_3":{"id":"text-550e386a3a","text":"\u003Cp\u003EIncident response is full of steps that are necessary, repetitive and expensive to perform by hand. When an alert arrives, the analyst has to pull surrounding activity, check asset ownership, inspect related indicators, consult prior incidents, attach threat intelligence, draft notes and decide whether the event belongs in a containment workflow or a lower-priority queue. Much of that work follows the same pattern each time.\u003C/p\u003E\u003Cp\u003EAI helps shorten the path. It can collect supporting evidence before the ticket is opened, summarize what changed, cluster duplicates, identify likely severity and prepare a case so the analyst begins with context instead of with raw fragments. In some environments it can also trigger bounded actions — revoking a token, isolating a device, stepping up authentication or creating a response task — when the confidence threshold and business impact are both well understood.\u003C/p\u003E\u003Cp\u003EThe operational gain here usually comes from drag reduction. A tier-one queue moves faster when obvious false positives are filtered earlier, when repeated alerts are grouped together and when the human reviewer spends less time assembling the case and more time deciding what it means.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_3":{"id":"title-v2-34e5920551","type":"heading3","lines":["Vulnerability management and prioritization"],":type":"snowflake-site/components/title-v2"},"text_4":{"id":"text-76ae8a00fc","text":"\u003Cp\u003EVulnerability scanners may report thousands of issues across endpoints, workloads, containers and applications. But the queue is only actionable when the team can distinguish between a flaw that is theoretically serious and one that is both exploitable and relevant in the current environment. AI helps by attaching context that static severity alone cannot capture — whether the asset is internet-facing, exploit code is circulating, the vulnerable system holds privileged access, the weakness appears in an exposed path or threat activity makes the issue more likely to be used soon.\u003C/p\u003E\u003Cp\u003EFor example, a medium-severity flaw on an exposed system that supports a revenue-critical service may deserve immediate action, while a higher-scoring issue buried in an isolated internal environment might be able to wait. Security teams have always known this informally, but AI helps apply this knowledge more consistently across a large estate.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_4":{"id":"title-v2-5cc02a0b0c","type":"heading3","lines":["Phishing and social engineering defense"],":type":"snowflake-site/components/title-v2"},"text_5":{"id":"text-004f49e6c7","text":"\u003Cp\u003EPhishing is where many organizations encounter the attacker side of AI most directly. \u003Ca href=\"https://www.snowflake.com/en/fundamentals/large-language-model/\"\u003ELarge language models\u003C/a\u003E (LLMs) make it easier to generate emails that read cleanly, mimic internal tone, reference plausible business activity and adapt to a target's role or region. And a message does not have to be perfect to succeed. It often merely has to look legitimate enough for a split-second decision to click a link, enter a credential or sign an approval.\u003C/p\u003E\r\n\u003Cp\u003EAI-powered defense responds by evaluating sender behavior, domain age, message content, link structure, historical communication patterns and the surrounding user context, rather than relying only on keywords or blocklists.\u003C/p\u003E\r\n\u003Cp\u003EThis capability is especially important in business email compromise and spear-phishing scenarios, where the malicious message often resembles routine work. A request to review an invoice, reset a password or approve a transfer may not stand out on language alone. It may be flagged as suspicious only when the system notices that the sender has never used that domain before, the target rarely receives this type of request, the embedded link resolves through a newly created host and the recipient has an elevated approval role.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_5":{"id":"title-v2-a4847f3810","type":"heading3","lines":["Threat intelligence analysis"],":type":"snowflake-site/components/title-v2"},"text_6":{"id":"text-b42d9d4ef5","text":"\u003Cp\u003EThreat intelligence teams work with a constant inflow of indicators, advisories, feed updates and internal signals, much of it arriving in different formats, with uneven reliability and a shelf life that can be very short. AI helps make this material more usable by correlating indicators across sources, grouping related activity into likely campaigns or actor patterns, removing obvious duplication and surfacing the threat clusters most relevant to the organization's environment, asset profile and current exposures.\u003C/p\u003E\r\n\u003Cp\u003EThe operational payoff is that analysts spend less time normalizing and ingesting data and more time on interpretation and action. AI can also surface relationships between indicators that manual review would miss — connecting a newly observed domain to infrastructure used in a prior campaign, for example, or identifying when a \u003Ca href=\"https://csrc.nist.gov/glossary/term/Tactics_Techniques_and_Procedures\"\u003ETTPs cluster\u003C/a\u003E reported in one sector has started appearing in another. For organizations in industry threat-sharing programs, AI-assisted correlation is increasingly how that information gets turned into actionable context rather than sitting in a queue.