Ninja Labz blog
What AI-Native Security Actually Looks Like
Not a chatbot bolted onto a SIEM. A security operation where AI does the reading, the correlating and the first draft of the response, evidence decides, and a human approves change. Live, on production, with receipts.
Every vendor now has AI. It is usually a chat box in the corner of the product you already bought, trained to summarise the alert you were already ignoring. That is AI-assisted security, and it is fine, in the way that a satnav bolted to a horse is fine.
AI-native security is a different animal. It is what you get when you design the operation on the assumption that machines do the reading, the correlating and the first draft of the response, and then build the controls that make that safe. We run one, on our own production estate, in public. This is what it actually looks like.
The loop
An AI-native operation is not a product. It is a loop that closes itself, and each step is something a machine does better than a tired human at 3am.
- Listen. CHATTER reads eleven live threat feeds as one: ransomware leak sites, dark-web mirrors, CISA’s Known Exploited Vulnerabilities catalogue, NVD, ThreatFox, OTX, security news, infosec Mastodon and Telegram. Every morning an AI reads every item from the previous 24 hours, not a sample, and writes Probably Fine Daily from it.
- Sense. Local detection sensors read the web logs on the server itself, and only findings leave the box. A whole day of edge traffic, 41,794 requests, fingerprinted in 0.54 seconds.
- Attribute. Our own threat intelligence names what is attacking us. The first live case was a Mirai botnet node, attributed at 0.91 confidence from six independent kinds of evidence, with the chain a human can check.
- Respond. The incident raises itself, an AI triages it, and when the attribution is strong enough the edge blocks the source for 24 hours. Automatically, reversibly, with no human paged.
- Close out. An AI SecOps agent writes the post-incident report, proposes changes for a human to approve, and writes new detection rules. On its first real run: 16 post-incident reports, 7 rules made live, 3 change requests, 0 humans paged.
- Forge. A Rule Forge compares what we are (what we collect, what we already detect, who is attacking us) with what the world is doing, and finds the detections we are missing. It found 18 gaps on its first run.
- Remember. A perimeter graph holds every address that has reached our edge, what it probed for and which of our sites it hit. Thirty days in, 61,837 addresses; 80 of them were hunting for AI keys by name.
The rules that make it safe
The interesting part of AI-native security is not the AI. It is the rules around it. Ours fit on a sticky note.
Evidence decides. The model advises. A human approves change.
In practice that means:
- Every claim carries receipts. The daily paper cites the source items for every story, and a sentence containing a number that is in none of its sources is cut automatically before publication. When one got through anyway, we published a correction and fixed the check the same morning.
- Every AI-written rule has to prove itself. Before a detection goes live it is backtested against the last 5,000 real events. It must fire on the attack it describes and stay quiet on at least 99 per cent of everything else. The model writes it; the gate decides.
- The machine can block, not change. Automatic actions are narrow, expire on their own, and are guarded (never our own addresses, never the platform we sit behind). Anything that changes the estate is a proposal a human approves.
- Spend is capped and owned. Expensive deep-inference runs are owner-only and once a day. Apps that do not need a model do not get a key; seven of ours had theirs switched off in one morning.
- Everything has an off switch that a tired person can find.
What it is not
It is not “the AI will handle it”. A model that is confidently wrong at machine speed is not a security control; it is an incident with good grammar. The whole design assumes the model will sometimes be wrong, and puts the evidence, the gates and the human exactly where being wrong would hurt.
It is also not magic. Our deep-reading AI once read everything it was given and then used seven per cent of it, because its notes were being truncated and discarded without complaint. Nothing failed; every check was green. We only found it because we went looking. AI-native means you have to audit the machine as carefully as you once audited the people, and you have to do it continuously, which, conveniently, is also something machines are good at.
Why this matters for everyone else
The attackers are already AI-native. The scanners hitting us this month ask for Anthropic, OpenAI and Claude credentials by name, and read developer-server files straight out of home directories. They rent their infrastructure from the same clouds you do. They do not have a change advisory board.
Defenders who bolt a chatbot onto yesterday’s workflow will spend the next few years summarising incidents faster. Defenders who redesign the loop will spend them preventing the next one. We would rather be the second kind, in public, with the receipts showing.
Everything is probably fine. We have built an operation that tells us, every morning, exactly how probably.
See it running
- Probably Fine Daily: the morning paper the loop writes, every day at 06:00 UK.
- The Loop: the whole operation in three and a half minutes of film.
- We Built Five Globes and Forgot Four of Them: what happened when we pointed the same approach at our own estate.
ScottG · Ninja Labz · ninjalabz.io
Every morning at 06:00 UK an AI reads every threat-intel item from the last 24 hours and writes the paper, with receipts.
Read Probably Fine Daily