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_6":{"id":"title-v2-cd70d5735e","type":"heading3","lines":["Identity and access management (IAM)"],":type":"snowflake-site/components/title-v2"},"text_7":{"id":"text-fc893a260d","text":"\u003Cp\u003EAn IAM workflow often contains a rich set of behavioral signals, including device posture, login timing, location, authentication method, privilege level, session duration, network context and subsequent access activity. AI can evaluate those signals together and produce a dynamic risk judgment rather than a static pass/fail decision. This supports adaptive access, where a user whose behavior matches expectation moves through with little friction, while a session that shows unusual patterns is challenged, restricted or escalated.\u003C/p\u003E\u003Cp\u003EThe benefit grows when identity is tied to downstream activity. A risky login matters more when it is followed by unusual query volume, privilege changes, token creation or access to data the user rarely touches. This is where identity protection begins to merge with data security and broader telemetry analysis to form a more robust defense.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_7":{"id":"title-v2-5476d37d83","type":"heading3","lines":["Network traffic and cloud environment analysis"],":type":"snowflake-site/components/title-v2"},"text_8":{"id":"text-18107e8d9a","text":"\u003Cp\u003ENetwork traffic still tells an important story, even in environments where identity and SaaS sprawl dominate the architecture. Attackers who gain footholds still need to move, communicate and extract value, which means command-and-control patterns, lateral movement, beaconing and exfiltration behaviors remain relevant.\u003C/p\u003E\u003Cp\u003EAI-powered network detection and response tools are useful because they can evaluate timing, sequencing and relationship patterns that do not look malicious in a single packet or a single connection. A low-and-slow exfiltration path, an unusual east-west communication pattern between workloads, or a sequence of internal calls that departs from baseline may emerge more clearly when the system compares it against normal behavior over time.\u003C/p\u003E\u003Cp\u003EIn cloud environments, the same logic extends to control-plane and workload telemetry. The activity of a role, workload or service account is often more important than the perimeter it sits behind. This is one reason AI cloud security is becoming a more distinct category: the data to be interpreted now includes API behavior, ephemeral resources, configuration drift and workload-to-workload relationships as much as traditional network traffic.\u003C/p\u003E\u003Cp\u003E\u003Cem\u003EExplore Snowflake solutions for \u003Ca href=\"https://www.snowflake.com/en/solutions/departments/cybersecurity/\"\u003Emodern cybersecurity operations\u003C/a\u003E.\u003C/em\u003E\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0","h3_title_0","text_1","h3_title_1","text_2","h3_title_2","text_3","h3_title_3","text_4","h3_title_4","text_5","h3_title_5","text_6","h3_title_6","text_7","h3_title_7","text_8"]},"section_3":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"youtube":"aem-GridColumn aem-GridColumn--default--12","text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","text":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"ai-powered-cybersecurity-tools-and-technologies","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-c2fd41d243","type":"heading2","lines":["AI-powered cybersecurity tools and technologies"],":type":"snowflake-site/components/title-v2"},"text":{"id":"text-48c642770a","text":"\u003Cp\u003E\u003Cu\u003E\u003C/u\u003EMost organizations will encounter AI in cybersecurity through products they already use or categories they already understand. For example:\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"text_0":{"id":"text-b234ffecb3","additionalClasses":"list--blue-bullets","text":"\u003Cul\u003E\r\n\u003Cli\u003EA SIEM may offer AI-assisted correlation and investigation.\u003C/li\u003E\r\n\u003Cli\u003EAn \u003Ca href=\"https://www.crowdstrike.com/en-us/cybersecurity-101/endpoint-security/edr-vs-mdr-vs-xdr/\"\u003EEDR or XDR platform\u003C/a\u003E may apply behavioral models to endpoint and cross-domain activity.\u003C/li\u003E\r\n\u003Cli\u003EA \u003Ca href=\"https://www.servicenow.com/products/security-operations/what-is-soar.html\"\u003ESOAR\u003C/a\u003E workflow may use AI to enrich alerts, classify incidents and summarize response notes.\u003C/li\u003E\r\n\u003Cli\u003EA network detection platform may use models to surface communication patterns that deviate from baseline.\u003C/li\u003E\r\n\u003Cli\u003EIdentity analytics tools may score session risk and flag account misuse.\u003C/li\u003E\r\n\u003C/ul\u003E\r\n\u003Cp\u003ESecurity teams rarely begin by building bespoke detection models against raw telemetry. They adopt AI through the stack, then learn where it is genuinely improving outcomes and where it still needs tighter controls or better data. Cloud security products increasingly use AI to prioritize exposure and policy drift in environments where manual review has become unwieldy.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/generative-ai/\"\u003EGenerative AI\u003C/a\u003E is also changing the analyst interface. A responder can describe the activity they want to investigate in plain language, receive a draft summary of a multi-stage incident or generate a first-pass report from case evidence that would otherwise take longer to assemble.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ci\u003EWatch top cybersecurity companies discuss what next-generation cybersecurity looks like in practice:\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"youtube":{"id":"embed-38680e2149","youtubeVideoId":"UD6fkNU2fIM","layout":"responsive","youtubeAspectRatio":"56.25","youtubeAutoPlay":false,"youtubeLoop":false,"youtubeMute":false,"youtubePlaysInline":false,"youtubeRel":false,"embeddableResourceType":"core/wcm/components/embed/v1/embed/embeddable/youtube","type":"EMBEDDABLE",":type":"snowflake-site/components/youtube"}},":itemsOrder":["title_v2","text","text_0","youtube"]},"section_4":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"the-rise-of-agentic-ai-in-cyber-defense","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-b7e39c4d04","type":"heading2","lines":["The rise of agentic AI in cyber defense"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-5c0ad9b991","text":"\u003Cp\u003ESecurity work contains many bounded, multi-step tasks that benefit from planning and execution across several tools — an ideal scenario for an \u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/agents/\"\u003Eagentic AI system\u003C/a\u003E. The realistic near-term model, though, is supervised assistance rather than fully autonomous defense. Organizations are not (and should not be) handing high-impact response authority to an agent and stepping away. They are experimenting with agents that help analysts collect evidence faster, prepare a case more thoroughly or suggest next actions within clear boundaries.\u003C/p\u003E\r\n\u003Cp\u003ECaution is warranted because an agent introduces a larger operating surface — and thus a larger attack surface. Once an AI agent can retrieve context, invoke tools, access tickets or trigger workflows, the quality of its permissions, grounding and validation begins to matter as much as the fluency of its output. A prompt-injected agent with broad access may be dangerous. For this reason, human approval gates, tool scoping, audit logs and \u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/ai-governance/\"\u003Egovernance controls\u003C/a\u003E belong in the design from the start.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ci\u003ERead \u003Ca href=\"https://www.snowflake.com/en/fundamentals/ai-security/agents/\"\u003EAI Security for Agents\u003C/a\u003E to learn how to secure agentic AI in production.\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0"]},"section_5":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"how-attackers-use-ai-and-how-defenders-should-respond","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-cbf9252ebb","type":"heading2","lines":["How attackers use AI — and how defenders should respond"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-9dd113174a","text":"\u003Cp\u003E\u003Ca href=\"https://www.weforum.org/publications/global-cybersecurity-outlook-2026/\"\u003EThe WEF Global Cybersecurity Outlook 2026\u003C/a\u003E reveals that CEOs ranked cyber-enabled fraud and phishing as their #1 concern in 2026. Attackers are using AI everywhere it lowers the cost of their attack efforts and accelerates results.\u003C/p\u003E\r\n\u003Cp\u003EPhishing is the obvious case, because LLMs can produce more tailored messages than many low-effort campaigns used in the past. Deepfakes extend this concern into voice and video, which matters in organizations that rely on remote approvals, executive requests or loosely verified internal communications. AI can also help attackers accelerate reconnaissance, test variations more quickly and explore ways to evade detection logic that depends on recognizable patterns.\u003C/p\u003E\r\n\u003Cp\u003ENot that every attacker has become dramatically more sophisticated, but more attackers can now produce quality deception at speed, which shifts the defender's problem from filtering clumsy attempts to validating plausible ones.\u003C/p\u003E\r\n\u003Cp\u003EDefensive response teams need stronger validation paths around approvals, better identity hygiene, tighter access control, model testing against adversarial conditions and a more explicit understanding of where AI-enabled workflows can themselves be manipulated. A system that relies on poor context, weak provenance or over-broad permissions can fail in ways that stay under the radar until the failure has already propagated.\u003C/p\u003E\r\n\u003Cp\u003EThis is one reason the data layer matters so much. If a model is acting on telemetry, logs, lineage, access metadata or retrieved documents, the quality and trustworthiness of those inputs becomes part of the security posture.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0"]},"section_6":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"h3_title_3":"aem-GridColumn aem-GridColumn--default--12","h3_title_4":"aem-GridColumn aem-GridColumn--default--12","text_1":"aem-GridColumn aem-GridColumn--default--12","text_0":"aem-GridColumn aem-GridColumn--default--12","text_3":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","h3_title_0":"aem-GridColumn aem-GridColumn--default--12","text_2":"aem-GridColumn aem-GridColumn--default--12","h3_title_1":"aem-GridColumn aem-GridColumn--default--12","text_5":"aem-GridColumn aem-GridColumn--default--12","h3_title_2":"aem-GridColumn aem-GridColumn--default--12","text_4":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"benefits-of-ai-in-cybersecurity","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-b2aa101709","type":"heading2","lines":["Benefits of AI in cybersecurity"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-aab2759299","text":"\u003Cp\u003EThe strongest benefits of using AI in cybersecurity tend to appear in the parts of security operations that are repetitive, time-sensitive and context-heavy.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_0":{"id":"title-v2-3228fa5e6d","type":"heading3","lines":["Faster detection and response"],":type":"snowflake-site/components/title-v2"},"text_1":{"id":"text-1ee6f6463b","text":"\u003Cp\u003EWhen AI can sort low-confidence alerts, attach relevant evidence and surface correlated activity earlier, analysts reach useful judgments faster. Speed matters because the economic and operational cost of delay compounds quickly once an attacker establishes a foothold.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_1":{"id":"title-v2-f0e4a9c011","type":"heading3","lines":["Better prioritization"],":type":"snowflake-site/components/title-v2"},"text_2":{"id":"text-4502212914","text":"\u003Cp\u003EAI helps rank vulnerabilities, incidents and access anomalies using a wider set of conditions than static scoring allows, which makes queues more actionable. AI can also surface findings that appear minor on their own but carry outsized consequences once asset exposure, privilege level or attacker activity is taken into account — and reduce wasted effort on findings that look serious in theory but matter less in context.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_2":{"id":"title-v2-37aa2db941","type":"heading3","lines":["More complete use of telemetry"],":type":"snowflake-site/components/title-v2"},"text_3":{"id":"text-50be746c74","text":"\u003Cp\u003ELogs and events that would otherwise remain underused become more valuable when models can evaluate them continuously and across domains. This is especially important in environments where the same incident touches endpoint, identity, cloud and data access systems within a short period of time.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_3":{"id":"title-v2-687a68f77d","type":"heading3","lines":["More consistent triage"],":type":"snowflake-site/components/title-v2"},"text_4":{"id":"text-22db2da3ed","text":"\u003Cp\u003ETriage quality tends to drift when analysts are overloaded, workflows are fragmented or the context arrives late. AI can make routine review more consistent by applying the same enrichment and ranking logic every time, which gives teams a more stable starting point for human judgment.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_4":{"id":"title-v2-dedd245936","type":"heading3","lines":["Better use of scarce expertise"],":type":"snowflake-site/components/title-v2"},"text_5":{"id":"text-0a2a50525d","text":"\u003Cp\u003EExperienced responders and security architects are expensive and difficult to replace. When AI absorbs more of the mechanical work around case assembly, evidence collection and initial summarization, those people can spend more time on investigation, threat hunting, architecture and control design.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0","h3_title_0","text_1","h3_title_1","text_2","h3_title_2","text_3","h3_title_3","text_4","h3_title_4","text_5"]},"section_7":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"h3_title_3":"aem-GridColumn aem-GridColumn--default--12","h3_title_4":"aem-GridColumn aem-GridColumn--default--12","text_1":"aem-GridColumn aem-GridColumn--default--12","text_0":"aem-GridColumn aem-GridColumn--default--12","text_3":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","h3_title_0":"aem-GridColumn aem-GridColumn--default--12","text_2":"aem-GridColumn aem-GridColumn--default--12","h3_title_1":"aem-GridColumn aem-GridColumn--default--12","text_5":"aem-GridColumn aem-GridColumn--default--12","h3_title_2":"aem-GridColumn aem-GridColumn--default--12","text_4":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"challenges-and-limitations-of-ai-in-cybersecurity","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-76ca8c5de7","type":"heading2","lines":["Challenges and limitations of AI in cybersecurity"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-43b6904aeb","text":"\u003Cp\u003EAI is not all-powerful, and its limitations are not inconsequential. These challenges need to be addressed as part of operational design.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_0":{"id":"title-v2-2cad2c9f5b","type":"heading3","lines":["Explainability and hallucinations"],":type":"snowflake-site/components/title-v2"},"text_1":{"id":"text-db2316333c","text":"\u003Cp\u003EAnalysts need to know why a model surfaced a finding, generated an output or triggered an action, which inputs factored into the decision and how much confidence the system actually has. Without this information, trust is hard to build and maintain.\u003C/p\u003E\r\n\u003Cp\u003EA related and consequential failure mode is hallucination. LLMs used in security workflows can generate plausible-sounding output that is factually wrong: a mischaracterized incident summary, an incorrect remediation step, a detection rule that appears valid but contains a logical error. In security operations, a hallucinated output can delay response, introduce false confidence or result in a control being misconfigured.\u003C/p\u003E\r\n\u003Cp\u003EThis makes grounding and validation especially important in security-facing AI deployments. Outputs that influence response decisions should be traceable to the underlying evidence they drew from, and analysts should have a practical way to verify claims rather than accepting summarized conclusions at face value. The risk is not that AI systems will always be wrong; it is that they can be wrong in ways that look authoritative, which is harder to catch than an obvious error.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_1":{"id":"title-v2-400e68efff","type":"heading3","lines":["Data quality and model drift"],":type":"snowflake-site/components/title-v2"},"text_2":{"id":"text-8b0a385808","text":"\u003Cp\u003EAn AI workflow inherits the weaknesses of the data it depends on. Incomplete logs, inconsistent identity mapping, stale asset context, poor retention or missing ownership can all weaken performance. Over time, models can also drift as environments, attacker behaviors and legitimate business processes change.\u003C/p\u003E\u003Cp\u003EFor example, a model trained on last year's access patterns may underperform against current attacker behavior or a reorganized environment without any obvious failure signal. This makes drift particularly insidious — the system continues to function, but coverage has eroded in ways that only become visible after a missed detection.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_2":{"id":"title-v2-8072c0b042","type":"heading3","lines":["False positives, false negatives and over-automation"],":type":"snowflake-site/components/title-v2"},"text_3":{"id":"text-183b65e69c","text":"\u003Cp\u003ESecurity teams already know the cost of noise. AI can reduce it, but it can also create new noise if a model is poorly calibrated or deployed without sufficient feedback loops. Additionally, overconfidence in automation can leave an organization exposed when an unusual incident falls outside the workflow the system was designed to handle. Human review cadences and exception-handling workflows exist precisely for these cases.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_3":{"id":"title-v2-703b67873e","type":"heading3","lines":["Adversarial pressure"],":type":"snowflake-site/components/title-v2"},"text_4":{"id":"text-dac96623dc","text":"\u003Cp\u003EAny detection method that becomes valuable will be targeted for evasion. Attackers can probe the boundaries of a model, exploit gaps in input validation or attempt to degrade the data used for training and inference. AI in security therefore needs continuous evaluation, not a onetime rollout.\u003C/p\u003E\u003Cp\u003EPrompt injection is a specific concern worth naming here. An attacker who can insert instructions into content that an AI system will process — a document, a ticket, a retrieved log entry — may be able to manipulate the system's behavior in ways that are difficult to detect and have nothing to do with the underlying model's accuracy.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_4":{"id":"title-v2-b99364200f","type":"heading3","lines":["Governance and accountability"],":type":"snowflake-site/components/title-v2"},"text_5":{"id":"text-9a05495314","text":"\u003Cp\u003EAs AI systems increasingly influence access, triage and response, organizations have to decide who is accountable for system behavior, how decisions are logged, how exceptions are handled and which controls apply when something goes wrong. \u003Ca href=\"https://www.nist.gov/itl/ai-risk-management-framework\"\u003ENIST's AI Risk Management Framework\u003C/a\u003E exists partly because these questions cannot be left unanswered or implicit.\u003C/p\u003E\u003Cp\u003EIn practice, this means defining which actions the AI system is permitted to take autonomously versus which require human approval, ensuring that model decisions are logged in a form that supports audit and review, establishing who owns the feedback process when the system underperforms, and scheduling periodic \u003Ca href=\"https://csrc.nist.gov/glossary/term/red_team\"\u003Ered-team\u003C/a\u003E evaluation to test whether the system holds up against realistic adversarial conditions — not just the scenarios it was designed around.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0","h3_title_0","text_1","h3_title_1","text_2","h3_title_2","text_3","h3_title_3","text_4","h3_title_4","text_5"]},"section_8":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"h3_title_3":"aem-GridColumn aem-GridColumn--default--12","h3_title_4":"aem-GridColumn aem-GridColumn--default--12","text_1":"aem-GridColumn aem-GridColumn--default--12","text_0":"aem-GridColumn aem-GridColumn--default--12","text_3":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12","h3_title_0":"aem-GridColumn aem-GridColumn--default--12","text_2":"aem-GridColumn aem-GridColumn--default--12","h3_title_1":"aem-GridColumn aem-GridColumn--default--12","text_5":"aem-GridColumn aem-GridColumn--default--12","h3_title_2":"aem-GridColumn aem-GridColumn--default--12","text_4":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"building-an-ai-cybersecurity-strategy-a-practical-roadmap","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-8b80294834","type":"heading2","lines":["Building an AI cybersecurity strategy: a practical roadmap"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-e610a83704","text":"\u003Cp\u003EA strong AI cybersecurity strategy takes shape when an organization treats AI as part of security operations design, not as a layer to be dropped on top of existing tools and processes.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_0":{"id":"title-v2-3d50c2cdfe","type":"heading3","lines":["1. Assess foundational readiness"],":type":"snowflake-site/components/title-v2"},"text_1":{"id":"text-d78c46079e","text":"\u003Cp\u003EBefore AI improves security operations, the underlying environment has to be legible enough to support it. Logging coverage, identity hygiene, asset ownership, data governance and workflow discipline all shape whether a model is working from usable context or from partial signals. If a team cannot confidently trace who owns a data set, which service account triggered a change or whether a critical log source is complete, the resulting workflow will move faster without necessarily becoming clearer.\u003C/p\u003E\u003Cp\u003ESecurity teams increasingly need visibility into data movement, access patterns, policy context and governed use, because AI-assisted security decisions are only as trustworthy as the underlying context attached to them.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_1":{"id":"title-v2-f85f60ffff","type":"heading3","lines":["2. Start with high-impact use cases"],":type":"snowflake-site/components/title-v2"},"text_2":{"id":"text-4719fc028c","text":"\u003Cp\u003EEarly AI efforts tend to work best in parts of security operations where the friction is visible, the workflow is established and the results can be clearly measured. Alert triage, phishing analysis, identity risk scoring and vulnerability prioritization are common starting points for this reason.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_2":{"id":"title-v2-c400330d7e","type":"heading3","lines":["3. Align governance and compliance early"],":type":"snowflake-site/components/title-v2"},"text_3":{"id":"text-48b0b3e888","text":"\u003Cp\u003EMap the initiative against the relevant control expectations before expansion. NIST's AI RMF provides one governance structure, while \u003Ca href=\"https://www.iso.org/standard/42001\"\u003EISO/IEC 42001\u003C/a\u003E offers a management-system discipline. \u003Ca href=\"https://artificialintelligenceact.eu/\"\u003EThe EU AI Act\u003C/a\u003E raises the bar for how some organizations will need to document and govern AI usage. Even when a framework is not legally binding in a given context, it often shapes stakeholder expectations anyway.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ci\u003EFor a deeper look at the policies, controls and oversight that support responsible AI use, explore our \u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/ai-governance/\"\u003Eguide to AI governance\u003C/a\u003E.\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_3":{"id":"title-v2-c130d9f5be","type":"heading3","lines":["4. Define the human-AI operating model"],":type":"snowflake-site/components/title-v2"},"text_4":{"id":"text-4ec9ba52d7","text":"\u003Cp\u003ESecurity teams work better when escalation boundaries are explicit — which actions may run automatically, which require approval, which conditions trigger exception review and which roles own model feedback. The most sustainable AI deployments are carefully bounded.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"h3_title_4":{"id":"title-v2-9cab2ede9e","type":"heading3","lines":["5. Measure, review and adjust"],":type":"snowflake-site/components/title-v2"},"text_5":{"id":"text-926cc5a148","text":"\u003Cp\u003ETrack what changes in practice: mean time to detect (MTTD), mean time to respond (MTTR), false-positive rates, remediation speed, analyst throughput and workflow adoption. Just as important, review where the system is weak — where context is missing, where the model is not well trusted or where human reviewers are quietly bypassing it.\u003C/p\u003E\u003Cp\u003E\u003Cem\u003EOrganizations running cloud workloads can explore our guide on \u003Ca href=\"https://www.snowflake.com/en/fundamentals/ai-security/cloud/\"\u003EAI cloud security\u003C/a\u003E for platform-specific guidance.\u003C/em\u003E\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0","h3_title_0","text_1","h3_title_1","text_2","h3_title_2","text_3","h3_title_3","text_4","h3_title_4","text_5"]},"section_9":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"where-ai-in-cybersecurity-is-heading-next","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-c8ada1d1f2","type":"heading2","lines":["Where AI in cybersecurity is heading next"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-4d7debaa8d","text":"\u003Cp\u003EThe next phase of AI in cybersecurity will likely be narrower and more consequential at the same time. One direction is toward faster adversarial iteration on both sides. The \u003Ca href=\"http://weforum.org/publications/global-cybersecurity-outlook-2026/\"\u003EWorld Economic Forum's 2026 outlook\u003C/a\u003E describes AI as a major force reshaping the cyber landscape, showing up operationally as shorter decision windows, more variable attack quality and greater pressure on defenders to detect subtle changes in behavior rather than only familiar artifacts.\u003C/p\u003E\u003Cp\u003EPredictive security work will likely also increasingly use AI. Instead of waiting for a control to fire after an event is already underway, teams are trying to estimate where compromise is most likely to emerge next by combining threat intelligence, exposure data, business criticality and behavioral signals.\u003C/p\u003E\u003Cp\u003EUndoubtedly, tighter regulation and governance will be required. As AI becomes more embedded in operational systems, enterprises will face more pressure to document training assumptions, model behavior, decision boundaries and auditability. This pressure is already becoming visible in the current governance frameworks. The business consequences of AI mismanagement — in the form of runaway risk, damaged trust and financial impact — are too high to ignore.\u003C/p\u003E\u003Cp\u003EOne of the most important priorities for enterprise architecture will be data-centric security. A credential, an endpoint or a workload may be the immediate point of compromise, but the prize an attacker often wants is data: customer records, models, intellectual property, financial information, regulated fields or operational context. As a result, the security conversation keeps moving closer to data access patterns, lineage, policy enforcement, telemetry unification and governed sharing.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0"]},"section_10":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"text_0":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"what-it-takes-to-use-ai-well-in-cybersecurity","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-a2f69c23e1","type":"heading2","lines":["What it takes to use AI well in cybersecurity"],":type":"snowflake-site/components/title-v2"},"text_0":{"id":"text-a8ac48796f","text":"\u003Cp\u003EAI is becoming part of cybersecurity for the same reason it is becoming part of so many operational systems: the work already produces more signals, more context and more decisions than people can process effectively on their own.\u003C/p\u003E\r\n\u003Cp\u003EIn security, though, usefulness has a stricter definition. A model has to help a team tell the difference between routine activity and meaningful risk, move faster without losing judgment and operate within controls that people can actually trust. This is why the strongest AI security programs usually start with concrete workflows and disciplined controls rather than with sweeping claims about autonomy. The organizations that benefit most will be the ones that pair AI with reliable data, workable workflows and strong human oversight.\u003C/p\u003E\r\n\u003Cp\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/industries/\"\u003ESee how AI is being used in other industries &gt;\u003C/a\u003E\u003C/p\u003E\r\n\u003Cp\u003E\u003Ci\u003EExplore the AI in Industries Hub:\u003C/i\u003E\u003C/p\u003E\r\n\u003Cul\u003E\r\n\u003Cli\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/industries/ai-in-healthcare/\"\u003EAI in Healthcare\u003C/a\u003E\u003C/li\u003E\r\n\u003Cli\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/industries/ai-in-manufacturing/\"\u003EAI in Manufacturing\u003C/a\u003E\u003C/li\u003E\r\n\u003Cli\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/industries/ai-in-retail/\"\u003EAI in Retail\u003C/a\u003E\u003C/li\u003E\r\n\u003C/ul\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2","text_0"]},"section_11":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"title_v2":"aem-GridColumn aem-GridColumn--default--12","simple_snowflake_acc":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"ai-in-cybersecurity-faqs","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-b7f4452948","type":"heading2","lines":["AI in Cybersecurity FAQs"],":type":"snowflake-site/components/title-v2"},"simple_snowflake_acc":{"id":"simple-snowflake-accordion-9fc8215522","showDivider":false,"accordionItemsList":[{"title":"What is AI in cybersecurity?","richText":"\u003Cp\u003EAI in cybersecurity refers to the use of AI techniques such as machine learning, behavioral analytics and natural language processing to detect suspicious activity, prioritize risk and automate parts of security operations. In practice, it is most often used across identity, endpoint, network, cloud and data-access workflows.\u003C/p\u003E"},{"title":"How does AI help detect cyber threats?","richText":"\u003Cp\u003EAI helps detect cyber threats by comparing activity against behavioral baselines, correlating signals across systems and surfacing patterns that would be difficult to piece together manually. This can include unusual logins, suspicious query behavior, lateral movement, phishing indicators or abnormal network communications.\u003C/p\u003E"},{"title":"Can AI replace human cybersecurity analysts?","richText":"\u003Cp\u003ENo. AI can reduce manual workload and help teams move faster, but high-impact decisions, unusual incidents and workflow design still require human judgment. The more realistic model is supervised collaboration, where AI assists with triage, enrichment and summarization.\u003C/p\u003E"},{"title":"What are the risks of using AI in cybersecurity?","richText":"\u003Cp\u003EThe main risks include weak explainability, poor data quality, model drift, false positives, false negatives, adversarial manipulation and inadequate governance. Teams also need to manage permission boundaries and auditability when AI becomes part of incident response or access control.\u003C/p\u003E"},{"title":"How are attackers using AI?","richText":"\u003Cp\u003EAttackers are using AI to generate more convincing phishing content, speed up reconnaissance, improve impersonation attempts and adapt malicious activity more quickly.\u003C/p\u003E"}],":type":"snowflake-site/components/simple-snowflake-accordion","appliedCssClassNames":"snowflake-responsive-component-bottom-padding-small"}},":itemsOrder":["title_v2","simple_snowflake_acc"]},"section_12":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"flexible_column_cont":"aem-GridColumn aem-GridColumn--default--12","title_v2":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"resources","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":type":"snowflake-site/components/container",":items":{"title_v2":{"id":"title-v2-87e0c2235c","type":"heading2","lines":["AI in Cybersecurity Resources"],":type":"snowflake-site/components/title-v2"},"flexible_column_cont":{"id":"flexible-column-container-fd316733b7","type":"2-column-even","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"extra-small","bottomPadding":"none","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-fdd8597fc6","appliedCssClassNames":"snowflake-responsive-container-inner-padding-medium",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"content_chip_0":{"id":"content-chip-5244b25e9c","tagText":"WHITE PAPER","tagColor":"#29B5E8","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.snowflake.com/en/resources/white-paper/snowflake-ai-security-framework/"},"linkTargetContentType":"GENERIC",":type":"snowflake-site/components/button","linkType":"SNOWFLAKE_EXTERNAL","text":"Read the white paper"},"headline":{"id":"title","type":"heading5","lines":["Snowflake AI Security Framework"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip"},"content_chip_1":{"id":"content-chip-b18eb11b01","tagText":"WEBINAR","tagColor":"#29B5E8","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.snowflake.com/webinars/thought-leadership/best-practices-for-ai-governance-and-security-in-snowflake-2025-08-27/"},"linkTargetContentType":"GENERIC",":type":"snowflake-site/components/button","linkType":"SNOWFLAKE_EXTERNAL","text":"Watch on demand"},"headline":{"id":"title-v2-080a0951a2","type":"heading5","lines":["Best Practices for AI Governance and Security in Snowflake"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip"}},":itemsOrder":["content_chip_0","content_chip_1"]},"flexible_column_content_container_2":{"layout":"SIMPLE","id":"container-03b19fe3d7","appliedCssClassNames":"snowflake-responsive-container-inner-padding-medium",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"content_chip_0":{"id":"content-chip-e1996a4217","tagText":"FEATURE","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.snowflake.com/en/product/features/horizon/"},"linkTargetContentType":"GENERIC",":type":"snowflake-site/components/button","linkType":"SNOWFLAKE_EXTERNAL","text":"Explore the feature"},"headline":{"id":"title-v2-3f4ac85007","type":"heading5","lines":["Snowflake Horizon Catalog"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip"},"content_chip_1":{"id":"content-chip-79feb3a85a","tagText":"BLOG","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.snowflake.com/en/blog/security-governance-practices-snowflake-intelligence/"},"linkTargetContentType":"GENERIC",":type":"snowflake-site/components/button","linkType":"SNOWFLAKE_EXTERNAL","text":"Read the post"},"headline":{"id":"title-v2-d9b3bf3b67","type":"heading5","lines":["Security and Governance Best Practices for Deploying Snowflake Intelligence Using Horizon Catalog"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip"}},":itemsOrder":["content_chip_0","content_chip_1"]},":type":"snowflake-site/components/flexible-column-container","isActiveTOC":false,"isBlogPage":false}},":itemsOrder":["title_v2","flexible_column_cont"]}},":itemsOrder":["section_0","section_1","section_2","section_3","section_4","section_5","section_6","section_7","section_8","section_9","section_10","section_11","section_12"]},":type":"snowflake-site/components/flexible-column-container","isActiveTOC":false,"isBlogPage":false}},":itemsOrder":["flexible_column_cont"]}},":itemsOrder":["container"]},"container":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"container":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-e6d9023d61","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"container":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"related_content":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-753c5a3c9b","appliedCssClassNames":"snowflake-container snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"related_content":{"id":"related-content-2fa8c0a755","relatedContent":[],":type":"snowflake-site/components/blog/related-content","isBlogPage":false}},":itemsOrder":["related_content"]}},":itemsOrder":["container"]},"container_411970921_":{"additionalClasses":"section__prefooter-25","layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"container":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-9a4ddf564a","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"container":{"layout":"RESPONSIVE_GRID","columnCount":12,"columnClassNames":{"flexible_column_cont":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","id":"container-f85a54e5fc","appliedCssClassNames":"snowflake-container snowflake-responsive-component-bottom-padding-extra-small snowflake-responsive-container-inner-padding-small",":type":"snowflake-site/components/container",":items":{"flexible_column_cont":{"id":"flexible-column-container-91b34fbd48","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"none","bottomPadding":"none","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"front-container","backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-1ed8d5dcfa",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"experiencefragment":{"id":"experiencefragment-873a9cdd7d","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/promos/pre-footer-promos/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/promos/pre-footer-promos/master.xfmodel.json"}},":itemsOrder":["experiencefragment"]},":type":"snowflake-site/components/flexible-column-container","isActiveTOC":false,"isBlogPage":false}},":itemsOrder":["flexible_column_cont"]}},":itemsOrder":["container"]}},":itemsOrder":["hero_system_copy","container_copy","container","container_411970921_"],":type":"wcm/foundation/components/responsivegrid"},"modal_container":{"layout":"SIMPLE","id":"container-f7cb387622",":type":"snowflake-site/components/modal/modal-container",":items":{},":itemsOrder":[]},"experiencefragment-footer":{"id":"experiencefragment-592fd8ae73","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer/master.xfmodel.json"},"experiencefragment":{"id":"experiencefragment-b39d59f2cf","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer-legal-disclaimers/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer-legal-disclaimers/master.xfmodel.json"}},":itemsOrder":["experiencefragment-banner","experiencefragment-header","markup_editor","responsivegrid","modal_container","experiencefragment-footer","experiencefragment"],":type":"wcm/foundation/components/responsivegrid"}},":itemsOrder":["root"],"isPasswordProtected":false,"analyticsContentTags":["snowflake-site:taxonomy/content-type/fundamentals"],"analyticsEnabled":true,"coveoConfig":{"searchHub":"snowflake.com","organizationId":"snowflakecomputingproduction8neljofn","apiKey":"xx335921a6-2a0a-40f2-a167-e390b4766c3d","pipeline":"snowflake.com"},"analyticsDebugMode":false,"analyticsData":{"excludeFromAnalytics":false,"subCategory":"","pageType":"homepage","templateName":"fundamentals-template","siteName":"snowflake","pageUrl":"/content/snowflake-site/global/en/artificial-intelligence/industries/ai-in-cybersecurity","language":"en","category":"general","pageName":"AI in Cybersecurity: How It Works, Use Cases and What’s Ahead","contentTags":["snowflake-site:taxonomy/content-type/fundamentals"]},"locale":"en"}
  